Total CVEs

142,027

Critical Severity

3,943

High Severity

14,108

Last 7 Days

1,724
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 15,481 - 15,500 of 38,432 CVEs
CVE-2026-7833 HIGH - 7.2

A weakness has been identified in EFM ipTIME C200 up to 1.092. This vulnerability affects the function sub_408F90 of the file /cgi/iux_set.cgi of the component ApplyRestore Endpoint. This manipulation of the argument RestoreFile causes command injection. The attack can be initiated remotely. The exp...

Published: May 05, 2026
Source: NVD
CVE-2026-7832 HIGH - 7.0

A security flaw has been discovered in IObit Advanced SystemCare 19. This affects an unknown part of the file ASC.exe of the component Service. The manipulation results in symlink following. Attacking locally is a requirement. This attack is characterized by high complexity. It is indicated that the...

Published: May 05, 2026
Source: NVD
CVE-2026-6918 HIGH - 7.5

In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte crafted TCP message.

Vendor: eclipse
Product: openj9
Published: May 05, 2026
Source: NVD
CVE-2026-28510 MEDIUM - 5.9

eLabFTW is an open source electronic lab notebook. In elabftw versions through 5.4.1, the login flow did not reliably preserve the multi-factor authentication state across authentication steps. Under certain conditions, an attacker with valid primary credentials could complete authentication with an...

Vendor: elabftw
Product: elabftw
Published: May 05, 2026
Source: NVD
CVE-2026-27694 MEDIUM - 5.4

Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the email notification templates insert user-controlled device, geofence, and driver names into HTML email output without proper escaping. An attacker with low privileges can store crafte...

Vendor: traccar
Product: traccar
Published: May 05, 2026
Source: NVD
CVE-2026-27693 MEDIUM - 5.4

Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the KML and GPX export functionality writes device names to XML output without proper escaping. An attacker with low privileges can create a device with a crafted name that injects XML co...

Vendor: traccar
Product: traccar
Published: May 05, 2026
Source: NVD
CVE-2026-27644 MEDIUM - 6.5

Traccar is an open source GPS tracking system. In versions between 6.11.1 and 6.13.0, the CSV export functionality writes position data, including user-controlled device and computed attributes, to CSV output without proper escaping. An attacker can inject spreadsheet formulas through exported field...

Vendor: traccar
Product: traccar
Published: May 05, 2026
Source: NVD
CVE-2026-6262 MEDIUM - 6.5

The Betheme theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 28.4. This is due to the upload_icons() function workflow using a user-controlled upload path (`mfn-icon-upload`) in a filesystem move operation without constraining it to the uploads directory...

Published: May 05, 2026
Source: NVD
CVE-2026-6261 HIGH - 8.8

The Betheme theme for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 28.4. This is due to the upload_icons() function workflow moving and unzipping user-controlled ZIP files into a public uploads directory without validating extracted file types. This makes it pos...

Published: May 05, 2026
Source: NVD
CVE-2026-43574 MEDIUM - 6.5

OpenClaw before 2026.4.12 contains an improper authorization vulnerability in helper-backed channels where empty resolved approver lists are interpreted as explicit approval authorization. Attackers can resolve pending approvals without proper authorization by exploiting this logic flaw if they know...

Vendor: OpenClaw
Product: OpenClaw
Published: May 05, 2026
Source: NVD
CVE-2026-43573 HIGH - 7.7

OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in existing-session browser interaction routes. Attackers can bypass SSRF navigation guards to interact with or navigate to unauthorized targets without policy enforcement.

Vendor: OpenClaw
Product: OpenClaw
Published: May 05, 2026
Source: NVD
CVE-2026-43572 MEDIUM - 5.3

OpenClaw versions 2026.4.10 before 2026.4.14 contain a missing authorization vulnerability in the Microsoft Teams SSO invoke handler that fails to apply sender allowlist checks. Attackers can bypass sender authorization by sending SSO invoke requests that are processed without proper validation, all...

Vendor: OpenClaw
Product: OpenClaw
Published: May 05, 2026
Source: NVD
CVE-2026-43571 HIGH - 8.8

OpenClaw before 2026.4.10 contains a plugin trust bypass vulnerability that allows channel setup catalog lookups to resolve workspace plugin shadows before bundled channel plugins. Attackers can exploit this by crafting malicious workspace plugins that bypass intended trust gates during setup-time p...

Vendor: OpenClaw
Product: OpenClaw
Published: May 05, 2026
Source: NVD
CVE-2026-43570 MEDIUM - 6.5

OpenClaw versions 2026.3.22 before 2026.4.5 contain a symlink traversal vulnerability in remote marketplace repository path handling that allows attackers to escape the expected repository root. Attackers can exploit this by providing crafted symlink paths to access files outside the intended reposi...

Vendor: OpenClaw
Product: OpenClaw
Published: May 05, 2026
Source: NVD
CVE-2026-43569 HIGH - 8.8

OpenClaw before 2026.4.9 contains an authentication bypass vulnerability allowing untrusted workspace plugins to be auto-enabled during non-interactive onboarding when provider auth choices are shadowed. Attackers can exploit this by crafting malicious workspace plugins that are automatically select...

Vendor: OpenClaw
Product: OpenClaw
Published: May 05, 2026
Source: NVD
CVE-2026-43568 MEDIUM - 6.5

OpenClaw versions 2026.4.5 before 2026.4.10 contain a privilege escalation vulnerability allowing write-scoped operators to modify persistent memory dreaming settings. Attackers with write-scoped gateway access can toggle admin-class configuration mutations through the /dreaming endpoint to escalate...

Vendor: OpenClaw
Product: OpenClaw
Published: May 05, 2026
Source: NVD
CVE-2026-43567 MEDIUM - 6.5

OpenClaw before 2026.4.10 contains a path traversal vulnerability in the screen_record tool's outPath parameter that bypasses workspace-only filesystem guards. Attackers can exploit this by specifying an outPath outside the workspace boundary to write files to unintended locations on the system...

Vendor: OpenClaw
Product: OpenClaw
Published: May 05, 2026
Source: NVD
CVE-2026-43566 CRITICAL - 9.1

OpenClaw versions 2026.4.7 before 2026.4.14 contain a privilege escalation vulnerability where heartbeat owner downgrade logic skips webhook wake events carrying untrusted content. Attackers can exploit this by sending untrusted webhook wake events to preserve owner-like execution context when the r...

Vendor: OpenClaw
Product: OpenClaw
Published: May 05, 2026
Source: NVD
CVE-2026-43535 MEDIUM - 6.8

OpenClaw before 2026.4.14 contains an authorization context reuse vulnerability in collect-mode queue batches that allows messages from different senders to inherit the final sender's authorization context. Attackers can exploit this by sending multiple queued messages to drain batches using a ...

Vendor: OpenClaw
Product: OpenClaw
Published: May 05, 2026
Source: NVD
CVE-2026-43534 CRITICAL - 9.1

OpenClaw before 2026.4.10 contains an input validation vulnerability that allows external hook metadata to be enqueued as trusted system events. Attackers can supply malicious hook names to escalate untrusted input into higher-trust agent context.

Vendor: OpenClaw
Product: OpenClaw
Published: May 05, 2026
Source: NVD