Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-62205 |
|
Vulnerability in openclaw (CVE-2026-62205)
vulnerability in openclaw (CVE-2026-62205). Data can be tampered with by attackers. Mitigation: upgrade to `2026.6.6` or later.
|
| CVE-2026-62203 |
|
Vulnerability in openclaw (CVE-2026-62203)
vulnerability in openclaw (CVE-2026-62203). Successful exploitation can lead to full system takeover.
|
| CVE-2026-62201 |
|
SSRF (Server-Side Request Forgery) in openclaw (CVE-2026-62201)
SSRF in openclaw (CVE-2026-62201). Confidential information can be exposed externally.
|
| CVE-2026-62202 |
|
Authorization Flaw in privilege-escalation (CVE-2026-62202)
vulnerability in privilege-escalation (CVE-2026-62202). Successful exploitation can lead to full system takeover.
|
| CVE-2026-62206 |
|
Vulnerability in openclaw (CVE-2026-62206)
vulnerability in openclaw (CVE-2026-62206). Data can be tampered with by attackers.
|
| CVE-2026-34150 |
|
Vulnerability in wazuh (CVE-2026-34150)
vulnerability in wazuh (CVE-2026-34150). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54340 |
|
Vulnerability in h2o (CVE-2026-54340)
vulnerability in h2o (CVE-2026-54340). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-39359 |
|
Path Traversal in path-traversal (CVE-2026-39359)
path traversal in path-traversal (CVE-2026-39359). Confidential information can be exposed externally.
|
| CVE-2026-44435 |
|
Vulnerability in dos (CVE-2026-44435)
vulnerability in dos (CVE-2026-44435). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44436 |
|
Vulnerability in dos (CVE-2026-44436)
vulnerability in dos (CVE-2026-44436). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44453 |
|
Vulnerability in dos (CVE-2026-44453)
vulnerability in dos (CVE-2026-44453). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-59117 |
|
Vulnerability in microsoft (CVE-2026-59117)
vulnerability in microsoft (CVE-2026-59117). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58598 |
|
Vulnerability in microsoft (CVE-2026-58598)
vulnerability in microsoft (CVE-2026-58598). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57077 |
|
Out-of-Bounds Read in CVE-2026-57077 (CVE-2026-57077)
vulnerability in CVE-2026-57077 (CVE-2026-57077). Confidential information can be exposed externally.
|
| CVE-2026-57076 |
|
Use-After-Free in CVE-2026-57076 (CVE-2026-57076)
vulnerability in CVE-2026-57076 (CVE-2026-57076). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53411 |
|
Vulnerability in zoom (CVE-2026-53411)
vulnerability in zoom (CVE-2026-53411). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53409 |
|
Vulnerability in zoom (CVE-2026-53409)
vulnerability in zoom (CVE-2026-53409). Successful exploitation can lead to full system takeover.
|
| CVE-2026-53410 |
|
Vulnerability in zoom (CVE-2026-53410)
vulnerability in zoom (CVE-2026-53410). Successful exploitation can lead to full system takeover.
|
| CVE-2024-34268 |
|
Vulnerability in CVE-2024-34268 (CVE-2024-34268)
vulnerability in CVE-2024-34268 (CVE-2024-34268). Data can be tampered with by attackers.
|
| CVE-2024-32386 |
|
Path Traversal in path-traversal (CVE-2024-32386)
path traversal in path-traversal (CVE-2024-32386). Confidential information can be exposed externally.
|
| CVE-2026-62309 |
|
Vulnerability in corednsio (CVE-2026-62309)
vulnerability in corednsio (CVE-2026-62309). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62290 |
|
Authorization Flaw in linuxfoundation (CVE-2026-62290)
vulnerability in linuxfoundation (CVE-2026-62290). Confidential information can be exposed externally. Exploitable via `X-API-Key header`.
|
| CVE-2026-61389 |
|
Out-of-Bounds Write in privilege-escalation (CVE-2026-61389)
out-of-bounds write in privilege-escalation (CVE-2026-61389). Successful exploitation can lead to full system takeover.
|
| CVE-2026-60063 |
|
Out-of-Bounds Write in privilege-escalation (CVE-2026-60063)
out-of-bounds write in privilege-escalation (CVE-2026-60063). Successful exploitation can lead to full system takeover.
|
| CVE-2026-55578 |
|
OS Command Injection in pheditor/pheditor (CVE-2026-55578)
OS command injection in pheditor/pheditor (CVE-2026-55578). Successful exploitation can lead to full system takeover. Exploitable via ``terminal``. Mitigation: upgrade to `2.0.6` or later.
|
| CVE-2026-54540 |
|
OS Command Injection in pheditor/pheditor (CVE-2026-54540)
OS command injection in pheditor/pheditor (CVE-2026-54540). Successful exploitation can lead to full system takeover. Exploitable via ``TERMINAL_COMMANDS``. Mitigation: upgrade to `2.0.5` or later.
|
| CVE-2026-46513 |
|
Vulnerability in CVE-2026-46513 (CVE-2026-46513)
vulnerability in CVE-2026-46513 (CVE-2026-46513). Confidential information can be exposed externally.
|
| CVE-2026-46353 |
|
Vulnerability in CVE-2026-46353 (CVE-2026-46353)
vulnerability in CVE-2026-46353 (CVE-2026-46353). Confidential information can be exposed externally.
|
| CVE-2026-46351 |
|
Vulnerability in CVE-2026-46351 (CVE-2026-46351)
vulnerability in CVE-2026-46351 (CVE-2026-46351). Confidential information can be exposed externally.
|
| CVE-2026-46336 |
|
Path Traversal in path-traversal (CVE-2026-46336)
path traversal in path-traversal (CVE-2026-46336). Data can be tampered with by attackers.
|
| CVE-2021-27137 KEV |
|
[KEV] Vulnerability in Dd-wrt c (CVE-2021-27137)
vulnerability in Dd-wrt c (CVE-2021-27137). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
|
| CVE-2026-9046 |
|
Vulnerability in CVE-2026-9046 (CVE-2026-9046)
vulnerability in CVE-2026-9046 (CVE-2026-9046). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63088 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-63088)
SSRF in ssrf (CVE-2026-63088). Confidential information can be exposed externally.
|
| CVE-2026-63085 |
|
Authorization Flaw in CVE-2026-63085 (CVE-2026-63085)
vulnerability in CVE-2026-63085 (CVE-2026-63085). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63086 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-63086)
SSRF in ssrf (CVE-2026-63086). Confidential information can be exposed externally.
|
| CVE-2026-13401 |
|
Vulnerability in c (CVE-2026-13401)
vulnerability in c (CVE-2026-13401). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13397 |
|
Vulnerability in c (CVE-2026-13397)
vulnerability in c (CVE-2026-13397). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13104 |
|
Vulnerability in CVE-2026-13104 (CVE-2026-13104)
vulnerability in CVE-2026-13104 (CVE-2026-13104). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13103 |
|
Path Traversal in path-traversal (CVE-2026-13103)
path traversal in path-traversal (CVE-2026-13103). Successful exploitation can lead to full system takeover.
|
| CVE-2026-59867 |
|
Path Traversal in Microsoft.OpenApi.Kiota (CVE-2026-59867)
path traversal in Microsoft.OpenApi.Kiota (CVE-2026-59867). Confidential information can be exposed externally. Exploitable via ``REMOTE_KIOTA_PROP``. Mitigation: upgrade to `1.29.1` or later.
|
| CVE-2026-57206 |
|
Vulnerability in CVE-2026-57206 (CVE-2026-57206)
vulnerability in CVE-2026-57206 (CVE-2026-57206). Data can be tampered with by attackers. Exploitable via `POST /api/admin/plugins/test-instantiation`.
|
| CVE-2026-53598 |
|
Path Traversal in prompty (CVE-2026-53598)
path traversal in prompty (CVE-2026-53598). Confidential information can be exposed externally. Exploitable via ``prompty``. Mitigation: upgrade to `2.0.0b2` or later.
|
| CVE-2025-45868 |
|
SQL Injection in sqli (CVE-2025-45868)
SQL injection in sqli (CVE-2025-45868). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15352 |
|
Vulnerability in cisa (CVE-2026-15352)
vulnerability in cisa (CVE-2026-15352). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-5674 |
|
Vulnerability in CVE-2026-5674 (CVE-2026-5674)
vulnerability in CVE-2026-5674 (CVE-2026-5674). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63305 |
|
OS Command Injection in CVE-2026-63305 (CVE-2026-63305)
OS command injection in CVE-2026-63305 (CVE-2026-63305). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63304 |
|
OS Command Injection in CVE-2026-63304 (CVE-2026-63304)
OS command injection in CVE-2026-63304 (CVE-2026-63304). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63306 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-63306 (CVE-2026-63306)
SSRF in CVE-2026-63306 (CVE-2026-63306). Confidential information can be exposed externally.
|
| CVE-2026-59862 |
|
Code Injection in Microsoft.OpenAPI.Kiota (CVE-2026-59862)
code injection in Microsoft.OpenAPI.Kiota (CVE-2026-59862). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.29.1` or later.
|
| CVE-2026-59861 |
|
Code Injection in Microsoft.OpenAPI.Kiota (CVE-2026-59861)
code injection in Microsoft.OpenAPI.Kiota (CVE-2026-59861). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.29.1` or later.
|