Total CVEs

140,373

Critical Severity

3,747

High Severity

13,527

Last 7 Days

1,782
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 9,701 - 9,720 of 13,224 CVEs
CVE-2026-28468 HIGH - 7.8

OpenClaw versions 2026.1.29-beta.1 prior to 2026.2.14 contain a vulnerability in the sandbox browser bridge server in which it accepts requests without requiring gateway authentication, allowing local attackers to access browser control endpoints. A local attacker can enumerate tabs, retrieve WebSoc...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 05, 2026
Source: NVD
CVE-2026-28466 HIGH - 8.8

OpenClaw versions prior to 2026.2.14 contain a vulnerability in the gateway in which it fails to sanitize internal approval fields in node.invoke parameters, allowing authenticated clients to bypass exec approval gating for system.run commands. Attackers with valid gateway credentials can inject app...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 05, 2026
Source: NVD
CVE-2026-28465 HIGH - 7.5

OpenClaw's voice-call plugin versions before 2026.2.3 contain an improper authentication vulnerability in webhook verification that allows remote attackers to bypass verification by supplying untrusted forwarded headers. Attackers can spoof webhook events by manipulating Forwarded or X-Forwarde...

Vendor: OpenClaw
Product: voice-call
Published: Mar 05, 2026
Source: NVD
CVE-2026-28463 HIGH - 8.4

OpenClaw exec-approvals allowlist validation checks pre-expansion argv tokens but execution uses real shell expansion, allowing safe bins like head, tail, or grep to read arbitrary local files via glob patterns or environment variables. Authorized callers or prompt-injection attacks can exploit this...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 05, 2026
Source: NVD
CVE-2026-28462 HIGH - 7.5

OpenClaw versions prior to 2026.2.13 contain a vulnerability in the browser control API in which it accepts user-supplied output paths for trace and download files without consistently constraining writes to temporary directories. Attackers with API access can exploit path traversal in POST /trace/s...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 05, 2026
Source: NVD
CVE-2026-28458 HIGH - 7.5

OpenClaw version 2026.1.20 prior to 2026.2.1 contains a vulnerability in the Browser Relay (extension must be installed and enabled) /cdp WebSocket endpoint in which it does not require authentication tokens, allowing websites to connect via loopback and access sensitive data. Attackers can exploit ...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 05, 2026
Source: NVD
CVE-2026-28456 HIGH - 8.4

OpenClaw versions 2026.1.5 prior to 2026.2.14 contain a vulnerability in the Gateway in which it does not sufficiently constrain configured hook module paths before passing them to dynamic import(), allowing code execution. An attacker with gateway configuration modification access can load and exec...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 05, 2026
Source: NVD
CVE-2026-28453 HIGH - 7.5

OpenClaw versions prior to 2026.2.14 fail to validate TAR archive entry paths during extraction, allowing path traversal sequences to write files outside the intended directory. Attackers can craft malicious archives with traversal sequences like ../../ to write files outside extraction boundaries, ...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 05, 2026
Source: NVD
CVE-2026-28447 HIGH - 7.5

OpenClaw versions 2026.1.29-beta.1 prior to 2026.2.1 contain a path traversal vulnerability in plugin installation that allows malicious plugin package names to escape the extensions directory. Attackers can craft scoped package names containing path traversal sequences like .. to write files outsid...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 05, 2026
Source: NVD
CVE-2026-28393 HIGH - 7.5

OpenClaw versions 2.0.0-beta3 prior to 2026.2.14 contain a path traversal vulnerability in hook transform module loading that allows arbitrary JavaScript execution. The hooks.mappings[].transform.module parameter accepts absolute paths and traversal sequences, enabling attackers with configuration w...

Vendor: OpenClaw
Product: OpenClaw
Published: Mar 05, 2026
Source: NVD
CVE-2026-30247 HIGH - 7.5

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, the application's "Import document via URL" feature is vulnerable to Server-Side Request Forgery (SSRF) through HTTP redirects. While the backend implements co...

Vendor: go
Product: github.com/Tencent/WeKnora
Published: Mar 05, 2026
Source: GitHub
CVE-2026-30244 HIGH - 7.5

Plane is an an open-source project management tool. Prior to version 1.2.2, unauthenticated attackers can enumerate workspace members and extract sensitive information including email addresses, user roles, and internal identifiers. The vulnerability stems from Django REST Framework permission class...

Vendor: pip
Product: plane
Published: Mar 05, 2026
Source: GitHub
CVE-2026-30242 HIGH - 8.5

Plane is an an open-source project management tool. Prior to version 1.2.3, the webhook URL validation in plane/app/serializers/webhook.py only checks ip.is_loopback, allowing attackers with workspace ADMIN role to create webhooks pointing to private/internal network addresses (10.x.x.x, 172.16.x.x,...

Vendor: pip
Product: plane
Published: Mar 05, 2026
Source: GitHub
CVE-2026-29077 HIGH - 7.1

Frappe is a full-stack web application framework. Prior to versions 15.98.0 and 14.100.0, due to a lack of validation when sharing documents, a user could share a document with a permission that they themselves didn't have. This issue has been patched in versions 15.98.0 and 14.100.0.

Vendor: frappe
Product: frappe
Published: Mar 05, 2026
Source: NVD
CVE-2026-28442 HIGH - 8.5

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.2-beta3, users are restricted from deleting internal system files or folders through the application interface. However, when interacting directly with the API, these restrictions can be byp...

Vendor: IceWhaleTech
Product: ZimaOS
Published: Mar 05, 2026
Source: NVD
CVE-2026-28436 HIGH - 7.2

Frappe is a full-stack web application framework. Prior to versions 16.11.0 and 15.102.0, an attacker can set a crafted image URL that results in XSS when the avatar is displayed, and it can be triggered for other users via website page comments. This issue has been patched in versions 16.11.0 and 1...

Vendor: frappe
Product: frappe
Published: Mar 05, 2026
Source: NVD
CVE-2026-28410 HIGH - 8.1

The Graph is an indexing protocol for querying networks like Ethereum, IPFS, Polygon, and other blockchains. Prior to version 3.0.0, a flaw in the token vesting contracts allows users to access tokens that should still be locked according to their vesting schedule. This issue has been patched in ver...

Vendor: graphprotocol
Product: contracts
Published: Mar 05, 2026
Source: NVD
CVE-2026-28405 HIGH - 8.0

MarkUs is a web application for the submission and grading of student assignments. Prior to version 2.9.1, the courses/<:course_id>/assignments/<:assignment_id>/submissions/html_content route reads the contents of a student-submitted file and renders them without sanitization. This issue...

Vendor: MarkUsProject
Product: Markus
Published: Mar 05, 2026
Source: NVD
CVE-2025-70995 HIGH - 8.8

An issue in Aranda Service Desk Web Edition (ASDK API 8.6) allows authenticated attackers to achieve remote code execution due to improper validation of uploaded files. An authenticated user can upload a crafted web.config file by sending a crafted POST request to /ASDKAPI/api/v8.6/item/addfile, whi...

Published: Mar 05, 2026
Source: NVD
CVE-2025-70949 HIGH - 7.5

An observable timing discrepancy in @perfood/couch-auth v0.26.0 allows attackers to access sensitive information via a timing side-channel.

Vendor: npm
Product: @perfood/couch-auth
Published: Mar 05, 2026
Source: NVD