Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-62189 |
|
Vulnerability in openclaw (CVE-2026-62189)
vulnerability in openclaw (CVE-2026-62189). Confidential information can be exposed externally.
|
| CVE-2026-62190 |
|
Vulnerability in openclaw (CVE-2026-62190)
vulnerability in openclaw (CVE-2026-62190). Successful exploitation can lead to full system takeover.
|
| CVE-2026-62191 |
|
Vulnerability in openclaw (CVE-2026-62191)
vulnerability in openclaw (CVE-2026-62191). Data can be tampered with by attackers.
|
| CVE-2026-62194 |
|
Vulnerability in privilege-escalation (CVE-2026-62194)
vulnerability in privilege-escalation (CVE-2026-62194). Successful exploitation can lead to full system takeover.
|
| CVE-2026-62192 |
|
Authorization Flaw in openclaw (CVE-2026-62192)
vulnerability in openclaw (CVE-2026-62192). Data can be tampered with by attackers.
|
| CVE-2026-62186 |
|
Vulnerability in openclaw (CVE-2026-62186)
vulnerability in openclaw (CVE-2026-62186). Confidential information can be exposed externally.
|
| CVE-2026-62187 |
|
Authorization Flaw in openclaw (CVE-2026-62187)
vulnerability in openclaw (CVE-2026-62187). Confidential information can be exposed externally.
|
| CVE-2026-62188 |
|
Authorization Flaw in openclaw (CVE-2026-62188)
vulnerability in openclaw (CVE-2026-62188). Confidential information can be exposed externally.
|
| CVE-2026-62185 |
|
Vulnerability in CVE-2026-62185 (CVE-2026-62185)
vulnerability in CVE-2026-62185 (CVE-2026-62185). Confidential information can be exposed externally.
|
| CVE-2026-61458 |
|
Vulnerability in CVE-2026-61458 (CVE-2026-61458)
vulnerability in CVE-2026-61458 (CVE-2026-61458). Confidential information can be exposed externally. Exploitable via `POST /p/`.
|
| CVE-2026-62184 |
|
Vulnerability in CVE-2026-62184 (CVE-2026-62184)
vulnerability in CVE-2026-62184 (CVE-2026-62184). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58500 |
|
Cross-Site Scripting (XSS) in appium (CVE-2026-58500)
cross-site scripting in appium (CVE-2026-58500). Data can be tampered with by attackers.
|
| CVE-2026-51539 |
|
Vulnerability in dos (CVE-2026-51539)
vulnerability in dos (CVE-2026-51539). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39042 |
|
Vulnerability in dos (CVE-2026-39042)
vulnerability in dos (CVE-2026-39042). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15685 |
|
Vulnerability in ollama (CVE-2026-15685)
vulnerability in ollama (CVE-2026-15685). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15597 |
|
Vulnerability in sqli (CVE-2026-15597)
vulnerability in sqli (CVE-2026-15597). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15680 |
|
Vulnerability in CVE-2026-15680 (CVE-2026-15680)
vulnerability in CVE-2026-15680 (CVE-2026-15680). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15683 |
|
Vulnerability in CVE-2026-15683 (CVE-2026-15683)
vulnerability in CVE-2026-15683 (CVE-2026-15683). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15684 |
|
Vulnerability in privilege-escalation (CVE-2026-15684)
vulnerability in privilege-escalation (CVE-2026-15684). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48364 |
|
Vulnerability in adobe (CVE-2026-48364)
vulnerability in adobe (CVE-2026-48364). Successful exploitation can lead to full system takeover.
|
| CVE-2026-48363 |
|
Vulnerability in adobe (CVE-2026-48363)
vulnerability in adobe (CVE-2026-48363). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58410 |
|
Vulnerability in CVE-2026-58410 (CVE-2026-58410)
vulnerability in CVE-2026-58410 (CVE-2026-58410). Confidential information can be exposed externally. Exploitable via ``familyId``.
|
| CVE-2026-55771 |
|
Code Injection in com.cedarpolicy:cedar-java (CVE-2026-55771)
code injection in com.cedarpolicy:cedar-java (CVE-2026-55771). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `4.9.0` or later.
|
| CVE-2026-49972 |
|
Unrestricted File Upload in laravel (CVE-2026-49972)
vulnerability in laravel (CVE-2026-49972). Successful exploitation can lead to full system takeover.
|
| CVE-2026-49970 |
|
Path Traversal in plank/laravel-mediable (CVE-2026-49970)
path traversal in plank/laravel-mediable (CVE-2026-49970). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.0.0` or later.
|
| CVE-2026-49969 |
|
SSRF (Server-Side Request Forgery) in laravel (CVE-2026-49969)
SSRF in laravel (CVE-2026-49969). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-26396 |
|
Path Traversal in path-traversal (CVE-2026-26396)
path traversal in path-traversal (CVE-2026-26396). Confidential information can be exposed externally.
|
| CVE-2025-45869 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2025-45869)
SSRF in ssrf (CVE-2025-45869). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59955 |
|
Vulnerability in com.ctrip.framework.apollo:apollo (CVE-2026-59955)
vulnerability in com.ctrip.framework.apollo:apollo (CVE-2026-59955). Confidential information can be exposed externally.
|
| CVE-2026-61462 |
|
Vulnerability in path-traversal (CVE-2026-61462)
vulnerability in path-traversal (CVE-2026-61462). Confidential information can be exposed externally.
|
| CVE-2026-61463 |
|
Privilege Escalation in privilege-escalation (CVE-2026-61463)
vulnerability in privilege-escalation (CVE-2026-61463). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59954 |
|
Vulnerability in com.ctrip.framework.apollo:apollo (CVE-2026-59954)
vulnerability in com.ctrip.framework.apollo:apollo (CVE-2026-59954). Confidential information can be exposed externally.
|
| CVE-2026-57432 |
|
Out-of-Bounds Read in perl (CVE-2026-57432)
vulnerability in perl (CVE-2026-57432). Successful exploitation can lead to full system takeover.
|
| CVE-2026-45414 |
|
Vulnerability in decidim (CVE-2026-45414)
vulnerability in decidim (CVE-2026-45414). Confidential information can be exposed externally. Exploitable via `Host header`. Mitigation: upgrade to `0.32.0` or later.
|
| CVE-2026-45378 |
|
Information Disclosure in decidim-verifications (CVE-2026-45378)
vulnerability in decidim-verifications (CVE-2026-45378). Confidential information can be exposed externally. Exploitable via ``verification_attachment``. Mitigation: upgrade to `0.32.0` or later.
|
| CVE-2026-58065 |
|
Vulnerability in apache (CVE-2026-58065)
vulnerability in apache (CVE-2026-58065). Successful exploitation can lead to full system takeover. Exploitable via ``known_hosts``.
|
| CVE-2026-59245 |
|
Privilege Escalation in apache (CVE-2026-59245)
vulnerability in apache (CVE-2026-59245). Confidential information can be exposed externally. Exploitable via ``dag_id``.
|
| CVE-2026-40553 |
|
Vulnerability in c (CVE-2026-40553)
vulnerability in c (CVE-2026-40553). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-40467 |
|
Use-After-Free in c (CVE-2026-40467)
vulnerability in c (CVE-2026-40467). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15584 |
|
Vulnerability in privilege-escalation (CVE-2026-15584)
vulnerability in privilege-escalation (CVE-2026-15584). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61955 |
|
SQL Injection in sqli (CVE-2026-61955)
SQL injection in sqli (CVE-2026-61955). Confidential information can be exposed externally.
|
| CVE-2026-59521 |
|
Unsafe Deserialization in deserialization (CVE-2026-59521)
vulnerability in deserialization (CVE-2026-59521). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61956 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-61956)
vulnerability in csrf (CVE-2026-61956). Data can be tampered with by attackers.
|
| CVE-2026-59516 |
|
Cross-Site Scripting (XSS) in CVE-2026-59516 (CVE-2026-59516)
cross-site scripting in CVE-2026-59516 (CVE-2026-59516). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57816 |
|
Cross-Site Scripting (XSS) in CVE-2026-57816 (CVE-2026-57816)
cross-site scripting in CVE-2026-57816 (CVE-2026-57816). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57815 |
|
Path Traversal in wordpress (CVE-2026-57815)
path traversal in wordpress (CVE-2026-57815). Confidential information can be exposed externally.
|
| CVE-2026-57814 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-57814)
cross-site scripting in wordpress (CVE-2026-57814). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-57799 |
|
Vulnerability in CVE-2026-57799 (CVE-2026-57799)
vulnerability in CVE-2026-57799 (CVE-2026-57799). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57800 |
|
Vulnerability in CVE-2026-57800 (CVE-2026-57800)
vulnerability in CVE-2026-57800 (CVE-2026-57800). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57802 |
|
Vulnerability in CVE-2026-57802 (CVE-2026-57802)
vulnerability in CVE-2026-57802 (CVE-2026-57802). Successful exploitation can lead to full system takeover.
|