Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
28433
Total
2190
Critical
8535
High
8856
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-29168 | HIGH | 7.3 | Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's mod_md via OCSP response data. This issue affects Apache HTTP Server: from 2.4.30 … | May 05, 2026 |
| CVE-2026-7833 | HIGH | 7.2 | A weakness has been identified in EFM ipTIME C200 up to 1.092. This vulnerability affects the function sub_408F90 of the file /cgi/iux_set.cgi of the component … | May 05, 2026 |
| CVE-2026-7832 | HIGH | 7.0 | A security flaw has been discovered in IObit Advanced SystemCare 19. This affects an unknown part of the file ASC.exe of the component Service. The … | May 05, 2026 |
| CVE-2026-6918 | HIGH | 7.5 | In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte crafted TCP message. | May 05, 2026 |
| CVE-2026-30246 | MEDIUM | 6.5 | Fiber is a web framework for Go. In github.com/gofiber/fiber/v3 versions through 3.1.0, the default key generator in the cache middleware uses only the request path … | May 05, 2026 |
| CVE-2026-28510 | MEDIUM | 5.9 | eLabFTW is an open source electronic lab notebook. In elabftw versions through 5.4.1, the login flow did not reliably preserve the multi-factor authentication state across … | May 05, 2026 |
| CVE-2026-27694 | MEDIUM | 5.4 | Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the email notification templates insert user-controlled device, geofence, and … | May 05, 2026 |
| CVE-2026-27693 | MEDIUM | 5.4 | Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the KML and GPX export functionality writes device names … | May 05, 2026 |
| CVE-2026-27644 | MEDIUM | 6.5 | Traccar is an open source GPS tracking system. In versions between 6.11.1 and 6.13.0, the CSV export functionality writes position data, including user-controlled device and … | May 05, 2026 |
| CVE-2026-6262 | MEDIUM | 6.5 | The Betheme theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 28.4. This is due to the upload_icons() function … | May 05, 2026 |
| CVE-2026-6261 | HIGH | 8.8 | The Betheme theme for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 28.4. This is due to the upload_icons() function … | May 05, 2026 |
| CVE-2026-43574 | MEDIUM | 6.5 | OpenClaw before 2026.4.12 contains an improper authorization vulnerability in helper-backed channels where empty resolved approver lists are interpreted as explicit approval authorization. Attackers can resolve … | May 05, 2026 |
| CVE-2026-43573 | HIGH | 7.7 | OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in existing-session browser interaction routes. Attackers can bypass SSRF navigation guards to interact with … | May 05, 2026 |
| CVE-2026-43572 | MEDIUM | 5.3 | OpenClaw versions 2026.4.10 before 2026.4.14 contain a missing authorization vulnerability in the Microsoft Teams SSO invoke handler that fails to apply sender allowlist checks. Attackers … | May 05, 2026 |
| CVE-2026-43571 | HIGH | 8.8 | OpenClaw before 2026.4.10 contains a plugin trust bypass vulnerability that allows channel setup catalog lookups to resolve workspace plugin shadows before bundled channel plugins. Attackers … | May 05, 2026 |
| CVE-2026-43570 | MEDIUM | 6.5 | OpenClaw versions 2026.3.22 before 2026.4.5 contain a symlink traversal vulnerability in remote marketplace repository path handling that allows attackers to escape the expected repository root. … | May 05, 2026 |
| CVE-2026-43569 | HIGH | 8.8 | OpenClaw before 2026.4.9 contains an authentication bypass vulnerability allowing untrusted workspace plugins to be auto-enabled during non-interactive onboarding when provider auth choices are shadowed. Attackers … | May 05, 2026 |
| CVE-2026-43568 | MEDIUM | 6.5 | OpenClaw versions 2026.4.5 before 2026.4.10 contain a privilege escalation vulnerability allowing write-scoped operators to modify persistent memory dreaming settings. Attackers with write-scoped gateway access can … | May 05, 2026 |
| CVE-2026-43567 | MEDIUM | 6.5 | OpenClaw before 2026.4.10 contains a path traversal vulnerability in the screen_record tool's outPath parameter that bypasses workspace-only filesystem guards. Attackers can exploit this by specifying … | May 05, 2026 |
| CVE-2026-43566 | CRITICAL | 9.1 | OpenClaw versions 2026.4.7 before 2026.4.14 contain a privilege escalation vulnerability where heartbeat owner downgrade logic skips webhook wake events carrying untrusted content. Attackers can exploit … | May 05, 2026 |
| CVE-2026-43535 | MEDIUM | 6.8 | OpenClaw before 2026.4.14 contains an authorization context reuse vulnerability in collect-mode queue batches that allows messages from different senders to inherit the final sender's authorization … | May 05, 2026 |
| CVE-2026-43534 | CRITICAL | 9.1 | OpenClaw before 2026.4.10 contains an input validation vulnerability that allows external hook metadata to be enqueued as trusted system events. Attackers can supply malicious hook … | May 05, 2026 |
| CVE-2026-43533 | HIGH | 8.6 | OpenClaw before 2026.4.10 contains an arbitrary file read vulnerability in QQBot media tags that allows attackers to reference host-local paths outside the intended media storage … | May 05, 2026 |
| CVE-2026-43532 | HIGH | 7.7 | OpenClaw versions 2026.4.7 before 2026.4.10 fail to normalize Discord event cover image parameters in sandbox media processing. Attackers can bypass media normalization to inject host-local … | May 05, 2026 |
| CVE-2026-43531 | HIGH | 7.3 | OpenClaw before 2026.4.9 contains an environment variable injection vulnerability allowing malicious workspace .env files to set runtime-control variables. Attackers can inject variables affecting update sources, … | May 05, 2026 |