Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
25534
Total
1899
Critical
7798
High
8005
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-45662 | HIGH | 8.8 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.0 and earlier, the deleteRegistry function in Dokploy (packages/server/src/services/registry.ts) executes docker logout ${response.registryUrl} without … | May 29, 2026 |
| CVE-2026-44962 | CRITICAL | 9.9 | Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied input is interpolated into XPath queries without proper sanitization. This … | May 29, 2026 |
| CVE-2026-39276 | HIGH | 7.2 | The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated administrators to execute arbitrary PHP code. By uploading a malicious … | May 29, 2026 |
| CVE-2026-39229 | MEDIUM | 6.5 | Bolt CMS through 3.7.0 allows SQL Injection in the 'order' parameter of the content listing pages. An authenticated attacker with low-level privileges can exploit this … | May 29, 2026 |
| CVE-2026-36324 | UNKNOWN | — | SourceCodester Doctor Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) due to improper handling of user supplied input in the user registration functionality … | May 29, 2026 |
| CVE-2026-35674 | HIGH | 8.8 | OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped clients to execute privileged commands. Attackers with operator.write scope … | May 29, 2026 |
| CVE-2026-35673 | MEDIUM | 6.5 | OpenClaw before 2026.4.29 contains an SSRF policy bypass vulnerability in browser debug and export routes that allows reuse of already-open blocked tabs. Attackers with access … | May 29, 2026 |
| CVE-2026-35630 | HIGH | 8.0 | OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to enforce configured approver identity. Non-approver users can click approval … | May 29, 2026 |
| CVE-2026-34507 | MEDIUM | 5.4 | OpenClaw before 2026.4.29 contains a policy bypass vulnerability in QQBot admin commands that allows authenticated senders to skip DM-only and allowFrom policy checks. Attackers can … | May 29, 2026 |
| CVE-2026-33386 | UNKNOWN | — | QuickCMS is vulnerable to Cross-Site Scripting (XSS) through its insecure HTTP-based plugin‑fetching mechanism. A malicious attacker can perform a Man‑in‑the‑Middle (MITM) attack by impersonating the … | May 29, 2026 |
| CVE-2026-33384 | UNKNOWN | — | QuickCMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables … | May 29, 2026 |
| CVE-2026-32906 | MEDIUM | 4.3 | OpenClaw before 2026.5.12 contains a privilege escalation vulnerability in Slack plugin approvals that allows exec-authorized users to resolve plugin approvals through the exec approver gate. … | May 29, 2026 |
| CVE-2026-32905 | HIGH | 8.3 | OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows non-owner authorized chat senders to issue device-pairing bootstrap codes without … | May 29, 2026 |
| CVE-2026-10101 | MEDIUM | 6.3 | ACM/MCE assisted-service writes raw referenced pull-secret contents into `InfraEnv.status.conditions[].message` when pull-secret validation fails. A namespace principal with the stock `view` ClusterRole cannot directly read Secrets, … | May 29, 2026 |
| CVE-2026-10099 | MEDIUM | 4.0 | XX-Net V5.16.6 contains a WebSocket frame parsing vulnerability in the WebSocket_receive_worker routine of simple_http_server.py that allows attackers to cause corrupted application data by sending unmasked … | May 29, 2026 |
| CVE-2026-10069 | HIGH | 7.5 | A vulnerability has been found in Shibby Tomato 1.28. The impacted element is an unknown function of the file usr/sbin/miniupnpd. Such manipulation leads to resource … | May 29, 2026 |
| CVE-2026-10068 | HIGH | 7.3 | A flaw has been found in Shibby Tomato 1.28. The affected element is the function send of the file usr/sbin/miniupnpd of the component SUBSCRIBE Call … | May 29, 2026 |
| CVE-2026-10067 | HIGH | 8.8 | A vulnerability was detected in Shibby Tomato 1.28. Impacted is the function sub_90F0 of the file multimon.cgi. The manipulation results in stack-based buffer overflow. The … | May 29, 2026 |
| CVE-2026-10066 | HIGH | 8.8 | A security vulnerability has been detected in Shibby Tomato up to 1.28. This issue affects the function sub_9068 of the file tomatoups.cgi of the component … | May 29, 2026 |
| CVE-2026-10065 | HIGH | 8.8 | A weakness has been identified in Shibby Tomato 1.28. This vulnerability affects the function get_ups_field of the file tomatodata.cgi. Executing a manipulation of the argument … | May 29, 2026 |
| CVE-2026-10064 | MEDIUM | 6.3 | A security flaw has been discovered in TRENDnet TEW-432BRP 3.10B20. This affects the function formSetPortTr of the file /goform/formSetPortTr. Performing a manipulation of the argument … | May 29, 2026 |
| CVE-2018-25404 | HIGH | 8.2 | The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the … | May 29, 2026 |
| CVE-2018-25403 | HIGH | 8.2 | The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the … | May 29, 2026 |
| CVE-2018-25402 | HIGH | 8.2 | The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the … | May 29, 2026 |
| CVE-2018-25401 | HIGH | 8.2 | The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the … | May 29, 2026 |