Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| GHSA-58wc-8wrv-xp9j |
|
Vulnerability in openclaw (GHSA-58wc-8wrv-xp9j)
vulnerability in openclaw (GHSA-58wc-8wrv-xp9j). Risk of unauthorized operations or information disclosure.
|
| GHSA-c8w7-9w9h-x69q |
|
Vulnerability in openclaw (GHSA-c8w7-9w9h-x69q)
vulnerability in openclaw (GHSA-c8w7-9w9h-x69q). Risk of unauthorized operations or information disclosure.
|
| GHSA-wrr6-p5r6-474m |
|
Vulnerability in openclaw (GHSA-wrr6-p5r6-474m)
vulnerability in openclaw (GHSA-wrr6-p5r6-474m). Risk of unauthorized operations or information disclosure.
|
| GHSA-6jm4-83g2-35gv |
|
Vulnerability in openclaw (GHSA-6jm4-83g2-35gv)
vulnerability in openclaw (GHSA-6jm4-83g2-35gv). Confidential information can be exposed externally.
|
| GHSA-6xcg-6q43-rj2v |
|
Vulnerability in openclaw (GHSA-6xcg-6q43-rj2v)
vulnerability in openclaw (GHSA-6xcg-6q43-rj2v). Risk of unauthorized operations or information disclosure.
|
| GHSA-wrmq-9fc4-gwwj |
|
Vulnerability in openclaw (GHSA-wrmq-9fc4-gwwj)
vulnerability in openclaw (GHSA-wrmq-9fc4-gwwj). Successful exploitation can lead to full system takeover.
|
| GHSA-9fr2-p65v-gqxq |
|
Vulnerability in openclaw (GHSA-9fr2-p65v-gqxq)
vulnerability in openclaw (GHSA-9fr2-p65v-gqxq). Confidential information can be exposed externally.
|
| GHSA-x7cf-6gp3-q5f8 |
|
Vulnerability in openclaw (GHSA-x7cf-6gp3-q5f8)
vulnerability in openclaw (GHSA-x7cf-6gp3-q5f8). Confidential information can be exposed externally.
|
| CVE-2026-54322 |
|
Vulnerability in github.com/daytonaio/daytona (CVE-2026-54322)
vulnerability in github.com/daytonaio/daytona (CVE-2026-54322). Data can be tampered with by attackers. Mitigation: upgrade to `0.185.0` or later.
|
| CVE-2026-52846 |
|
Vulnerability in github.com/caddyserver/caddy/v2 (CVE-2026-52846)
vulnerability in github.com/caddyserver/caddy/v2 (CVE-2026-52846). Risk of unauthorized operations or information disclosure. Exploitable via ``stripHTML``. Mitigation: upgrade to `2.11.4` or later.
|
| CVE-2026-52845 |
|
Authentication Bypass in github.com/caddyserver/caddy/v2 (CVE-2026-52845)
authentication bypass in github.com/caddyserver/caddy/v2 (CVE-2026-52845). Confidential information can be exposed externally. Exploitable via `GET /index.php`. Mitigation: upgrade to `2.11.4` or later.
|
| CVE-2026-52844 |
|
Path Traversal in github.com/caddyserver/caddy/v2 (CVE-2026-52844)
path traversal in github.com/caddyserver/caddy/v2 (CVE-2026-52844). Confidential information can be exposed externally. Exploitable via `GET /private/secret.txt`. Mitigation: upgrade to `2.11.4` or later.
|
| CVE-2026-50574 |
|
Vulnerability in yt-dlp (CVE-2026-50574)
vulnerability in yt-dlp (CVE-2026-50574). Successful exploitation can lead to full system takeover. Exploitable via ``title``. Mitigation: upgrade to `2026.6.9` or later.
|
| CGA-fjwf-7hq6-qrmv |
|
CGA-fjwf-7hq6-qrmv |
| CVE-2026-54321 |
|
Vulnerability in github.com/daytonaio/daytona (CVE-2026-54321)
vulnerability in github.com/daytonaio/daytona (CVE-2026-54321). Confidential information can be exposed externally. Mitigation: upgrade to `0.184.0` or later.
|
| CVE-2026-53622 |
|
Vulnerability in Traefik (CVE-2026-53622)
vulnerability in Traefik (CVE-2026-53622). Confidential information can be exposed externally. Exploitable via ``Host``. Mitigation: upgrade to `3.7.3` or later.
|
| CVE-2026-53755 |
|
SSRF (Server-Side Request Forgery) in crawl4ai (CVE-2026-53755)
SSRF in crawl4ai (CVE-2026-53755). Confidential information can be exposed externally. Mitigation: upgrade to `0.8.9` or later.
|
| USN-8438-1 |
|
Vulnerability in openimageio (USN-8438-1)
vulnerability in openimageio (USN-8438-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.6.11~dfsg0-1ubuntu1+esm2` or later.
|
| GHSA-7cx2-g3h9-382p |
|
Path Traversal in crawl4ai (GHSA-7cx2-g3h9-382p)
path traversal in crawl4ai (GHSA-7cx2-g3h9-382p). Risk of unauthorized operations or information disclosure. Exploitable via `POST /screenshot`. Mitigation: upgrade to `0.8.8` or later.
|
| GHSA-f989-c77f-r2cq |
|
Information Disclosure in crawl4ai (GHSA-f989-c77f-r2cq)
vulnerability in crawl4ai (GHSA-f989-c77f-r2cq). Risk of unauthorized operations or information disclosure. Exploitable via ``base_url``. Mitigation: upgrade to `0.8.8` or later.
|
| CVE-2026-53754 |
|
SSRF (Server-Side Request Forgery) in crawl4ai (CVE-2026-53754)
SSRF in crawl4ai (CVE-2026-53754). Confidential information can be exposed externally. Mitigation: upgrade to `0.8.8` or later.
|
| CVE-2026-50023 |
|
Vulnerability in yt-dlp (CVE-2026-50023)
vulnerability in yt-dlp (CVE-2026-50023). Successful exploitation can lead to full system takeover. Exploitable via ``master.m3u8``. Mitigation: upgrade to `2026.6.9` or later.
|
| CVE-2026-50019 |
|
Information Disclosure in yt-dlp (CVE-2026-50019)
vulnerability in yt-dlp (CVE-2026-50019). Confidential information can be exposed externally. Exploitable via ``curl``. Mitigation: upgrade to `2026.6.9` or later.
|
| CVE-2026-47750 |
|
Out-of-Bounds Write in c (CVE-2026-47750)
out-of-bounds write in c (CVE-2026-47750). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47747 |
|
Vulnerability in c (CVE-2026-47747)
vulnerability in c (CVE-2026-47747). Successful exploitation can lead to full system takeover.
|
| CVE-2026-54157 |
|
SSRF (Server-Side Request Forgery) in @lobehub/lobehub (CVE-2026-54157)
SSRF in @lobehub/lobehub (CVE-2026-54157). Confidential information can be exposed externally. Exploitable via `POST /webapi/proxy`. Mitigation: upgrade to `2.1.57` or later.
|
| CVE-2026-56266 |
|
Path Traversal in crawl4ai (CVE-2026-56266)
path traversal in crawl4ai (CVE-2026-56266). Confidential information can be exposed externally. Exploitable via ``output_path``. Mitigation: upgrade to `0.8.7` or later.
|
| CVE-2026-53753 |
|
Code Injection in crawl4ai (CVE-2026-53753)
code injection in crawl4ai (CVE-2026-53753). Successful exploitation can lead to full system takeover. Exploitable via `POST /crawl`. Mitigation: upgrade to `0.8.7` or later.
|
| CVE-2026-50135 |
|
Vulnerability in github.com/gohugoio/hugo (CVE-2026-50135)
vulnerability in github.com/gohugoio/hugo (CVE-2026-50135). Confidential information can be exposed externally. Exploitable via ``resources.Get``. Mitigation: upgrade to `0.162.0` or later.
|
| MAL-2026-5926 |
|
Vulnerability in test-copppss (MAL-2026-5926)
vulnerability in test-copppss (MAL-2026-5926). Risk of unauthorized operations or information disclosure. Exploitable via ``preinstall``.
|
| MAL-2026-5923 |
|
Vulnerability in @welcome-onboarding-web/mobile-focus-account-beta-merging (MAL-2026-5923)
vulnerability in @welcome-onboarding-web/mobile-focus-account-beta-merging (MAL-2026-5923). Risk of unauthorized operations or information disclosure.
|
| MAL-2026-5924 |
|
Vulnerability in binproto (MAL-2026-5924)
vulnerability in binproto (MAL-2026-5924). Risk of unauthorized operations or information disclosure. Exploitable via ``fetchLinuxBinary``.
|
| GHSA-4qw9-xmhp-hc7v |
|
Vulnerability in motion-lib (GHSA-4qw9-xmhp-hc7v)
vulnerability in motion-lib (GHSA-4qw9-xmhp-hc7v). Risk of unauthorized operations or information disclosure. Exploitable via ``process``.
|
| MAL-2026-5912 |
|
Vulnerability in js-digest (MAL-2026-5912)
vulnerability in js-digest (MAL-2026-5912). Risk of unauthorized operations or information disclosure. Exploitable via `GET /user`.
|
| GHSA-wqxw-wj7c-pv2x |
|
Vulnerability in pretie_x2 (GHSA-wqxw-wj7c-pv2x)
vulnerability in pretie_x2 (GHSA-wqxw-wj7c-pv2x). Risk of unauthorized operations or information disclosure. Exploitable via ``pretie_x2``.
|
| GHSA-m9g3-3j2m-gf65 |
|
Vulnerability in pretie_x1 (GHSA-m9g3-3j2m-gf65)
vulnerability in pretie_x1 (GHSA-m9g3-3j2m-gf65). Risk of unauthorized operations or information disclosure.
|
| GHSA-f4m6-gffx-m3mq |
|
Vulnerability in nottuff7 (GHSA-f4m6-gffx-m3mq)
vulnerability in nottuff7 (GHSA-f4m6-gffx-m3mq). Risk of unauthorized operations or information disclosure. Exploitable via ``ishowfeet1``.
|
| GHSA-w6gq-6584-67xq |
|
Vulnerability in nottuff23 (GHSA-w6gq-6584-67xq)
vulnerability in nottuff23 (GHSA-w6gq-6584-67xq). Risk of unauthorized operations or information disclosure. Exploitable via ``nottuff1..30``.
|
| GHSA-2gj2-9868-32pf |
|
Vulnerability in nottuff25 (GHSA-2gj2-9868-32pf)
vulnerability in nottuff25 (GHSA-2gj2-9868-32pf). Risk of unauthorized operations or information disclosure. Exploitable via ``sw.js``.
|
| GHSA-r54f-vpj7-r35g |
|
Vulnerability in nottuff4 (GHSA-r54f-vpj7-r35g)
vulnerability in nottuff4 (GHSA-r54f-vpj7-r35g). Risk of unauthorized operations or information disclosure.
|
| GHSA-pvm5-2r8w-jpqq |
|
Vulnerability in nottuff15 (GHSA-pvm5-2r8w-jpqq)
vulnerability in nottuff15 (GHSA-pvm5-2r8w-jpqq). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-50134 |
|
SSRF (Server-Side Request Forgery) in github.com/gohugoio/hugo (CVE-2026-50134)
SSRF in github.com/gohugoio/hugo (CVE-2026-50134). Risk of unauthorized operations or information disclosure. Exploitable via ``security.http.urls``. Mitigation: upgrade to `0.162.0` or later.
|
| CVE-2026-50133 |
|
Cross-Site Scripting (XSS) in github.com/gohugoio/hugo (CVE-2026-50133)
cross-site scripting in github.com/gohugoio/hugo (CVE-2026-50133). Risk of unauthorized operations or information disclosure. Exploitable via ``security.allowContent``. Mitigation: upgrade to `0.162.0` or later.
|
| USN-8412-2 |
|
Vulnerability in qemu (USN-8412-2)
vulnerability in qemu (USN-8412-2). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1:2.11+dfsg-1ubuntu7.42+esm6` or later.
|
| CVE-2026-53866 |
|
OpenClaw: Shell inline-command parsing could miss an allowlist check
OpenClaw: Shell inline-command parsing could miss an allowlist check
|
| CVE-2026-53865 |
|
Vulnerability in openclaw (CVE-2026-53865)
vulnerability in openclaw (CVE-2026-53865). Confidential information can be exposed externally. Exploitable via ``trash``. Mitigation: upgrade to `2026.5.2` or later.
|
| CVE-2026-53864 |
|
OpenClaw: Host environment sanitizer missed two Node.js control variables
OpenClaw: Host environment sanitizer missed two Node.js control variables
|
| CVE-2026-53863 |
|
Vulnerability in openclaw (CVE-2026-53863)
vulnerability in openclaw (CVE-2026-53863). Data can be tampered with by attackers. Mitigation: upgrade to `2026.4.25` or later.
|
| CVE-2026-53862 |
|
Privilege Escalation in openclaw (CVE-2026-53862)
vulnerability in openclaw (CVE-2026-53862). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2026.5.12` or later.
|
| CVE-2026-53861 |
|
Vulnerability in openclaw (CVE-2026-53861)
vulnerability in openclaw (CVE-2026-53861). Confidential information can be exposed externally. Mitigation: upgrade to `2026.5.6` or later.
|