Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-32846 Path Traversal in openclaw (CVE-2026-32846)
path traversal in openclaw (CVE-2026-32846). Confidential information can be exposed externally. Mitigation: upgrade to `2026.03.28` or later.
CVE-2026-1961 OS Command Injection in CVE-2026-1961 (CVE-2026-1961)
OS command injection in CVE-2026-1961 (CVE-2026-1961). Successful exploitation can lead to full system takeover.
CVE-2026-24068 Vulnerability in privilege-escalation (CVE-2026-24068)
vulnerability in privilege-escalation (CVE-2026-24068). Successful exploitation can lead to full system takeover.
CVE-2026-23397 Out-of-Bounds Read in Kernel (CVE-2026-23397)
vulnerability in Kernel (CVE-2026-23397). Confidential information can be exposed externally. Mitigation: upgrade to `6.1.167, 6.6.130, 6.12.78, 6.18.20, 6.19.10` or later.
CVE-2026-28760 Vulnerability in CVE-2026-28760 (CVE-2026-28760)
vulnerability in CVE-2026-28760 (CVE-2026-28760). Successful exploitation can lead to full system takeover.
CVE-2026-32680 Vulnerability in CVE-2026-32680 (CVE-2026-32680)
vulnerability in CVE-2026-32680 (CVE-2026-32680). Successful exploitation can lead to full system takeover.
CVE-2025-15101 OS Command Injection in asus (CVE-2025-15101)
OS command injection in asus (CVE-2025-15101). Successful exploitation can lead to full system takeover.
CVE-2026-33526 Use-After-Free in dos (CVE-2026-33526)
vulnerability in dos (CVE-2026-33526). Risk of unauthorized operations or information disclosure. Exploitable via ``icp_port``.
CVE-2026-32748 Vulnerability in dos (CVE-2026-32748)
vulnerability in dos (CVE-2026-32748). Risk of unauthorized operations or information disclosure. Exploitable via ``icp_port``.
CVE-2026-33634 KEV [KEV] Vulnerability in github.com/aquasecurity/trivy (CVE-2026-33634)
vulnerability in github.com/aquasecurity/trivy (CVE-2026-33634). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited. Mitigation: upgrade to `0.35.0` or later.
CVE-2026-33247 Vulnerability in nats (CVE-2026-33247)
vulnerability in nats (CVE-2026-33247). Confidential information can be exposed externally. Mitigation: upgrade to `2.11.15, 2.12.6` or later.
CVE-2026-33216 Vulnerability in nats (CVE-2026-33216)
vulnerability in nats (CVE-2026-33216). Confidential information can be exposed externally. Mitigation: upgrade to `2.11.15, 2.12.6` or later.
CVE-2026-33217 Authorization Flaw in nats (CVE-2026-33217)
vulnerability in nats (CVE-2026-33217). Data can be tampered with by attackers. Mitigation: upgrade to `2.11.15, 2.12.6` or later.
CVE-2026-33218 Vulnerability in nats (CVE-2026-33218)
vulnerability in nats (CVE-2026-33218). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.11.15, 2.12.6` or later.
CVE-2026-29785 Vulnerability in nats (CVE-2026-29785)
vulnerability in nats (CVE-2026-29785). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.11.14, 2.12.5` or later.
CVE-2026-27889 Vulnerability in nats (CVE-2026-27889)
vulnerability in nats (CVE-2026-27889). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.11.14, 2.12.5` or later.
CVE-2026-30587 Cross-Site Scripting (XSS) in seafile (CVE-2026-30587)
cross-site scripting in seafile (CVE-2026-30587). Confidential information can be exposed externally. Mitigation: upgrade to `13.0.17` or later.
CVE-2025-67030 Path Traversal in path-traversal (CVE-2025-67030)
path traversal in path-traversal (CVE-2025-67030). Successful exploitation can lead to full system takeover.
CVE-2026-3104 Vulnerability in isc (CVE-2026-3104)
vulnerability in isc (CVE-2026-3104). Risk of unauthorized operations or information disclosure.
CVE-2026-1519 Vulnerability in isc (CVE-2026-1519)
vulnerability in isc (CVE-2026-1519). Risk of unauthorized operations or information disclosure.
CVE-2026-28529 Use-After-Free in privilege-escalation (CVE-2026-28529)
vulnerability in privilege-escalation (CVE-2026-28529). Successful exploitation can lead to full system takeover.
CVE-2024-51348 Vulnerability in CVE-2024-51348 (CVE-2024-51348)
vulnerability in CVE-2024-51348 (CVE-2024-51348). Successful exploitation can lead to full system takeover.
CVE-2026-23288 Out-of-Bounds Read in linux (CVE-2026-23288)
vulnerability in linux (CVE-2026-23288). Successful exploitation can lead to full system takeover.
CVE-2026-23364 Vulnerability in linux (CVE-2026-23364)
vulnerability in linux (CVE-2026-23364). Confidential information can be exposed externally.
CVE-2026-23327 Out-of-Bounds Read in c (CVE-2026-23327)
vulnerability in c (CVE-2026-23327). Confidential information can be exposed externally.
CVE-2026-23319 Use-After-Free in linux (CVE-2026-23319)
vulnerability in linux (CVE-2026-23319). Successful exploitation can lead to full system takeover.
CVE-2026-23306 Use-After-Free in Kernel (CVE-2026-23306)
vulnerability in Kernel (CVE-2026-23306). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `6.1.167, 6.6.130, 6.12.77, 6.18.17, 6.19.7` or later.
CVE-2026-23305 Out-of-Bounds Read in linux (CVE-2026-23305)
vulnerability in linux (CVE-2026-23305). Confidential information can be exposed externally.
CVE-2026-23294 Vulnerability in linux (CVE-2026-23294)
vulnerability in linux (CVE-2026-23294). Successful exploitation can lead to full system takeover.
CVE-2026-23280 Vulnerability in linux (CVE-2026-23280)
vulnerability in linux (CVE-2026-23280). Successful exploitation can lead to full system takeover.
CVE-2026-23281 Use-After-Free in linux (CVE-2026-23281)
vulnerability in linux (CVE-2026-23281). Successful exploitation can lead to full system takeover.
CVE-2026-23392 Use-After-Free in Kernel (CVE-2026-23392)
vulnerability in Kernel (CVE-2026-23392). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `6.1.167, 6.6.130, 6.12.78, 6.18.20, 6.19.10` or later.
CVE-2026-23391 Vulnerability in Kernel (CVE-2026-23391)
vulnerability in Kernel (CVE-2026-23391). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `6.1.167, 6.6.130, 6.12.78, 6.18.20, 6.19.10` or later.
CVE-2026-23378 Out-of-Bounds Write in Kernel (CVE-2026-23378)
out-of-bounds write in Kernel (CVE-2026-23378). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `6.1.167, 6.6.130, 6.12.77, 6.18.17, 6.19.7` or later.
CVE-2026-23359 Out-of-Bounds Write in Kernel (CVE-2026-23359)
out-of-bounds write in Kernel (CVE-2026-23359). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `6.1.167, 6.6.130, 6.12.77, 6.18.17, 6.19.7` or later.
CVE-2026-23351 Use-After-Free in Kernel (CVE-2026-23351)
vulnerability in Kernel (CVE-2026-23351). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `6.1.167, 6.6.130, 6.12.77, 6.18.17, 6.19.7` or later.
CVE-2026-23343 Out-of-Bounds Write in Kernel (CVE-2026-23343)
out-of-bounds write in Kernel (CVE-2026-23343). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `6.1.167, 6.6.130, 6.12.77, 6.18.17, 6.19.7` or later.
CVE-2026-23340 Use-After-Free in Kernel (CVE-2026-23340)
vulnerability in Kernel (CVE-2026-23340). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `6.1.167, 6.6.130, 6.12.77, 6.18.17, 6.19.7` or later.
CVE-2026-3608 Vulnerability in CVE-2026-3608 (CVE-2026-3608)
vulnerability in CVE-2026-3608 (CVE-2026-3608). Risk of unauthorized operations or information disclosure.
CVE-2026-2072 Cross-Site Scripting (XSS) in hitachi (CVE-2026-2072)
cross-site scripting in hitachi (CVE-2026-2072). Confidential information can be exposed externally.
CVE-2026-20622 Vulnerability in apple (CVE-2026-20622)
vulnerability in apple (CVE-2026-20622). Confidential information can be exposed externally.
CVE-2026-4371 Vulnerability in mozilla (CVE-2026-4371)
vulnerability in mozilla (CVE-2026-4371). Confidential information can be exposed externally.
CVE-2026-33331 Cross-Site Scripting (XSS) in orpc (CVE-2026-33331)
cross-site scripting in orpc (CVE-2026-33331). Confidential information can be exposed externally.
CVE-2026-1995 In versions before 7.0.0.64, IDrive’s id_service.exe process runs with elevated privileges and regularly reads from several files under the C:\ProgramData\IDrive\ directory. The UTF16-LE encoded conte...
In versions before 7.0.0.64, IDrive’s id_service.exe process runs with elevated privileges and regularly reads from several files under the C:\ProgramData\IDrive\ directory. The UTF16-LE encoded contents of these files are used as arguments for starting a process, but they can be edited by any stand...
CVE-2026-32853 Out-of-Bounds Read in libvncserver-project (CVE-2026-32853)
vulnerability in libvncserver-project (CVE-2026-32853). Confidential information can be exposed externally.
CVE-2026-32854 Vulnerability in c (CVE-2026-32854)
vulnerability in c (CVE-2026-32854). Risk of unauthorized operations or information disclosure.
CVE-2026-27651 Vulnerability in nginx-gateway (CVE-2026-27651)
vulnerability in nginx-gateway (CVE-2026-27651). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.28.3, 1.29.7` or later.
CVE-2026-27784 Vulnerability in nginx-gateway (CVE-2026-27784)
vulnerability in nginx-gateway (CVE-2026-27784). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.28.3, 1.29.7` or later.
CVE-2026-27654 Vulnerability in nginx (CVE-2026-27654)
vulnerability in nginx (CVE-2026-27654). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.28.3, 1.29.7` or later.
CVE-2026-32647 Out-of-Bounds Read in nginx-gateway (CVE-2026-32647)
vulnerability in nginx-gateway (CVE-2026-32647). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.28.3, 1.29.7` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →