Critical vulnerabilities, curated daily for security professionals
🎯 SSCV Profile
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Risk scores will be adjusted based on your selected environment
📊
Archived Security Brief
Friday's disclosures center on cloud and collaboration infrastructure, with critical flaws in Azure DevOps, Microsoft Teams, Apache Cassandra, and Kubernetes affecting widely deployed enterprise environments. Critical CVE volume rose 82% to 20 from 11 the prior day, while high-priority issues held steady at 100. Notable entries include CVE-2026-33587 (CVSS 10) impacting Docker container isolation, CVE-2026-42826 (CVSS 10) in Azure DevOps, and CVE-2026-33109 (CVSS 9.9) in Apache Cassandra. Remote code execution, container escape, and secret exposure dominate the attack patterns, with cloud-native and DevOps toolchains carrying the heaviest exposure. No vendor patches are currently available across this set, requiring teams to rely on configuration hardening, network segmentation, and compensating controls until fixes ship.
Cloud and DevOps platforms lead exposure: Azure DevOps, Azure Cloud Shell, Kubernetes, and Apache Cassandra all carry CVSS 9.6+ flaws
Critical CVEs rose 82% day-over-day to 20, driven by container and cloud orchestration issues
High-priority CVEs held flat at 100, sustaining elevated remediation workload
Attack patterns concentrate on container escape (Docker CVE-2026-33587), secret exposure (Kubernetes CVE-2026-42880), and RCE in collaboration tools (Microsoft Teams CVE-2026-33823)
Patch availability sits at 0% across the disclosed set, leaving mitigation as the only near-term option
Five CVEs show active exploitation, including Palo Alto PAN, Ivanti EPMM, ConnectWise ScreenConnect, Windows, and Linux Kernel
Immediate action: Prioritize inventory and exposure assessment for Azure DevOps, Microsoft Teams, Apache Cassandra, Kubernetes, and Docker environments, alongside the actively exploited Palo Alto, Ivanti EPMM, and ConnectWise ScreenConnect deployments. With no patches yet available for the new critical CVEs, apply network segmentation, restrict administrative access, and enable enhanced logging on affected systems while monitoring vendor advisories for fix releases.
💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove
Section Navigation
⭐
Featured Vulnerability
⭐ FeaturedITWNoPatch
CVE-2026-0300
9.3📝
Palo Alto NetworksPAN-OS (PA-Series and VM-Series firewalls)
Unauthenticated RCE in Palo Alto PAN-OS firewalls
A buffer overflow in the User-ID Authentication Portal lets an unauthenticated network attacker execute arbitrary code as root on PA-Series and VM-Series firewalls. Palo Alto Networks confirms limited exploitation in the wild against portals reachable from untrusted IP space.
⚠️
CISA Known Exploited Vulnerabilities
⚠️ CISA KEVURGENT
CVE-2026-0300
9.8
Palo AltoNetworks PAN
⏰ Federal Deadline:May 8, 2026(1 days remaining)
A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.
The risk of this issue is greatly reduced if you secure access to the User-ID™ Authentication Portal per the best practice guidelines https://knowledgebase.paloaltonetworks.com/KCSArticleDetail by restricting access to only trusted internal IP addresses.
Prisma Access, Cloud NGFW and Panorama appliances are not impacted by this vulnerability.
CVSS Base9.8
→
CRSSelect profile
⚠️ CISA KEVURGENT
CVE-2026-6973
9.5
IvantiEndpoint Manager Mobile (EPMM)
⏰ Federal Deadline:May 9, 2026(2 days remaining)
Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
→
CRSSelect profile
⚠️ CISA KEVURGENT
CVE-2024-1708
9.5📜 Late Disclosure
ConnectWiseScreenConnect
⏰ Federal Deadline:May 11, 2026(4 days remaining)
ConnectWise ScreenConnect Path Traversal Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
→
CRSSelect profile
⚠️ CISA KEVURGENT
CVE-2026-32202
9.5
MicrosoftWindows
⏰ Federal Deadline:May 11, 2026(4 days remaining)
Microsoft Windows Protection Mechanism Failure Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
→
CRSSelect profile
⚠️ CISA KEVURGENT
CVE-2026-31431
9.5
LinuxKernel
⏰ Federal Deadline:May 14, 2026(7 days remaining)
Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
→
CRSSelect profile
🚨
Critical Vulnerabilities
CVE-2026-41902
9.1📝
HPFreeScout
FreeScout contains a flaw in the user-setup endpoint where invite hashes do not expire, allowing unauthenticated attackers to perform permanent account takeovers.
CVSS Base9.1
→
CRSSelect profile
CVE-2026-33109
9.9📝
ApacheCassandra allows
Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute arbitrary code.
CVSS Base9.9
→
CRSSelect profile
CVE-2026-33844
9📝
ApacheCassandra allows
Improper input validation in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.
CVSS Base9
→
CRSSelect profile
CVE-2026-37709
9.8
HPcomponent
Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute arbitrary code via the app/Http/Controllers/Api/UploadedFilesController.php component
CVSS Base9.8
→
CRSSelect profile
CVE-2026-33587
10📝
Dockercontainer via
A Server-Side Template Injection (SSTI) vulnerability in Open Notebook v1.8.3 allows authenticated users to execute arbitrary Python code and OS commands within the Docker container.
CVSS Base10
→
CRSSelect profile
CVE-2026-42826
10📝
AzureDevOps allows
An exposure of sensitive information in Azure DevOps allows an unauthenticated attacker to disclose data over a network.
CVSS Base10
→
CRSSelect profile
CVE-2026-33823
9.6📝
MicrosoftTeams allows
Improper authorization in Microsoft Teams permits an authorized attacker to perform unauthorized information disclosure over a network.
CVSS Base9.6
→
CRSSelect profile
CVE-2026-35428
9.6📝
AzureCloud Shell
A command injection vulnerability in Azure Cloud Shell allows an unauthorized attacker to perform spoofing over a network.
CVSS Base9.6
→
CRSSelect profile
CVE-2026-42880
9.6📝
KubernetesSecret data
A missing authorization gap in Argo CD allows read-only users to extract plaintext Kubernetes Secret data via the ServerSideDiff endpoint.
CVSS Base9.6
→
CRSSelect profile
CVE-2026-41500
9.8📝
GitHubElecterm
A command injection vulnerability in Electerm allows attackers to execute arbitrary code by supplying a malicious release name.
CVSS Base9.8
→
CRSSelect profile
CVE-2026-41501
9.8📝
Linuxelecterm
A command injection vulnerability exists in electerm prior to version 3.3.8, where remote version strings are unsafely passed to system commands.
CVSS Base9.8
→
CRSSelect profile
CVE-2026-43941
9.6📝
ElectermElecterm
A vulnerability in Electerm's terminal hyperlink handler allows arbitrary code execution or local file access when a user clicks a malicious link.
CVSS Base9.6
→
CRSSelect profile
CVE-2026-41589
9.6📝
CharmWish
A path traversal vulnerability in the SCP middleware of the Wish SSH server allows unauthorized file access and modification.
CVSS Base9.6
→
CRSSelect profile
CVE-2026-6508
9.8
ArchInstitute Liderahenk
Origin Validation Error vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects Liderahenk: from 2.0.1 before 2.0.2.
CVSS Base9.8
→
CRSSelect profile
CVE-2026-41201
9.1📝
ArchCI4MS
CI4MS contains a stored DOM-based XSS vulnerability in the backup module that can be leveraged for full account takeover.
CVSS Base9.1
→
CRSSelect profile
CVE-2026-7414
9.8📝
YarboYarbo Firmware
Yarbo firmware v2.3.9 contains hardcoded administrative credentials that cannot be changed, leading to trivial unauthorized management access.
CVSS Base9.8
→
CRSSelect profile
CVE-2026-7415
9.8📝
YarboFirmware
The embedded MQTT broker in Yarbo firmware v2.3.9 allows anonymous connections and lacks ACLs, enabling unauthorized control of the device.
CVSS Base9.8
→
CRSSelect profile
CVE-2026-5791
9.6📝
InforDivvyDrive
A Cross-Site Request Forgery (CSRF) vulnerability in DivvyDrive versions 4.8.2.9 through 4.8.3.1 allows unauthorized actions to be performed on behalf of authenticated users.
CVSS Base9.6
→
CRSSelect profile
CVE-2026-6795
9.6
InforMultiple Products
URL redirection to untrusted site ('open redirect') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Parameter Injection.
This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2.
CVSS Base9.6
→
CRSSelect profile
CVE-2026-40982
9.1📝
Spring CloudConfig Server
Spring Cloud Config allows directory traversal via specially crafted URLs, enabling unauthorized access to arbitrary files.
CVSS Base9.1
→
CRSSelect profile
⚠️
High Priority Updates
CVE-2026-7926
8.8📝
GoogleChrome prior
A Use-After-Free (UAF) vulnerability in the PresentationAPI of Google Chrome allows for potential arbitrary code execution via a specially crafted web page.
CVSS Base8.8
→
CRSSelect profile
CVE-2026-7898
8.8📝
GoogleChrome on
A Use-After-Free vulnerability in the Chromoting component of Google Chrome for Linux allows for potential arbitrary code execution.
CVSS Base8.8
→
CRSSelect profile
CVE-2026-7901
8.8📝
GoogleChrome on
A Use-After-Free vulnerability in the ANGLE graphics engine of Google Chrome on Mac allows for potential arbitrary code execution.
CVSS Base8.8
→
CRSSelect profile
CVE-2026-7906
8.8📝
GoogleChrome prior
A Use-After-Free vulnerability in the SVG implementation of Google Chrome allows for potential arbitrary code execution.
CVSS Base8.8
→
CRSSelect profile
CVE-2026-7907
8.8
GoogleChrome prior
Use after free in DOM in Google Chrome prior to 148
CVSS Base8.8
→
CRSSelect profile
CVE-2026-7921
8.8
GoogleChrome prior
Use after free in Passwords in Google Chrome prior to 148
CVSS Base8.8
→
CRSSelect profile
CVE-2026-7928
8.8
GoogleChrome on
Use after free in WebRTC in Google Chrome on Windows prior to 148
CVSS Base8.8
→
CRSSelect profile
CVE-2026-7938
8.8
GoogleChrome prior
Use after free in CSS in Google Chrome prior to 148
CVSS Base8.8
→
CRSSelect profile
CVE-2026-7940
8.8
GoogleChrome prior
Use after free in V8 in Google Chrome prior to 148
CVSS Base8.8
→
CRSSelect profile
CVE-2026-7974
8.8
GoogleChrome prior
Use after free in Blink in Google Chrome prior to 148
CVSS Base8.8
→
CRSSelect profile
CVE-2026-7980
8.8
GoogleChrome prior
Use after free in WebAudio in Google Chrome prior to 148
CVSS Base8.8
→
CRSSelect profile
CVE-2026-7984
8.8
GoogleChrome prior
Use after free in ReadingMode in Google Chrome prior to 148
CVSS Base8.8
→
CRSSelect profile
CVE-2026-7987
8.8
GoogleChrome prior
Use after free in WebRTC in Google Chrome prior to 148
CVSS Base8.8
→
CRSSelect profile
CVE-2026-7991
8.8
GoogleChrome prior
Use after free in UI in Google Chrome prior to 148
CVSS Base8.8
→
CRSSelect profile
CVE-2026-8002
8.8
GoogleChrome on
Use after free in Audio in Google Chrome on Mac prior to 148
CVSS Base8.8
→
CRSSelect profile
CVE-2026-8016
8.8
GoogleChrome prior
Use after free in WebRTC in Google Chrome prior to 148
CVSS Base8.8
→
CRSSelect profile
CVE-2026-7900
8.3
GoogleChrome prior
Heap buffer overflow in ANGLE in Google Chrome prior to 148
CVSS Base8.3
→
CRSSelect profile
CVE-2026-7911
8.3
GoogleChrome on
Use after free in Aura in Google Chrome on Windows prior to 148
CVSS Base8.3
→
CRSSelect profile
CVE-2026-7917
8.3
GoogleChrome on
Use after free in Fullscreen in Google Chrome on Windows prior to 148
CVSS Base8.3
→
CRSSelect profile
CVE-2026-7918
8.3
GoogleChrome prior
Use after free in GPU in Google Chrome prior to 148
CVSS Base8.3
→
CRSSelect profile
CVE-2026-7919
8.3
GoogleChrome prior
Use after free in Aura in Google Chrome prior to 148
CVSS Base8.3
→
CRSSelect profile
CVE-2026-7920
8.3
GoogleChrome prior
Use after free in Skia in Google Chrome prior to 148
CVSS Base8.3
→
CRSSelect profile
CVE-2026-7922
8.3
GoogleChrome prior
Use after free in ServiceWorker in Google Chrome prior to 148
CVSS Base8.3
→
CRSSelect profile
CVE-2026-7956
8.3
GoogleChrome prior
Use after free in Navigation in Google Chrome prior to 148
CVSS Base8.3
→
CRSSelect profile
CVE-2026-7970
8.3
GoogleChrome prior
Use after free in TopChrome in Google Chrome prior to 148
CVSS Base8.3
→
CRSSelect profile
CVE-2026-7975
8.3
GoogleChrome prior
Use after free in DevTools in Google Chrome prior to 148
CVSS Base8.3
→
CRSSelect profile
CVE-2026-7985
8.3
GoogleChrome prior
Use after free in GPU in Google Chrome prior to 148
CVSS Base8.3
→
CRSSelect profile
CVE-2026-8001
8.3
GoogleChrome on
Use After Free in Printing in Google Chrome on Linux, Mac, ChromeOS prior to 148
CVSS Base8.3
→
CRSSelect profile
CVE-2026-7896
8.8
GoogleChrome prior
Integer overflow in Blink in Google Chrome prior to 148
CVSS Base8.8
→
CRSSelect profile
CVE-2026-7899
8.8
GoogleChrome prior
Out of bounds read and write in V8 in Google Chrome prior to 148
CVSS Base8.8
→
CRSSelect profile
CVE-2026-7902
8.8
GoogleChrome prior
Out of bounds memory access in V8 in Google Chrome prior to 148
CVSS Base8.8
→
CRSSelect profile
CVE-2026-7903
8.8
GoogleChrome on
Integer overflow in ANGLE in Google Chrome on Mac,Windows prior to 148
CVSS Base8.8
→
CRSSelect profile
CVE-2026-7927
8.8
GoogleChrome prior
Type Confusion in Runtime in Google Chrome prior to 148
CVSS Base8.8
→
CRSSelect profile
CVE-2026-7930
8.8
GoogleChrome prior
Insufficient validation of untrusted input in Cookies in Google Chrome prior to 148
CVSS Base8.8
→
CRSSelect profile
CVE-2026-7951
8.8
GoogleChrome prior
Out of bounds write in WebRTC in Google Chrome prior to 148
CVSS Base8.8
→
CRSSelect profile
CVE-2026-7957
8.8
GoogleChrome on
Out of bounds write in Media in Google Chrome on Mac, iOS prior to 148
CVSS Base8.8
→
CRSSelect profile
CVE-2026-7973
8.8
GoogleChrome on
Integer overflow in Dawn in Google Chrome on Windows prior to 148
CVSS Base8.8
→
CRSSelect profile
CVE-2026-7988
8.8
GoogleChrome prior
Type Confusion in WebRTC in Google Chrome prior to 148
CVSS Base8.8
→
CRSSelect profile
CVE-2026-7992
8.8
GoogleChrome on
Insufficient validation of untrusted input in UI in Google Chrome on Linux, ChromeOS prior to 148
CVSS Base8.8
→
CRSSelect profile
CVE-2026-7995
8.8
GoogleChrome prior
Out of bounds read in AdFilter in Google Chrome prior to 148
CVSS Base8.8
→
CRSSelect profile
CVE-2026-8000
8.8
GoogleChrome on
Insufficient validation of untrusted input in ChromeDriver in Google Chrome on Windows prior to 148
CVSS Base8.8
→
CRSSelect profile
CVE-2026-41143
8.8
HPat line
YesWiki is a wiki system written in PHP
CVSS Base8.8
→
CRSSelect profile
CVE-2026-32207
8.8
AzureMachine Learning
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network
CVSS Base8.8
→
CRSSelect profile
CVE-2026-35435
8.6
AzureAI Foundry
Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network
CVSS Base8.6
→
CRSSelect profile
CVE-2026-7905
8.3
GoogleChrome on
Insufficient validation of untrusted input in Media in Google Chrome on Android prior to 148
CVSS Base8.3
→
CRSSelect profile
CVE-2026-7914
8.3
GoogleChrome on
Type Confusion in Accessibility in Google Chrome on Windows prior to 148
CVSS Base8.3
→
CRSSelect profile
CVE-2026-7916
8.3
GoogleChrome prior
Insufficient data validation in InterestGroups in Google Chrome prior to 148
CVSS Base8.3
→
CRSSelect profile
CVE-2026-7923
8.3
GoogleChrome prior
Out of bounds write in Skia in Google Chrome prior to 148
CVSS Base8.3
→
CRSSelect profile
CVE-2026-7963
8.3
GoogleChrome prior
Inappropriate implementation in ServiceWorker in Google Chrome prior to 148
CVSS Base8.3
→
CRSSelect profile
CVE-2026-7967
8.3
GoogleChrome prior
Insufficient validation of untrusted input in Navigation in Google Chrome prior to 148
CVSS Base8.3
→
CRSSelect profile
CVE-2026-34327
8.2
MicrosoftPartner Center
Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attacker to perform spoofing over a network
CVSS Base8.2
→
CRSSelect profile
CVE-2026-7978
8.1
GoogleChrome on
Inappropriate implementation in Companion in Google Chrome on Mac prior to 148
CVSS Base8.1
→
CRSSelect profile
CVE-2026-7981
8.1
GoogleChrome prior
Out of bounds read in Codecs in Google Chrome prior to 148
CVSS Base8.1
→
CRSSelect profile
CVE-2026-8018
8.1
GoogleChrome prior
Insufficient policy enforcement in DevTools in Google Chrome prior to 148
CVSS Base8.1
→
CRSSelect profile
CVE-2026-41105
8.1
AzureNotification Service
Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network
CVSS Base8.1
→
CRSSelect profile
CVE-2026-7913
7.8
GoogleChrome on
Insufficient policy enforcement in DevTools in Google Chrome on Android prior to 148
CVSS Base7.8
→
CRSSelect profile
CVE-2026-20034
8.8
CiscoUnity Connection
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to execute arbitrary code on an affected device
CVSS Base8.8
→
CRSSelect profile
CVE-2026-5127
8.8
WordPressis vulnerable
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Deserialization of Untrusted Data in versions up to, and including, 4
CVSS Base8.8
→
CRSSelect profile
CVE-2026-6692
8.8
WordPressis vulnerable
The Slider Revolution plugin for WordPress is vulnerable to Arbitrary File Upload in versions 7
CVSS Base8.8
→
CRSSelect profile
CVE-2026-7252
8.1
WordPressis vulnerable
The WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unscheduled_original_file_deletion function in all versions up to, and including, 4
CVSS Base8.1
→
CRSSelect profile
CVE-2026-41934
8.8
HPhandler
Vvveb before version 1
CVSS Base8.8
→
CRSSelect profile
CVE-2026-41938
8.8
HPhandler
Vvveb before version 1
CVSS Base8.8
→
CRSSelect profile
CVE-2026-41936
8.1
HPto inject
Vvveb before version 1
CVSS Base8.1
→
CRSSelect profile
CVE-2026-33588
8.1
Dockercontainer via
Lack of user input validation in the file upload functionality of Open Notebook v1
CVSS Base8.1
→
CRSSelect profile
CVE-2026-6691
7.8📝
SAPC Driver
A heap buffer overflow in the MongoDB C Driver's Cyrus SASL integration allows for potential arbitrary code execution before authentication.
CVSS Base7.8
→
CRSSelect profile
CVE-2026-42215
8.8
UnknownMultiple Products
GitPython is a python library used to interact with Git repositories
CVSS Base8.8
→
CRSSelect profile
CVE-2026-43940
8.4
ftpMultiple Products
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client
CVSS Base8.4
→
CRSSelect profile
CVE-2025-1978
8.3
Hitachi StorageMultiple Products
Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console in Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One Block 23, One Block 24, One Block 26, One Block 28
CVSS Base8.3
→
CRSSelect profile
CVE-2026-42284
8.1
UnknownMultiple Products
GitPython is a python library used to interact with Git repositories
CVSS Base8.1
→
CRSSelect profile
CVE-2026-5787
8.9
beforeEPMM before
An Improper Certificate Validation in Ivanti EPMM before versions 12
CVSS Base8.9
→
CRSSelect profile
CVE-2026-5786
8.8
Ivanti EPMM beforeEPMM before
An Improper Access Control vulnerability in Ivanti EPMM before versions 12
CVSS Base8.8
→
CRSSelect profile
CVE-2026-8138
8.8
TendaCX12L
A vulnerability was found in Tenda CX12L 16
CVSS Base8.8
→
CRSSelect profile
CVE-2026-42275
8.7
UnknownMultiple Products
zrok is software for sharing web services, files, and network resources
CVSS Base8.7
→
CRSSelect profile
CVE-2026-41422
8.3
UnknownMultiple Products
Daptin is a GraphQL/JSON-API headless CMS
CVSS Base8.3
→
CRSSelect profile
CVE-2024-43384
8📜 Late Disclosure
InforMultiple Products
A low privileged remote attacker can gain the root password due to improper removal of sensitive information before storage or transfer
CVSS Base8
→
CRSSelect profile
CVE-2024-30151
8.3📜 Late Disclosure
UnknownMultiple Products
HCL BigFix Service Management (SX) is affected by a Broken Access Control vulnerability leading to privilege escalation
CVSS Base8.3
→
CRSSelect profile
CVE-2025-31951
8.8📝
HCLBigFix RunBookAI
HCL BigFix RunBookAI is affected by a command smuggling vulnerability due to unvalidated command input.
CVSS Base8.8
→
CRSSelect profile
CVE-2026-42503
8.8
UnknownMultiple Products
gopls by default communicates via pipe
CVSS Base8.8
→
CRSSelect profile
CVE-2026-7875
8.8
NanoClawMultiple Products
NanoClaw version 1
CVSS Base8.8
→
CRSSelect profile
CVE-2026-43584
8.8
OpenClawMultiple Products
OpenClaw before 2026
CVSS Base8.8
→
CRSSelect profile
CVE-2026-44110
8.8
OpenClawMultiple Products
OpenClaw before 2026
CVSS Base8.8
→
CRSSelect profile
CVE-2026-44115
8.8
OpenClawMultiple Products
OpenClaw before 2026
CVSS Base8.8
→
CRSSelect profile
CVE-2026-41142
8.8
UnknownMultiple Products
OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry
CVSS Base8.8
→
CRSSelect profile
CVE-2026-41139
8.8
UnknownMultiple Products
Math
CVSS Base8.8
→
CRSSelect profile
CVE-2026-3953
8.8
Gosoft SoftwareMultiple Products
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gosoft Software Industry and Trade Ltd
CVSS Base8.8
→
CRSSelect profile
CVE-2026-5784
8.8
DivvyDriveMultiple Products
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc
CVSS Base8.8
→
CRSSelect profile
CVE-2026-6002
8.8
DivvyDriveMultiple Products
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in DivvyDrive Information Technologies Inc
CVSS Base8.8
→
CRSSelect profile
CVE-2026-41900
8.8
UnknownMultiple Products
OpenLearnX is an open-source, decentralized learning and assessment platform
CVSS Base8.8
→
CRSSelect profile
CVE-2026-8137
8.8
TotolinkMultiple Products
A vulnerability has been found in Totolink X5000R 9
CVSS Base8.8
→
CRSSelect profile
CVE-2026-41505
8.7
UnknownMultiple Products
RELATE is a web-based courseware package
CVSS Base8.7
→
CRSSelect profile
CVE-2026-44116
8.6
OpenClawMultiple Products
OpenClaw before 2026
CVSS Base8.6
→
CRSSelect profile
CVE-2026-42047
8.6
InforMultiple Products
Inngest is a platform for running event-driven and scheduled background functions with queueing, retries, and step orchestration
CVSS Base8.6
→
CRSSelect profile
CVE-2026-42449
8.5
MCPMultiple Products
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations
CVSS Base8.5
→
CRSSelect profile
CVE-2025-14341
8.3
DivvyDriveMultiple Products
Improperly controlled modification of Dynamically-Determined object attributes, Allocation of resources without limits or throttling vulnerability in DivvyDrive Information Technologies Inc
CVSS Base8.3
→
CRSSelect profile
CVE-2026-41490
8.3
DeltaMultiple Products
Dagster is an orchestration platform for the development, production, and observation of data assets
CVSS Base8.3
→
CRSSelect profile
CVE-2026-41669
8.2
UnknownMultiple Products
Admidio is an open-source user management solution
CVSS Base8.2
→
CRSSelect profile
CVE-2026-41670
8.2
UnknownMultiple Products
Admidio is an open-source user management solution
CVSS Base8.2
→
CRSSelect profile
CVE-2026-43585
8.1
OpenClawMultiple Products
OpenClaw before 2026
CVSS Base8.1
→
CRSSelect profile
CVE-2025-9661
8.1
OneMultiple Products
OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One Block 23, 24, 26 and 28