Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-34382 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-34382)
vulnerability in csrf (CVE-2026-34382). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34384 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-34384)
vulnerability in csrf (CVE-2026-34384). Data can be tampered with by attackers.
|
| CVE-2026-34394 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-34394)
vulnerability in csrf (CVE-2026-34394). Confidential information can be exposed externally.
|
| CVE-2026-34395 |
|
Vulnerability in wwbn (CVE-2026-34395)
vulnerability in wwbn (CVE-2026-34395). Confidential information can be exposed externally.
|
| CVE-2026-34396 |
|
Cross-Site Scripting (XSS) in csrf (CVE-2026-34396)
cross-site scripting in csrf (CVE-2026-34396). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34381 |
|
Vulnerability in apache (CVE-2026-34381)
vulnerability in apache (CVE-2026-34381). Confidential information can be exposed externally.
|
| CVE-2026-34372 |
|
Vulnerability in symfony (CVE-2026-34372)
vulnerability in symfony (CVE-2026-34372). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34204 |
|
Authentication Bypass in minio (CVE-2026-34204)
authentication bypass in minio (CVE-2026-34204). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-30520 |
|
SQL Injection in sqli (CVE-2026-30520)
SQL injection in sqli (CVE-2026-30520). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-2123 |
|
Vulnerability in privilege-escalation (CVE-2026-2123)
vulnerability in privilege-escalation (CVE-2026-2123). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34360 |
|
SSRF (Server-Side Request Forgery) in hapifhir (CVE-2026-34360)
SSRF in hapifhir (CVE-2026-34360). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34361 |
|
Vulnerability in hapifhir (CVE-2026-34361)
vulnerability in hapifhir (CVE-2026-34361). Confidential information can be exposed externally.
|
| CVE-2026-34359 |
|
Vulnerability in hapifhir (CVE-2026-34359)
vulnerability in hapifhir (CVE-2026-34359). Confidential information can be exposed externally.
|
| CVE-2026-5203 |
|
Path Traversal in path-traversal (CVE-2026-5203)
path traversal in path-traversal (CVE-2026-5203). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5204 |
|
Buffer Overflow in tenda (CVE-2026-5204)
vulnerability in tenda (CVE-2026-5204). Successful exploitation can lead to full system takeover.
|
| CVE-2026-22561 |
|
Vulnerability in privilege-escalation (CVE-2026-22561)
vulnerability in privilege-escalation (CVE-2026-22561). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34503 |
|
Vulnerability in openclaw (CVE-2026-34503)
vulnerability in openclaw (CVE-2026-34503). Confidential information can be exposed externally.
|
| CVE-2026-34504 |
|
SSRF (Server-Side Request Forgery) in c (CVE-2026-34504)
SSRF in c (CVE-2026-34504). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-33580 |
|
Vulnerability in openclaw (CVE-2026-33580)
vulnerability in openclaw (CVE-2026-33580). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-33581 |
|
Path Traversal in openclaw (CVE-2026-33581)
path traversal in openclaw (CVE-2026-33581). Confidential information can be exposed externally.
|
| CVE-2026-33576 |
|
Authorization Flaw in openclaw (CVE-2026-33576)
vulnerability in openclaw (CVE-2026-33576). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-33577 |
|
Authorization Flaw in openclaw (CVE-2026-33577)
vulnerability in openclaw (CVE-2026-33577). Confidential information can be exposed externally.
|
| CVE-2026-33578 |
|
Authorization Flaw in openclaw (CVE-2026-33578)
vulnerability in openclaw (CVE-2026-33578). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-33579 |
|
Authorization Flaw in privilege-escalation (CVE-2026-33579)
vulnerability in privilege-escalation (CVE-2026-33579). Successful exploitation can lead to full system takeover.
|
| CVE-2026-5198 |
|
Vulnerability in sqli (CVE-2026-5198)
vulnerability in sqli (CVE-2026-5198). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-4267 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-4267)
cross-site scripting in wordpress (CVE-2026-4267). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3139 |
|
Vulnerability in wordpress (CVE-2026-3139)
vulnerability in wordpress (CVE-2026-3139). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-3191 |
|
Cross-Site Request Forgery (CSRF) in wordpress (CVE-2026-3191)
vulnerability in wordpress (CVE-2026-3191). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34505 |
|
Vulnerability in openclaw (CVE-2026-34505)
vulnerability in openclaw (CVE-2026-34505). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34506 |
|
Authorization Flaw in openclaw (CVE-2026-34506)
vulnerability in openclaw (CVE-2026-34506). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32988 |
|
Vulnerability in openclaw (CVE-2026-32988)
vulnerability in openclaw (CVE-2026-32988). Data can be tampered with by attackers.
|
| CVE-2026-32970 |
|
Vulnerability in openclaw (CVE-2026-32970)
vulnerability in openclaw (CVE-2026-32970). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-32971 |
|
Vulnerability in openclaw (CVE-2026-32971)
vulnerability in openclaw (CVE-2026-32971). Successful exploitation can lead to full system takeover.
|
| CVE-2026-32976 |
|
Vulnerability in openclaw (CVE-2026-32976)
vulnerability in openclaw (CVE-2026-32976). Data can be tampered with by attackers.
|
| CVE-2026-32977 |
|
Vulnerability in openclaw (CVE-2026-32977)
vulnerability in openclaw (CVE-2026-32977). Data can be tampered with by attackers.
|
| CVE-2026-32982 |
|
Vulnerability in openclaw (CVE-2026-32982)
vulnerability in openclaw (CVE-2026-32982). Confidential information can be exposed externally.
|
| CVE-2026-32916 |
|
Vulnerability in openclaw (CVE-2026-32916)
vulnerability in openclaw (CVE-2026-32916). Confidential information can be exposed externally.
|
| CVE-2026-32917 |
|
OS Command Injection in openclaw (CVE-2026-32917)
OS command injection in openclaw (CVE-2026-32917). Successful exploitation can lead to full system takeover.
|
| CVE-2026-32920 |
|
Vulnerability in c (CVE-2026-32920)
vulnerability in c (CVE-2026-32920). Successful exploitation can lead to full system takeover.
|
| CVE-2026-32921 |
|
Vulnerability in openclaw (CVE-2026-32921)
vulnerability in openclaw (CVE-2026-32921). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-33997 |
|
Vulnerability in docker (CVE-2026-33997)
vulnerability in docker (CVE-2026-33997). Confidential information can be exposed externally.
|
| CVE-2026-4046 |
|
Vulnerability in c (CVE-2026-4046)
vulnerability in c (CVE-2026-4046). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-34237 |
|
Vulnerability in io.modelcontextprotocol.sdk:mcp-core (CVE-2026-34237)
vulnerability in io.modelcontextprotocol.sdk:mcp-core (CVE-2026-34237). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.18.3` or later.
|
| CVE-2026-4266 |
|
Unsafe Deserialization in deserialization (CVE-2026-4266)
vulnerability in deserialization (CVE-2026-4266). Successful exploitation can lead to full system takeover.
|
| CVE-2026-4315 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-4315)
vulnerability in csrf (CVE-2026-4315). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-2370 |
|
Vulnerability in gitlab (CVE-2026-2370)
vulnerability in gitlab (CVE-2026-2370). Confidential information can be exposed externally. Mitigation: upgrade to `18.8.7, 18.9.3, 18.10.1` or later.
|
| CVE-2026-3055 KEV |
|
[KEV] Out-of-Bounds Read in Citrix netscaler (CVE-2026-3055)
vulnerability in Citrix netscaler (CVE-2026-3055). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2026-23399 |
|
Vulnerability in Kernel (CVE-2026-23399)
vulnerability in Kernel (CVE-2026-23399). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.12.78, 6.18.20, 6.19.10` or later.
|
| CVE-2026-27309 |
|
Use-After-Free in adobe (CVE-2026-27309)
vulnerability in adobe (CVE-2026-27309). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34046 |
|
Vulnerability in langflow (CVE-2026-34046)
vulnerability in langflow (CVE-2026-34046). Successful exploitation can lead to full system takeover. Exploitable via ``_read_flow``.
|