21637 Total CVEs
12808 AI Analyzed
306 CISA KEV
4748 Critical
All Vendors
Showing 7501-7550 of 21637 CVEs Page 151 of 433
CVE-2026-32980
7.5
OpenClaw webhook request

OpenClaw before 2026

2026-03-30
CVE-2026-32979
7.3
OpenClaw Multiple Products

OpenClaw before 2026

2026-03-30
CVE-2026-32978
8
OpenClaw Multiple Products

OpenClaw before 2026

2026-03-30
CVE-2026-32975
Analyzed
9.8
OpenClaw OpenClaw

A weak authorization vulnerability in OpenClaw's Zalouser allowlist mode allows attackers to bypass channel authorization by spoofing mutable group di...

2026-03-30
CVE-2026-32974
8.6
OpenClaw Multiple Products

OpenClaw before 2026

2026-03-30
CVE-2026-32973
Analyzed
9.8
Linux OpenClaw

An execution allowlist bypass in OpenClaw due to improper path normalization and glob matching allows attackers to execute unauthorized commands on th...

2026-03-30
CVE-2026-32972
7.1
OpenClaw Multiple Products

OpenClaw before 2026

2026-03-30
CVE-2026-32971
7.1
OpenClaw Multiple Products

OpenClaw before 2026

2026-04-01
CVE-2026-32969
7.5
Unknown Multiple Products

An unauthenticated remote attacker can exploit a Pre-Auth blind SQL Injection vulnerability in the userinfo endpoint’s authentication method due to im...

2026-03-24
CVE-2026-32968
Analyzed
9.8
SAP com_mb24sysapi module

An unauthenticated remote attacker can exploit an OS command injection vulnerability in the SAP com_mb24sysapi module, leading to full system compromi...

2026-03-24
CVE-2026-32965
7.5
AMC Multiple Products

Initialization of a resource with an insecure default vulnerability exists in SD-330AC and AMC Manager provided by silex technology, Inc

2026-04-20
CVE-2026-3296
Analyzed
9.8
HP is vulnerable

The Everest Forms WordPress plugin is vulnerable to PHP Object Injection via unsafe deserialization of user-supplied form metadata.

2026-04-08
CVE-2026-32956
Analyzed
9.8
Unknown SD-330AC and AMC Manager

silex technology SD-330AC and AMC Manager contain a heap-based buffer overflow vulnerability, potentially allowing arbitrary code execution.

2026-04-20
CVE-2026-32955
8.8
AMC Multiple Products

SD-330AC and AMC Manager provided by silex technology, Inc

2026-04-20
CVE-2026-32944
7.5
Parse Multiple Products

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node

2026-03-20
CVE-2026-32940
Analyzed
9.3
SiYuan SiYuan

SiYuan versions 3.6.0 and below contain a click-through XSS vulnerability in the dynamic icon API due to incomplete SVG sanitization.

2026-03-20
CVE-2026-3294
Analyzed
8.8
TP-Link Range Extenders

An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a lo...

2026-06-02
CVE-2026-32938
Analyzed
9.9
SiYuan SiYuan

SiYuan versions 3.6.0 and below are vulnerable to path traversal and sensitive file exfiltration via improper validation of file:// links in pasted HT...

2026-03-20
CVE-2026-32933
7.5
Unknown Multiple Products

AutoMapper is a convention-based object-object mapper in

2026-03-20
CVE-2026-32931
7.5
HP webshell by

Chamilo LMS is a learning management system

2026-04-12
CVE-2026-32930
7.1
Unknown Multiple Products

Chamilo LMS is a learning management system

2026-04-12
CVE-2026-32929
7.8
SFT Multiple Products

V-SFT versions 6

2026-04-02
CVE-2026-32928
7.8
SFT Multiple Products

V-SFT versions 6

2026-04-02
CVE-2026-32927
7.8
SFT Multiple Products

V-SFT versions 6

2026-04-02
CVE-2026-32926
7.8
SFT Multiple Products

V-SFT versions 6

2026-04-02
CVE-2026-32925
7.8
SFT Multiple Products

V-SFT versions 6

2026-04-02
CVE-2026-32924
Analyzed
9.8
OpenClaw OpenClaw

An authorization bypass in OpenClaw's Feishu integration misclassifies group chat reaction events as private conversations, allowing attackers to circ...

2026-03-30
CVE-2026-32922
Analyzed
9.9
OpenClaw OpenClaw

A privilege escalation vulnerability in OpenClaw's token rotation mechanism allows users with limited pairing scopes to mint high-privilege administra...

2026-03-30
CVE-2026-32920
8.4
OpenClaw Multiple Products

OpenClaw before 2026

2026-04-01
CVE-2026-32918
8.4
OpenClaw Multiple Products

OpenClaw before 2026

2026-03-30
CVE-2026-32917
Analyzed
9.8
OpenClaw OpenClaw

OpenClaw contains a remote command injection vulnerability in the iMessage attachment staging flow. Unsanitized SCP paths allow attackers to execute c...

2026-04-01
CVE-2026-32916
Analyzed
9.4
OpenClaw OpenClaw

OpenClaw versions before 2026.3.11 contain an unauthenticated authorization bypass allowing remote attackers to execute privileged gateway actions via...

2026-04-01
CVE-2026-32915
8.8
OpenClaw Multiple Products

OpenClaw before 2026

2026-03-30
CVE-2026-32914
8.8
OpenClaw Multiple Products

OpenClaw before 2026

2026-03-30
CVE-2026-32913
Analyzed
9.3
OpenClaw OpenClaw

OpenClaw fails to properly validate headers during cross-origin redirects, leading to the leakage of sensitive authorization headers like API keys to...

2026-03-24
CVE-2026-32894
7.1
Unknown Multiple Products

Chamilo LMS is a learning management system

2026-04-12
CVE-2026-32892
Analyzed
9.1
HP passes user

Chamilo LMS contains an OS Command Injection vulnerability in its file move function, allowing authenticated users to execute arbitrary commands on th...

2026-04-11
CVE-2026-32891
Analyzed
9
Discord bot for

Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. Versions 1.4.1 and bel...

2026-03-20
CVE-2026-32890
Analyzed
9.6
Discord bot for

Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. In versions 1.4.1 and...

2026-03-20
CVE-2026-32888
8.8
HP functionality

Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework

2026-03-20
CVE-2026-32887
7.4
Unknown Multiple Products

Effect is a TypeScript framework that consists of several packages that work together to help build TypeScript applications

2026-03-22
CVE-2026-32886
7.5
Parse Multiple Products

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node

2026-03-20
CVE-2026-32882
Analyzed
7.1
Unknown Multiple Products

libheif is a HEIF and AVIF file format decoder and encoder

2026-05-20
CVE-2026-3288
8.8
Nginx where the

A security issue was discovered in ingress-nginx where the `nginx

2026-03-10
CVE-2026-32878
7.5
Parse Multiple Products

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node

2026-03-20
CVE-2026-32877
8.2
Unknown Multiple Products

Botan is a C++ cryptography library

2026-03-31
CVE-2026-32875
7.5
Unknown Multiple Products

UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3

2026-03-20
CVE-2026-32874
7.5
Unknown Multiple Products

UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3

2026-03-20
CVE-2026-32873
7.5
Unknown Multiple Products

ewe is a Gleam web server

2026-03-20
CVE-2026-32865
Analyzed
9.8
OPEXUS eComplaint and eCASE

OPEXUS eComplaint and eCASE expose secret verification codes in HTTP responses during password resets. Attackers can use this to hijack accounts and r...

2026-03-20