CVE-2020-7796
Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Saturday's vulnerability disclosures highlight significant risks across EV charging infrastructure, video-sharing platforms, and enterprise collaboration tools. The day brought 13 critical CVEs, a 59% decrease from the prior day's 32, alongside 100 high-priority vulnerabilities holding steady. Multiple OCPP charging infrastructure flaws (CVE-2026-22552, CVE-2026-26051, CVE-2026-26288) scored 9.4 CVSS, while CVE-2026-29058 affecting AVideo scored 9.8 and CVE-2026-2446 targeting a WordPress plugin also reached 9.8. Attack patterns span remote code execution and authentication bypass across HP applications, SiYuan, and Chamilo LMS, with 15 actively exploited vulnerabilities including flaws in Zimbra, GitLab, Roundcube Webmail, and VMware Aria Operations. No patches are currently available for disclosed vulnerabilities, requiring organizations to prioritize compensating controls and network segmentation.
Immediate action: Organizations using OCPP-based EV charging infrastructure, AVideo, WordPress, and Chamilo LMS should implement network segmentation and access restrictions immediately as no patches are available. Review exposure to actively exploited vulnerabilities in Zimbra, GitLab, Roundcube Webmail, and VMware Aria Operations, applying any existing mitigations or workarounds until vendor patches are released.
Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability - Active in CISA KEV catalog.
TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability - Active in CISA KEV catalog.
Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability - Active in CISA KEV catalog.
Google Chrome is vulnerable to a "Use After Free" condition in its CSS engine, which could allow a remote attacker to execute arbitrary code via a crafted webpage.
GitLab Server-Side Request Forgery (SSRF) Vulnerability - Active in CISA KEV catalog.
RoundCube Webmail Deserialization of Untrusted Data Vulnerability - Active in CISA KEV catalog.
RoundCube Webmail Cross-site Scripting Vulnerability - Active in CISA KEV catalog.
FileZen is affected by a high-severity OS command injection vulnerability that allows a threat actor to execute arbitrary commands on the underlying operating system.
VMware Aria Operations contains a command injection vulnerability that could allow an attacker to execute arbitrary commands on the affected system.
A memory corruption vulnerability exists in memory allocation processes when handling specific alignments, potentially leading to arbitrary code execution or system instability.
Hikvision Multiple Products Improper Authentication Vulnerability - Active in CISA KEV catalog.
Rockwell Multiple Products Insufficient Protected Credentials Vulnerability - Active in CISA KEV catalog.
Apple Multiple products Use-After-Free Vulnerability - Active in CISA KEV catalog.
Apple Multiple Products Integer Overflow or Wraparound Vulnerability - Active in CISA KEV catalog.
Apple iOS and iPadOS Use-After-Free Vulnerability - Active in CISA KEV catalog.
Vito versions prior to 3.20.3 contain a missing authorization check in workflow site-creation actions, allowing authenticated attackers to manage sites on unauthorized servers.
WWBN AVideo prior to 24.0 is vulnerable to an unauthenticated SQL injection in multiple components due to improper sanitization of JSON-formatted POST request bodies.
SiYuan versions prior to 3.5.9 contain an unauthenticated reflected XSS vulnerability in the dynamic icon API endpoint, allowing JavaScript execution via crafted SVG outputs.
The PowerPack for LearnDash WordPress plugin before 1.3.0 lacks authorization and CSRF checks in an AJAX action, allowing unauthenticated users to create admin accounts.
Chamilo LMS prior to 1.11.34 contains a stored XSS vulnerability in the learning path Settings field, allowing low-privileged trainers to hijack administrator accounts.
Chamilo LMS prior to 1.11.34 is vulnerable to stored XSS in the course description field, enabling authenticated trainers to capture administrator session tokens.
OCPP WebSocket endpoints lack authentication, allowing unauthenticated attackers to impersonate charging stations. This enables unauthorized control of charging infrastructure and data corruption.
Unauthenticated attackers can exploit missing authentication in WebSocket endpoints to impersonate charging stations and manipulate backend data via the OCPP protocol.
A lack of authentication in WebSocket endpoints allows unauthenticated attackers to impersonate charging stations, manipulate data, and issue unauthorized commands via the OCPP protocol.
AVideo is vulnerable to unauthenticated command injection via the base64Url parameter. Attackers can execute arbitrary OS commands, leading to full server compromise.
AppEngine's Fileaccess over HTTP feature lacks proper access restrictions, allowing unauthenticated read/write access to sensitive filesystem areas, including device parameters and Lua code.
The CROWN REST interface fails to enforce whitelists on internal testing directories. Unauthenticated attackers can upload manipulated parameter files to modify critical device settings.
Ghostfolio versions prior to 2.245.0 are vulnerable to a full-read SSRF in the manual asset import feature, allowing attackers to exfiltrate cloud metadata and probe internal services.
CoreDNS is a DNS server that chains plugins
Chartbrew, an open-source data visualization platform, contains a vulnerability that could allow unauthorized access to connected databases and APIs.
The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'dnd_upload_cf7_upload' function in versions up to, and including, 1
A webhook routing vulnerability in OpenClaw's Google Chat monitor allows cross-account policy misrouting. Attackers can bypass allowlists by exploiting first-match request verification semantics.
The WooCommerce WordPress plugin from versions 5
The Paid Videochat Turnkey Site β HTML5 PPV Live Webcams plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7
A stack buffer overflow vulnerability in the Diebold Nixdorf (Wincor Nixdorf) wnBios64 component could allow for arbitrary code execution at the firmware level.
The WowOptin: Next-Gen Popup Maker β Create Stunning Popups and Optins for Lead Generation plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the 'install_and_active_plugin' function in all versions up to, and including, 1
TimescaleDB is a time-series database for high-performance real-time analytics packaged as a Postgres extension
Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes
Net-Billetterie 2
DoceboLMS 1
Pedidos 1
Rmedia SMS 1
Alienor Web Libre 2
Silurus Classifieds Script 2
Data Center Audit 2
GPS Tracking System 2
Nominas 0
ServerZilla 1
PlayJoom 0
WWBN AVideo is an open source video platform
OpenClaw versions prior to 2026
Talishar is a fan-made Flesh and Blood project
Easyndexer 1
Zarf, an airgap native package manager for Kubernetes, contains a vulnerability that could compromise the integrity of package deployments in restricted environments.
The Mesa Python library for agent-based modeling contains a vulnerability that could allow for arbitrary code execution during the processing of simulation data.
Local privilege escalation due to insecure Unix socket permissions
OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI
An issue in Aranda Service Desk Web Edition (ASDK API 8
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support
OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI
Meneame English Pligg 5
Alive Parish 2
OOP CMS BLOG 1
OpenCode Systems OC Messaging / USSD Gateway OC Release 6
MarkUs is a web application for the submission and grading of student assignments
OpenClaw versions prior to 2026.2.14 contain a privilege escalation flaw in the Slack slash-command handler that allows unauthorized users to execute privileged commands via direct messages.
OpenClaw versions prior to 2026
Missing authentication and authorization in the web API of Tata Consultancy Services Cognix Recon Client v3
Traefik is an HTTP reverse proxy and load balancer
Traefik is an HTTP reverse proxy and load balancer
EdTv 2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter
Avira Internet Security contains a deserialization of untrusted data vulnerability in the System Speedup component, potentially allowing for arbitrary code execution.
An authorization bypass vulnerability in Tata Consultancy Services Cognix Recon Client v3
FreePBX is an open source IP PBX
FreePBX is an open source IP PBX
FreePBX is an open source IP PBX
A flaw was found in org
OpenClaw versions prior to 2026
Chamilo is a learning management system
Chamilo is a learning management system
Snipe-IT versions prior to 8
OliveTin gives access to predefined shell commands from a web interface
Flowise is a drag & drop user interface to build a customized large language model flow
Wallos is an open-source, self-hostable personal subscription tracker
Gogs is an open source self-hosted Git service
Payment Orchestrator Service Elevation of Privilege Vulnerability
Home-Gallery
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI
Plane is an an open-source project management tool
OpenClaw exec-approvals allowlist validation checks pre-expansion argv tokens but execution uses real shell expansion, allowing safe bins like head, tail, or grep to read arbitrary local files via glob patterns or environment variables
OpenClaw versions 2026
OpenClaw versions prior to 2026
OpenClaw versions prior to 2026
OneUptime is a solution for monitoring and managing online services
Warranty Tracking System 11
BitZoom 1
Gumbo CMS 0
Tina4 Stack 1
Webiness Inventory 2
A broken access control vulnerability in the password reset functionality of Tata Consultancy Services Cognix Recon Client v3
A security flaw in the IdentityBrokerService
OpenClaw versions 2026
OpenClaw version 2026
OpenClaw versions prior to 2026
OpenClaw versions prior to 2026
Sensitive information disclosure and manipulation due to improper authentication
Chamilo is a learning management system
Avira Internet Security's Software Updater component contains an improper link resolution vulnerability that could allow for unauthorized file manipulation or privilege escalation.
Avira Internet Security contains a time-of-check time-of-use (TOCTOU) vulnerability in the Optimizer component
OpenClaw versions 2
OpenClaw versions 2026
Flowise is a drag & drop user interface to build a customized large language model flow
In Eclipse Jetty, versions 12
An Arbitrary File Read vulnerability exists in the ImageTextPromptValue class in Exploding Gradients RAGAS v0
OliveTin gives access to predefined shell commands from a web interface
OliveTin gives access to predefined shell commands from a web interface
OliveTin gives access to predefined shell commands from a web interface
An observable timing discrepancy in @perfood/couch-auth v0
OpenClaw versions prior to 2026
OpenClaw versions prior to 2026
OpenClaw versions prior to 2026
OpenClaw versions prior to 2026
OpenClaw versions prior to 2026
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests
SVGO, short for SVG Optimizer, is a Node
EverSync 0
AMPPS 2