2026-07-17
2026-07-17 02:18Z
HIGH

CVE-2026-62223 — OpenClaw: before 2026.5.18 contain an authorization bypass vulnerability in the device-pair approval feature that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62223

OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in the device-pair approval feature that allows lower-trust callers to execute actions beyond their intended authorization. Attackers can exploit misconfigured input paths to execute or persist unauthorized actions when the affected feature is enabled and reachable. CVSSv3.1 8.8 (HIGH)

CWECWE 863VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-17
2026-07-17 02:18Z
HIGH

CVE-2026-62218 — OpenClaw: 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62218

OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature that allows lower-trust callers to bypass role-management checks. Attackers can perform actions requiring stronger authorization by reaching the affected feature through configured input paths. CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-17
2026-07-17 02:18Z
HIGH

CVE-2026-62217 — OpenClaw: When the feature is enabled and reachable, a lower-trust caller or configured input path

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62217

OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. When the feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization, allowing non-allowlisted senders to perform unauthorized operations. CVSSv3.1 8.8 (HIGH)

CWECWE 863VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-17
2026-07-17 02:18Z
HIGH

CVE-2026-62215 — OpenClaw: versions before 2026.6.5 contain an authentication bypass vulnerability in HTTP Canvas responses that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62215

OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability in HTTP Canvas responses that allows lower-trust callers to forge trusted A2UI actions. Attackers can perform actions requiring stronger authorization by submitting crafted requests through configured input paths, bypassing intended policy checks. CVSSv3.1 8.0 (HIGH)

CWECWE 345VNDOpenclawTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-07-17
2026-07-17 02:18Z
HIGH

CVE-2026-62209 — OpenClaw: versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mode dispatch

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62209

OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mode dispatch feature, which could ignore the toolsAllow policy check. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could perform actions that should have required a stronger authorization or policy check. CVSSv3.1 8.1 (HIGH)

CWECWE 863VNDOpenclawTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-17
2026-07-17 02:18Z
HIGH

CVE-2026-62207 — OpenClaw: versions before 2026.6.5 contain an authentication bypass vulnerability that allows lower-trust callers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62207

OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability that allows lower-trust callers to reach admin-scoped tools. Attackers can perform actions requiring stronger authorization by exploiting insufficient policy checks on configured input paths. CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-17
2026-07-17 02:18Z
HIGH

CVE-2026-62203 — OpenClaw: versions before 2026.6.6 contain an environment variable filtering vulnerability in host exec that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62203

OpenClaw versions before 2026.6.6 contain an environment variable filtering vulnerability in host exec that fails to properly sanitize rustup startup variables. Attackers with lower-trust caller access or configured input paths can execute or persist actions beyond their intended authorization level. CVSSv3.1 8.8 (HIGH)

CWECWE 184VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-17
2026-07-17 02:18Z
HIGH

CVE-2026-62202 — OpenClaw: versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62202

OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that allows lower-trust callers to regain denied execution tools. Attackers can execute or persist actions beyond their intended authorization by leveraging misconfigured input paths in the affected cron feature. CVSSv3.1 8.8 (HIGH)

CWECWE 863VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-17
2026-07-17 02:18Z
CRIT

CVE-2026-14956 — Bricksforge: The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14956

The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper validation of the fieldIds parameter in the Pro Forms registration action, which allows attacker-supplied field IDs to be added to the trusted form-field whitelist. This makes it possible for unauthenticated attackers to register a new administrator account by submitting a crafted request to a publicly accessible Bricksforge Pro For CVSSv3.1 9.8 (CRITICAL)

CWECWE 269VNDBricksforgeTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-16
2026-07-16 23:16Z
CRIT

CVE-2026-44182 — Jupyter Enterprise_gateway: In versions prior to 3.3.0, the server interpolates untrusted environment variables (e.g., KERNEL_XXX) into

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44182

Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In versions prior to 3.3.0, the server interpolates untrusted environment variables (e.g., KERNEL_XXX) into Kubernetes manifests without YAML-aware escaping, enabling YAML injection attacks. Attackers can inject new fields, overwrite critical fields (e.g., duplicate securityContext keys, where the last one prevails), and inject docum CVSSv3.1 10.0 (CRITICAL) · EPSS 27th percentile

CWECWE 74VNDJupyterTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-16
2026-07-16 23:16Z
CRIT

CVE-2026-44181 — Jupyter Enterprise_gateway: In versions 2.0.0rc2 and above, prior to 3.3.0, the environment variables (KERNEL_XXX) used during

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44181

Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In versions 2.0.0rc2 and above, prior to 3.3.0, the environment variables (KERNEL_XXX) used during the rendering of the Kubernetes manifest are vulnerable to Server Side Template Injection (SSTI). By including Jinja2 template expressions it is possible to execution Python code and OS Commands in the Enterprise Gateway service. The co CVSSv3.1 10.0 (CRITICAL)

CWECWE 1336VNDJupyterTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-07-16
2026-07-16 23:16Z
HIGH

CVE-2026-43978 — wger is a free, open-source workout and fitness manager.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43978

wger is a free, open-source workout and fitness manager. In versions prior to 2.6, a gym trainer can escalate their session to any higher-privileged account (gym manager, general manager) by chaining two calls to the trainer-login endpoint. Once a trainer performs a legitimate switch into a low-privileged user, the session flag trainer.identity is set and this flag alone bypasses the permission check on all subsequent trainer-login calls. This grants full gym administration c CVSSv3.1 8.1 (HIGH)

CWECWE 269TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-16
2026-07-16 22:17Z
CRIT

CVE-2026-57075 — YAML: YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57075

YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec. The base64 decoder in the bundled libsyck indexes the 256-entry static table b64_xtable with a signed char, so any !!binary byte >= 0x80 sign-extends to a negative index and reads before the table. The decoder receives the raw bytes of any !!binary node, a standard YAML type not gated by $LoadBlessed or $LoadCode, so it is reached on the default Load p CVSSv3.1 9.1 (CRITICAL)

CWECWE 125TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-16
2026-07-16 22:17Z
CRIT

CVE-2026-53412 — Input: Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53412

Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an account takeover via network access. CVSSv3.1 9.8 (CRITICAL)

CWECWE 20VNDInputTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-16
2026-07-16 22:17Z
CRIT

CVE-2026-44180 — Jupyter: This input validation vulnerability allows running Jupyter kernels as root, which can be dangerous

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44180

Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. Versions 2.0.0rc1 and above prior to 3.3.0 have a prohibited UID and GID feature that by default prevents launching kernels with UID or GID 0 (root), and this restriction can be bypassed using a specially crafted KERNEL_UID or KERNEL_GID value. This input validation vulnerability allows running Jupyter kernels as root, which can be d CVSSv3.1 9.8 (CRITICAL)

CWECWE 20VNDJupyterTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-16
2026-07-16 21:17Z
HIGH

CVE-2026-55173 — WWBN: Versions 29.0 and below remain vulnerable to OS command injection because the fix for

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55173

WWBN AVideo is an open source video platform. Versions 29.0 and below remain vulnerable to OS command injection because the fix for CVE-2026-33482 was incomplete and still does not neutralize a single & ( the shell background operator). CVE-2026-33482 reported that sanitizeFFmpegCommand() (plugin/API/standAlone/functions.php) failed to strip $(...) command substitution, allowing OS command injection at the execAsync() sh -c sink. The fix (commit 25c8ab90) added $, (, ), {, }, CVSSv3.1 8.1 (HIGH)

CWECWE 78VNDWwbnTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-16
2026-07-16 21:17Z
HIGH

CVE-2026-44023 — Docling: In applications that accept untrusted URLs, this could allow SSRF attacks targeting local files

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44023

Docling Core defines core data types and transformations for the document processing application Docling. In versions 1.5.0 and above, prior to 2.74.1, docling-core did not sufficiently restrict remote request destinations and could resolve a server-provided Content-Disposition to a local path in an unsafe manner. In applications that accept untrusted URLs, this could allow SSRF attacks targeting local files outside the user-defined cache directory. This issue has been fixed CVSSv3.1 8.6 (HIGH)

CWECWE 918CWECWE 22VNDDoclingTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-16
2026-07-16 21:17Z
HIGH

CVE-2026-44019 — Docling: In versions 2.5.0 and above, prior to 2.74.1, docling-core could allow local file:// image

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44019

Docling Core defines core data types and transformations for the document processing application Docling. In versions 2.5.0 and above, prior to 2.74.1, docling-core could allow local file:// image references and accepted inline data: content without a decoded-size limit. In applications that accept untrusted image references, this may allow access to local files readable by the process or excessive memory use from large inline payloads. This issue has been fixed in version 2. CVSSv3.1 8.1 (HIGH)

CWECWE 73CWECWE 400VNDDoclingTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-16
2026-07-16 21:17Z
CRIT

CVE-2026-38158 — SQL: A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38158

A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to access sensitive database information via crafted SQL statements. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-16
2026-07-16 20:16Z
CRIT

CVE-2026-63089 — WireGuard: Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63089

WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation vulnerability that allows unauthenticated network attackers to recover WireGuard peer credentials by brute-forcing a keyspace of at most 1000 candidate tokens per client ID, as the token is computed using CRC32 over a random value constrained to 0-999. Attackers can enumerate candidate tokens against the unauthenticated /cnf/:oneTimeLink route, which lacks CVSSv3.1 9.3 (CRITICAL)

CWECWE 338CWECWE 613VNDWireguardTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-07-16
2026-07-16 20:16Z
HIGH

CVE-2026-49998 — Centrifugo: Prior to 6.8.1, Centrifugo dynamic JWKS endpoint verification could reuse a key for one

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49998

Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.1, Centrifugo dynamic JWKS endpoint verification could reuse a key for one allowed issuer to verify a JWT for another allowed issuer because the JWKS cache and singleflight lookup were keyed only by JWT header kid, not by the resolved JWKS endpoint, issuer, audience, or trust-domain namespace, affecting client.token.jwks_public_endpoint, client.subscription_token.jwks_public_endpoint, internal/jwks CVSSv3.1 8.2 (HIGH)

CWECWE 347VNDCentrifugoTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-16
2026-07-16 19:16Z
CRIT

CVE-2026-54526 — Argoproj Argo_workflows: Prior to 3.7.15 and 4.0.6, the allow-list fix for CVE-2026-31892 is incomplete because workflow/util/merge.go

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54526

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 3.7.15 and 4.0.6, the allow-list fix for CVE-2026-31892 is incomplete because workflow/util/merge.go ValidateUserOverrides and SanitizeUserWorkflowSpec walk only the top-level fields of WorkflowSpec via reflection, and WorkflowSpec.ArtifactGC is allow-listed wholesale; the struct behind that field, WorkflowLevelArtifactGC, has a PodSpecPatch sub-field whos CVSSv3.1 9.9 (CRITICAL)

CWECWE 284VNDArgoVNDArgoprojTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-16
2026-07-16 19:16Z
CRIT

CVE-2026-46512 — Frogman: provides headless PBX control through MCP and HTTP API.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46512

Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_dialplan_apply accepted template parameters including greeting, dest, url, extension, code, and file, and Tools/DialplanApply.php wrote Dialplan/Templates.php output to extensions_custom.conf while only Dialplan/TemplateBase.php:38-42 sanitized contextName(), allowing a PERM_WRITE caller using confirm:true to inject arbitrary Asterisk directives such as System(), Set(SHELL(...)), Goto, or Macro CVSSv3.1 9.9 (CRITICAL)

CWECWE 94VNDFrogmanTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-16
2026-07-16 19:16Z
HIGH

CVE-2026-46353 — BigBlueButton: Prior to 3.0.21, bbb-web checksum validation could be bypassed when a presentationUploadExternalUrl parameter was

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46353

BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web checksum validation could be bypassed when a presentationUploadExternalUrl parameter was supplied to API request handling in CreateMeeting.java and ValidationService.java, allowing a user to send valid requests to some endpoints without a checksum. This issue is fixed in version 3.0.21. CVSSv3.1 8.1 (HIGH)

CWECWE 284VNDBigbluebuttonTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-16
2026-07-16 19:16Z
HIGH

CVE-2026-46351 — BigBlueButton: Prior to 3.0.21, bbb-web generated conference sessionToken values with insufficiently secure randomness in bbb-common-web/src/main/java/org/bigbluebutton/api/Util.java

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46351

BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web generated conference sessionToken values with insufficiently secure randomness in bbb-common-web/src/main/java/org/bigbluebutton/api/Util.java and bigbluebutton-web/grails-app/controllers/org/bigbluebutton/web/controllers/ApiController.groovy, allowing a session user to predict other users' conference session tokens and impersonate them. This issue is fixed in version 3.0.21. CVSSv3.1 8.1 (HIGH)

CWECWE 330VNDBigbluebuttonTYPVulnerability
8.1
CVSS v3.1
91
Edit Score