Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

23,162 CVEs

CVEs (23,162, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 476–500 of 23,162 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-42420 MEDIUM Patched 4.3 2026-04-28 OpenClaw before 2026.4.8 contains improper input validation in base64 decode paths that allocate memory before enforcing decoded-size limits. Attackers can exploit multiple…
CVE-2026-42421 MEDIUM Patched 5.4 2026-04-28 OpenClaw before 2026.4.8 contains a session management vulnerability where existing WebSocket sessions survive shared gateway token rotation. Attackers can maintain unautho…
CVE-2026-42422 HIGH Patched 8.8 2026-04-28 OpenClaw before 2026.4.8 contains a role bypass vulnerability in the device.token.rotate function that allows minting tokens for unapproved roles. Attackers can bypass devi…
CVE-2026-42423 HIGH Patched 7.5 2026-04-28 OpenClaw before 2026.4.8 contains an approval-timeout fallback mechanism that bypasses strictInlineEval explicit-approval requirements on gateway and node exec hosts. Attac…
CVE-2026-42424 MEDIUM Patched 5.7 2026-04-28 OpenClaw before 2026.4.8 treats shared reply MEDIA paths as trusted, allowing crafted references to trigger cross-channel local file exfiltration. Attackers can exploit thi…
CVE-2026-42426 HIGH Patched 8.8 2026-04-28 OpenClaw before 2026.4.8 contains an improper authorization vulnerability where the node.pair.approve method accepts operator.write scope instead of the narrower operator.p…
CVE-2026-42427 MEDIUM Patched 5.3 2026-04-28 OpenClaw before 2026.4.8 contains a remote code execution vulnerability caused by missing environment variable denylist entries for HGRCPATH, CARGO_BUILD_RUSTC_WRAPPER, RUS…
CVE-2026-42428 HIGH Patched 7.1 2026-04-28 OpenClaw versions before 2026.4.8 fail to enforce integrity verification on downloaded plugin archives. Attackers can install malicious or tampered plugin packages without …
CVE-2026-42429 HIGH Patched 7.1 2026-04-28 OpenClaw before 2026.4.8 contains a privilege escalation vulnerability in the gateway plugin HTTP authentication mechanism that escalates identity-bearing operator.read req…
CVE-2026-42430 MEDIUM Patched 6.5 2026-04-28 OpenClaw before 2026.4.8 contains a server-side request forgery vulnerability in Playwright redirect handling that allows attackers to bypass strict SSRF checks. Attackers …
CVE-2026-42431 HIGH Patched 8.1 2026-04-28 OpenClaw before 2026.4.8 contains a security bypass vulnerability in node.invoke(browser.proxy) that allows mutation of persistent browser profiles. Attackers can exploit t…
CVE-2026-42432 HIGH Patched 7.8 2026-04-28 OpenClaw before 2026.4.8 contains a privilege escalation vulnerability allowing previously paired nodes to reconnect with exec-capable commands without the operator.admin s…
CVE-2026-5794 NONE — 2026-04-28 A vulnerability affecting the detailed versions of Cryptobox allows a legitimate user to prevent another to login by triggering an account lockout via sending a specially c…
CVE-2026-6238 MEDIUM 6.5 2026-04-28 The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA lengt…
CVE-2026-6807 MEDIUM 5.5 2026-04-28 A vulnerability in GRASSMARLIN v3.2.1 allows crafted session data to trigger improper handling of XML input, which may result in unintended exposure of sensitive informat…
CVE-2026-7290 MEDIUM 6.3 2026-04-28 A vulnerability was determined in JeecgBoot up to 3.9.1. Impacted is the function SqlInjectionUtil of the file jeecg-boot/jeecg-boot-base-core/src/main/java/org/jeecg/commo…
CVE-2026-7291 MEDIUM 6.3 2026-04-28 A weakness has been identified in o2oa up to 10.0. This affects the function FileAction of the file FileAction.java of the component URL Fetching. Executing a manipulation …
CVE-2026-7292 MEDIUM 5.6 2026-04-28 A security vulnerability has been detected in o2oa up to 10.0. This impacts the function syncFile of the file NodeAgent.java of the component NodeAgent. The manipulation le…
CVE-2026-7293 MEDIUM 4.7 2026-04-28 A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function delete_category of the file /admin/ajax.php?action=delete_category. Th…
CVE-2026-7294 LOW 2.4 2026-04-28 A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is the function save_settings of the file /admin/index.php?page=save_se…
CVE-2026-7295 LOW 2.4 2026-04-28 A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this issue is the function save_menu of the file /admin/ajax.php?action=save_menu…
CVE-2026-33467 MEDIUM Patched 5.9 2026-04-28 Improper Verification of Cryptographic Signature (CWE-347) in Elastic Package Registry could allow an attacker positioned to intercept network traffic, or to otherwise infl…
CVE-2026-37750 MEDIUM 6.1 2026-04-28 A reflected Cross-Site Scripting (XSS) vulnerability in School Management System by mahmoudai1 allows unauthenticated remote attackers to execute arbitrary JavaScript in vi…
CVE-2026-41446 CRITICAL 9.8 2026-04-28 Snap One WattBox 800 and 820 series firmware versions prior to 2.10.0.0 contain undisclosed diagnostic HTTP endpoints that require only the device MAC address and service t…
CVE-2026-41649 HIGH Patched 7.7 2026-04-28 Outline is a service that allows for collaborative documentation. The `shares.create` API endpoint starting in version 0.86.0 and prior to version 1.7.0 has an insecure dir…