Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54243
Total
4300
Critical
16125
High
15819
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-102094 | HIGH | 7.2 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Unsafe Reflection and does not sufficiently restrict the code that the mail-processing pipeline could load … | Sep 30, 2026 |
| CVE-2026-102093 | HIGH | 7.2 | Kiteworks Core before version 9.5.0 is vulnerable to Improper Privilege Management and does not correctly enforce restrictions on role assignment, which could allow an authenticated … | Sep 30, 2026 |
| CVE-2026-102092 | HIGH | 8.7 | Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-site Scripting (XSS) that could allow an authenticated user to store crafted content that executes arbitrary … | Sep 30, 2026 |
| CVE-2026-102091 | HIGH | 7.5 | Kiteworks Secure Data Forms before version 9.5.0 is vulnerable to Server-Side Request Forgery that could allow an unauthenticated, remote attacker to make the server issue … | Sep 30, 2026 |
| CVE-2026-102090 | MEDIUM | 4.3 | Kiteworks Core before version 9.5.1 is vulnerable to Content Injection. A URL parameter in the PDF viewer was insufficiently validated, allowing an attacker-controlled document to … | Sep 30, 2026 |
| CVE-2026-102089 | HIGH | 7.2 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to a path traversal weakness in an administrative import function allowed an authenticated administrator to write … | Sep 30, 2026 |
| CVE-2026-101276 | UNKNOWN | — | iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog server_timer_proc() frees streams without cancelling/joining their worker threads, so a blocked worker … | Sep 30, 2026 |
| CVE-2024-58387 | HIGH | 7.5 | Inspur Haiyue HCM Cloud contains an arbitrary file read vulnerability in the /api/model_report/file/download endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying … | Sep 30, 2026 |
| CVE-2023-54403 | HIGH | 7.5 | Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability in /ajax/getemaildata.php that allows unauthenticated attackers to bypass authentication using the DontCheckLogin=1 … | Sep 30, 2026 |
| CVE-2023-54402 | HIGH | 7.5 | iDocView contains a server-side request forgery vulnerability in its /doc/upload endpoint that allows remote unauthenticated attackers to fetch arbitrary URLs by supplying a hardcoded default … | Sep 30, 2026 |
| CVE-2026-103548 | UNKNOWN | — | Improperly stored passwords in the config file in Itron MV-90 xi 3.0 allows attackers to decode the passwords and password histories to gain access to … | Sep 30, 2026 |
| CVE-2026-103547 | UNKNOWN | — | In ldapd in OpenBSD 7.8 before errata 057 and 7.9 before errata 021, delegated BSD authentication results are correlated only by the LDAP child process … | Sep 30, 2026 |
| CVE-2026-103387 | MEDIUM | 4.3 | A weakness has been identified in garycourt uri-js up to 4.4.1. This affects the function URI.parse of the file src/schemes/mailto.ts of the component Mailto Header … | Sep 30, 2026 |
| CVE-2026-102994 | UNKNOWN | — | pypdf is a free and open-source pure-python PDF library. Prior to 6.18.0, a crafted PDF containing indirect-object identifiers or generation-number tokens that continue for a … | Sep 30, 2026 |
| CVE-2026-102993 | UNKNOWN | — | pypdf is a free and open-source pure-python PDF library. Prior to 6.17.0, a crafted PDF can provide unusually large Roman page-label values that cause pypdf/_page_labels.py … | Sep 30, 2026 |
| CVE-2026-102992 | UNKNOWN | — | piscina is a node.js worker pool implementation. Prior to 4.9.4, 5.3.2, and 6.0.0-rc.5, Piscina stores ThreadPool.options in src/index.ts as a plain object that inherits from … | Sep 30, 2026 |
| CVE-2026-102991 | MEDIUM | 6.5 | Mako is a template library written in Python. Prior to 1.4.2, on Windows, TemplateLookup.get_template() in mako/lookup.py resolves template URIs with posixpath, while Template.__init__() in mako/template.py … | Sep 30, 2026 |
| CVE-2026-102990 | UNKNOWN | — | basic-ftp is an FTP client for Node.js. Prior to 6.2.1, Client.list() can be forced by a malicious or compromised FTP server to spend quadratic CPU … | Sep 30, 2026 |
| CVE-2026-101885 | HIGH | 7.8 | ZeroClaw versions before 0.8.5 built with plugins-wasm feature contain a path traversal vulnerability in plugin installation that fails to validate the wasm_path manifest field. Attackers … | Sep 30, 2026 |
| CVE-2026-101884 | HIGH | 7.5 | OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS variables. Attackers with gateway or … | Sep 30, 2026 |
| CVE-2026-101883 | MEDIUM | 5.4 | OpenClaw Windows Node through 2026.9.4 contains a server-side request forgery vulnerability in the canvas.present capability that bypasses URL risk evaluation enforced by canvas.navigate. Attackers with … | Sep 30, 2026 |
| CVE-2026-101882 | HIGH | 8.8 | OpenClaw Windows Node before 2026.7.1 contains an incomplete validation vulnerability in system.execApprovals.set that accepts wildcard-executable rules and abusable system binaries like mshta, rundll32, and certutil. … | Sep 30, 2026 |
| CVE-2026-101881 | MEDIUM | 6.5 | OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits vulnerability in the gateway WebSocket transport that allows connected gateways to exhaust node … | Sep 30, 2026 |
| CVE-2026-101880 | HIGH | 8.8 | OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval policy where ExecShellWrapperParser fails to split commands on pipe operators or … | Sep 30, 2026 |
| CVE-2026-101879 | MEDIUM | 6.5 | OpenClaw Windows Node before 2026.7.1-3 contains a missing authorization vulnerability in NodeService capture handlers that allows connected gateways or agents to perform screen snapshots, camera … | Sep 30, 2026 |