Search
23,162 CVEs
CVEs (23,162, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 426–450 of 23,162 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-38948 | MEDIUM | 5.4 | 2026-04-28 | Cross-Site Scripting (XSS) vulnerability exists in FUEL CMS v1.5.2 and before within the asset upload functionality. The application fails to properly sanitize uploaded SVG… | |
| CVE-2026-41873 | CRITICAL | 9.8 | 2026-04-28 | ** UNSUPPORTED WHEN ASSIGNED ** Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Pony Mail leading to admin account takeove… | |
| CVE-2026-24178 | CRITICAL | Patched | 9.8 | 2026-04-28 | NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization bypass through … |
| CVE-2026-24186 | HIGH | Patched | 8.8 | 2026-04-28 | NVIDIA FLARE SDK contains a vulnerability in FOBS, where an attacker may cause deserialization of untrusted data by sending a malicious FOBS- encoded message. A successful… |
| CVE-2026-24204 | MEDIUM | Patched | 6.5 | 2026-04-28 | NVIDIA Flare SDK contains a vulnerability where an Attacker may cause an Improper Input Validation by path traversing. A successful exploit of this vulnerability may lead t… |
| CVE-2026-24222 | HIGH | Patched | 8.6 | 2026-04-28 | NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker could cause improper access control by sending prompt-… |
| CVE-2026-24231 | MEDIUM | Patched | 6.3 | 2026-04-28 | NVIDIA NemoClaw contains a vulnerability in the validateEndpointUrl() SSRF protection component, where an attacker could cause a server-side request forgery by supplying a … |
| CVE-2026-38949 | HIGH | 8.9 | 2026-04-28 | Cross-Site Scripting (XSS) vulnerability exists in HTMLy version 3.1.1 in the content creation functionality at the /add/content?type=image endpoint. The application fails … | |
| CVE-2026-3893 | CRITICAL | 9.4 | 2026-04-28 | The Carlson VASCO-B GNSS Receiver lacks an authentication mechanism, allowing an attacker with network access to directly access and modify its configuration and operatio… | |
| CVE-2026-41373 | MEDIUM | Patched | 6.1 | 2026-04-28 | OpenClaw before 2026.3.31 contains an incomplete host-env-security-policy.json that fails to restrict compiler binary environment variables, allowing untrusted models to su… |
| CVE-2026-41374 | MEDIUM | Patched | 5.3 | 2026-04-28 | OpenClaw before 2026.3.31 performs Discord audio preflight transcription before validating member authorization, allowing unauthenticated attackers to consume resources. Re… |
| CVE-2026-41375 | MEDIUM | Patched | 6.5 | 2026-04-28 | OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the /phone arm and /phone disarm endpoints that fails to properly enforce operator.admin scope c… |
| CVE-2026-41376 | MEDIUM | Patched | 5.4 | 2026-04-28 | OpenClaw before 2026.3.31 contains an allowlist bypass vulnerability in Matrix thread root and reply context handling that fails to properly validate message senders. Attac… |
| CVE-2026-41377 | MEDIUM | Patched | 4.6 | 2026-04-28 | OpenClaw before 2026.3.31 contains a fail-open vulnerability in the plugin installation flow where security scan failures do not block installation. Attackers can exploit s… |
| CVE-2026-41378 | HIGH | Patched | 8.8 | 2026-04-28 | OpenClaw before 2026.3.31 contains a privilege escalation vulnerability allowing paired nodes with role=node to dispatch node.event agent requests with unrestricted gateway… |
| CVE-2026-41379 | HIGH | Patched | 7.1 | 2026-04-28 | OpenClaw before 2026.3.28 contains a privilege escalation vulnerability allowing authenticated operators with write permissions to access admin-class Talk Voice configurati… |
| CVE-2026-41380 | HIGH | Patched | 7.3 | 2026-04-28 | OpenClaw before 2026.3.28 contains an execution approval vulnerability in exec-approvals-allowlist.ts that allows allow-always persistence to trust wrapper carrier executab… |
| CVE-2026-41381 | MEDIUM | Patched | 5.4 | 2026-04-28 | OpenClaw before 2026.3.31 contains an access control bypass vulnerability in the Discord voice manager that allows attackers to bypass channel-level member access allowlist… |
| CVE-2026-41382 | MEDIUM | Patched | 5.4 | 2026-04-28 | OpenClaw before 2026.3.31 contains an authorization bypass vulnerability in Discord voice ingress that allows attackers to bypass channel and member allowlist restrictions.… |
| CVE-2026-41383 | HIGH | Patched | 8.1 | 2026-04-28 | OpenClaw before 2026.4.2 contains an arbitrary directory deletion vulnerability in mirror mode that allows attackers to delete remote directories by influencing remoteWorks… |
| CVE-2026-41384 | HIGH | Patched | 7.8 | 2026-04-28 | OpenClaw before 2026.3.24 contains an environment variable injection vulnerability in the CLI backend runner that allows attackers to inject malicious environment variables… |
| CVE-2026-41385 | MEDIUM | Patched | 6.5 | 2026-04-28 | OpenClaw before 2026.3.31 stores Nostr privateKey as plaintext in configuration, allowing exposure through config.get method calls that bypass redaction mechanisms. Attacke… |
| CVE-2026-41386 | CRITICAL | Patched | 9.1 | 2026-04-28 | OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bootstrap setup codes are not bound to intended device roles and scopes during pairing. Attack… |
| CVE-2026-41387 | HIGH | Patched | 7.8 | 2026-04-28 | OpenClaw before 2026.3.22 contains an incomplete host environment variable sanitization vulnerability in host-env-security-policy.json and host-env-security.ts that allows … |
| CVE-2026-41388 | MEDIUM | Patched | 6.5 | 2026-04-28 | OpenClaw before 2026.3.31 contains a configuration management vulnerability where startup migration treats empty-array settings as missing values. Attackers can restart the… |