Edition of June 16, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-22312 | 8.6 | 14.2 | Radiflow | iSAP Smart Collector | CWE-798 | Use of Hard-coded Credentials Vulnerability in Radiflow iSAP Smart Collector |
| CVE-2026-48775 | 6.8 | 14.3 | langchain-ai | langgraph | CWE-502 | LangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loading |
| CVE-2026-10639 | 4.8 | 14.3 | zephyrproject | zephyr | CWE-416 | Use-after-free reading `net_pkt_iface()` of a sent ICMPv4 echo-reply packet i… |
| CVE-2026-0151 | 8.8 | 14.1 | Android | CWE-190 | In IntfGraphCreate of intfgraph.c, there is a possible out of bounds write du… | |
| CVE-2026-0154 | 8.8 | 14.1 | Android | CWE-120 | In Modem, there is a possible way to trigger a modem crash during a SIP REFER… | |
| CVE-2026-0160 | 8.8 | 14.1 | Android | CWE-120 | In TextRtpPayloadDecoderNode::DecodeT140 of TextRtpPayloadDecoderNode.cpp, th… | |
| CVE-2026-0161 | 8.8 | 14.1 | Android | CWE-190 | In numberOfReportBlocks of RtpSession.cpp, there is a possible out of bounds … | |
| CVE-2026-0162 | 8.8 | 14.1 | Android | CWE-843 | In ParsePayloads of AudioSdpParser.cpp, there is a possible memory corruption… | |
| CVE-2026-0164 | 8.8 | 14.1 | Android | CWE-120 | In Modem, there is a possible out of bounds write due to a missing bounds che… | |
| CVE-2026-46770 | 6.1 | 14.1 | Oracle Corporation | Oracle Application Development Framework (ADF) | CWE-284 | Vulnerability in the Oracle Application Development Framework (ADF) product o… |
| CVE-2026-52712 | 7.6 | 13.8 | tnomi | Attendance Manager | CWE-89 | WordPress Attendance Manager plugin <= 0.6.2 - SQL Injection vulnerability |
| CVE-2026-10093 | 6.4 | 13.8 | deepakkite | Secure Client Portal and Private File Sharing Plugin – User Private Files | CWE-79 | File Sharing & Download Manager <= 2.1.6 - Authenticated (Subscriber+) Stored… |
| CVE-2026-9187 | 5.3 | 13.8 | zealopensource | Abandoned Contact Form 7 | CWE-862 | Abandoned Contact Form 7 <= 2.2 - Missing Authorization to Unauthenticated Ar… |
| CVE-2026-12325 | 6.5 | 13.6 | Mozilla | Firefox | CWE-400 | Denial-of-service in the Graphics: ImageLib component |
| CVE-2026-53857 | 8.6 | 13.4 | OpenClaw | OpenClaw | CWE-290 | OpenClaw < 2026.5.3 - Mutable Display Name Binding in Zalo allowFrom Policy |
| CVE-2025-68045 | 7.5 | 13.5 | Arraytics | WP Event SOlution | CWE-862 | WordPress WP Event SOlution plugin <= 4.1.12 - Broken Access Control vulnerab… |
| CVE-2026-52711 | 7.5 | 13.5 | kilbot | WooCommerce POS | CWE-862 | WordPress WooCommerce POS plugin <= 1.8.14 - Broken Access Control vulnerability |
| CVE-2026-44587 | 6.1 | 13.2 | carrierwaveuploader | carrierwave | CWE-79 | CarrierWave has a denylisted_content_type bypass via Unescaped Regex Metachar… |
| CVE-2026-53840 | 6.0 | 13.2 | OpenClaw | OpenClaw | CWE-522 | OpenClaw < 2026.5.12 - Custom Header Leakage via MCP Streamable HTTP Cross-Or… |
| CVE-2026-47684 | 7.7 | 13.0 | Sync-in | server | CWE-918 | Sync-in Server: SSRF protection bypass via IPv4-mapped IPv6 addresses in regE… |
| CVE-2026-12303 | 4.3 | 13.0 | Mozilla | Firefox | CWE-125 | Information disclosure due to incorrect boundary conditions in the Graphics: … |
| CVE-2026-39598 | 8.0 | 12.9 | Kodezen LLC | Academy LMS Pro | CWE-434 | WordPress Academy LMS Pro plugin < 3.5.2 - Arbitrary File Upload vulnerability |
| CVE-2026-48780 | 8.2 | 12.5 | forem | forem | CWE-287 | Forem vulnerable to bypass of email address domain restrictions |
| CVE-2026-48776 | 9.1 | 12.3 | langchain-ai | langchain-ai | CWE-22 | LangGraph SDK has unsafe URL path construction |
| CVE-2026-46786 | 9.6 | 11.7 | Oracle Corporation | Oracle WebCenter Content | CWE-352 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-0156 | 7.5 | 11.7 | Android | CWE-476 | In checkSsrcCollisionOnRcv of RtpSession.cpp, there is a possible memory safe… | |
| CVE-2026-12319 | 6.5 | 11.5 | Mozilla | Firefox | CWE-400 | Denial-of-service in the Audio/Video: Playback component |
| CVE-2026-53844 | 6.0 | 11.5 | OpenClaw | OpenClaw | CWE-862 | OpenClaw < 2026.4.29 - Session Visibility Check Bypass in Shared Memory Search |
| CVE-2026-53859 | 6.0 | 11.5 | OpenClaw | OpenClaw | CWE-918 | OpenClaw < 2026.5.26 - Hostname Validation Bypass via Trailing-Dot Inconsistency |
| CVE-2026-48781 | 9.9 | 11.4 | gitroomhq | postiz-app | CWE-302 | Postiz has cross-tenant SUPERADMIN takeover via Skool-provider JWT forgery |
| CVE-2026-12324 | 7.3 | 11.3 | Mozilla | Firefox | CWE-703 | Incorrect boundary conditions in the Graphics: CanvasWebGL component |
| CVE-2026-1764 | 5.6 | 11.3 | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Localsearch: tracker-miners: gnome localsearch mp3 extractor: heap buffer ove… |
| CVE-2025-71261 | 8.6 | 11.2 | SUSE | Harvester | CWE-295 | Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS |
| CVE-2026-12322 | 5.4 | 11.1 | Mozilla | Firefox | CWE-1021 | Clickjacking issue in the Widget: Gtk component |
| CVE-2026-47964 | 7.8 | 11.0 | Adobe | DNG SDK | CWE-122 | DNG SDK | Heap-based Buffer Overflow (CWE-122) |
| CVE-2026-53852 | 2.3 | 11.0 | OpenClaw | OpenClaw | CWE-636 | OpenClaw < 2026.4.25 - Scope Bypass via Empty-Scope Device Re-pairing |
| CVE-2026-49073 | 8.5 | 10.8 | wpWax | Directorist Booking | CWE-89 | WordPress Directorist Booking plugin <= 3.0.3 - SQL Injection vulnerability |
| CVE-2026-39577 | 5.5 | 10.9 | Elated-Themes | Playroom | CWE-502 | WordPress Playroom theme <= 1.4.1 - PHP Object Injection vulnerability |
| CVE-2026-10780 | 4.3 | 10.8 | mohammadtanzilurrahman | Static Block | CWE-639 | Static Block <= 2.2 - Insecure Direct Object Reference to Authenticated (Cont… |
| CVE-2026-47749 | 7.8 | 10.6 | leejet | stable-diffusion.cpp | CWE-122 | stable-diffusion.cpp: Heap buffer overflow in SHORT_BINUNICODE parsing for Py… |
| CVE-2026-35272 | 8.4 | 10.2 | Oracle Corporation | PeopleSoft Enterprise PT PeopleTools | CWE-269 | Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle P… |
| CVE-2026-0141 | 4.3 | 10.2 | Android | CWE-120 | In decodeAppPacket of RtcpAppPacket.cpp, there is a possible OOB read due to … | |
| CVE-2024-30476 | 5.4 | 10.0 | Dell | PowerStore | CWE-79 | PowerStore contains a Stored Cross-Site Scripting Vulnerability in the PowerS… |
| CVE-2026-54191 | 7.1 | 9.9 | Pods Framework | Pods | CWE-79 | WordPress Pods plugin <= 3.3.8 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-54198 | 7.1 | 9.9 | David Lingren | Media LIbrary Assistant | CWE-79 | WordPress Media LIbrary Assistant plugin <= 3.35 - Reflected Cross Site Scrip… |
| CVE-2026-46785 | 9.3 | 9.7 | Oracle Corporation | Oracle WebCenter Content | CWE-352 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-40809 | 6.5 | 9.7 | Rara Themes | Metro Magazine | CWE-862 | WordPress Metro Magazine theme <= 1.4.1 - Broken Access Control vulnerability |
| CVE-2026-24155 | 7.8 | 9.4 | NVIDIA | NeMo Framework | CWE-94 | NVIDIA NeMo Framework for all platforms contains a code injection vulnerabili… |
| CVE-2026-53851 | 6.3 | 9.1 | OpenClaw | OpenClaw | CWE-862 | OpenClaw < 2026.5.12 - Slack Reaction Event Notification Bypass |
| CVE-2026-12304 | 9.1 | 8.9 | Mozilla | Firefox | CWE-346 | Same-origin policy bypass in the Networking: Cookies component |
| CVE-2026-2604 | 5.6 | 8.9 | GNOME | Evolution Data Server | CWE-73 | Evolution-data-server: evolution data server: arbitrary file deletion via inc… |
| CVE-2026-35288 | 8.2 | 8.7 | Oracle Corporation | PeopleSoft Enterprise PT PeopleTools | CWE-269 | Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle P… |
| CVE-2026-53841 | 2.1 | 8.7 | OpenClaw | OpenClaw | CWE-83 | OpenClaw < 2026.5.12 - Cross-Site Scripting via Unsafe Markdown Links in Expo… |
| CVE-2026-48869 | 7.1 | 8.5 | Kriesi | Enfold | CWE-79 | WordPress Enfold theme <= 7.1.4 - Reflected Cross Site Scripting (XSS) vulner… |
| CVE-2026-12311 | 4.7 | 8.4 | Mozilla | Firefox | CWE-200 | Information disclosure, sandbox escape in the Security: Process Sandboxing co… |
| CVE-2026-53845 | 2.3 | 8.3 | OpenClaw | OpenClaw | CWE-693 | OpenClaw < 2026.5.6 - Skill-Command Dispatch Hook Bypass via Before-Tool-Call… |
| CVE-2026-53848 | 2.3 | 8.4 | OpenClaw | OpenClaw | CWE-184 | OpenClaw < 2026.5.26 - Exec Allowlist Bypass via Transparent Command Wrappers |
| CVE-2026-0128 | 6.5 | 8.1 | Android | CWE-190 | In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read d… | |
| CVE-2026-47747 | 7.8 | 7.9 | leejet | stable-diffusion.cpp | CWE-122 | stable-diffusion.cpp has a Heap-based Buffer Overflow |
| CVE-2026-47750 | 7.8 | 7.9 | leejet | stable-diffusion.cpp | CWE-787 | stable-diffusion.cpp: Heap buffer overflow in GLOBAL opcode parsing for PyTor… |
| CVE-2025-69151 | 7.1 | 7.8 | ThemeGoods | Grand Car Rental | CWE-79 | WordPress Grand Car Rental theme <= 3.7 - Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-46869 | 6.5 | 7.9 | Oracle Corporation | MySQL Shell | CWE-352 | Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: D… |
| CVE-2026-12320 | 4.3 | 7.7 | Mozilla | Firefox | CWE-200 | Information disclosure in the Password Manager component |
| CVE-2026-0140 | 4.3 | 7.6 | Android | CWE-125 | In RtpPacket::decodePacket, there is a possible out-of-bounds read due to an … | |
| CVE-2026-53847 | 5.3 | 7.5 | OpenClaw | OpenClaw | CWE-266 | OpenClaw < 2026.5.6 - Privilege Escalation via Active Memory Write Scope |
| CVE-2026-39548 | 7.1 | 7.3 | Sneeit | MagOne | CWE-79 | WordPress MagOne theme <= 9.0 - Reflected Cross Site Scripting (XSS) vulnerab… |
| CVE-2026-12313 | 4.7 | 7.3 | Mozilla | Firefox | CWE-269 | Information disclosure, sandbox escape in the Security: Process Sandboxing co… |
| CVE-2026-0130 | 3.5 | 7.1 | Android | CWE-122 | In RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read due to … | |
| CVE-2026-42089 | 8.6 | 7.0 | yeoman | environment | CWE-829 | yeoman-environment Vulnerable to Arbitrary Package Installation without User … |
| CVE-2026-52714 | 5.9 | 6.9 | SEO Squirrly | SEO Plugin by Squirrly SEO | CWE-862 | WordPress SEO Plugin by Squirrly SEO plugin <= 12.4.16 - Broken Access Contro… |
| CVE-2026-0165 | 5.7 | 6.8 | Android | CWE-120 | In several functions of the RTCP packet decoder, there is a possible out-of-b… | |
| CVE-2026-53860 | 2.3 | 6.8 | OpenClaw | OpenClaw | CWE-807 | OpenClaw < 2026.5.7 - Sender Policy Bypass via Mutable Conversation Identifie… |
| CVE-2025-11694 | 8.7 | 6.7 | Rockwell Automation | CompactLogix 5370 | CWE-354 | Rockwell Automation CompactLogix 5370 Controllers – Multiple Vulnerabilities |
| CVE-2026-48783 | 4.8 | 6.8 | gitroomhq | postiz-app | CWE-345 | Postiz has an unauthenticated billing-enforcement bypass via /public/modify-s… |
| CVE-2026-53863 | 6.0 | 6.7 | OpenClaw | OpenClaw | CWE-639 | OpenClaw < 2026.4.25 - Unvalidated Group ID Acceptance in Tool Group Policy |
| CVE-2026-0155 | 4.3 | 6.6 | Android | CWE-120 | In ImsMediaBitReader::ReadByteBuffer, there is a possible OOB read due to a m… | |
| CVE-2026-0157 | 4.3 | 6.6 | Android | CWE-120 | In RtcpHeader::decodeRtcpHeader, there is a possible OOB read due to a missin… | |
| CVE-2026-46865 | 8.2 | 6.6 | Oracle Corporation | Oracle Enterprise Manager Base Platform | CWE-284 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracl… |
| CVE-2026-46894 | 8.0 | 6.5 | Oracle Corporation | Oracle iSupplier Portal | CWE-352 | Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Sui… |
| CVE-2026-12323 | 5.4 | 6.5 | Mozilla | Firefox | CWE-1021 | Spoofing issue in the DOM: Core & HTML component |
| CVE-2026-0129 | 3.5 | 6.6 | Android | CWE-120 | In RtcpByePacket::decodeByePacket, there is a possible due to a missing bound… | |
| CVE-2026-46877 | 6.0 | 6.4 | Oracle Corporation | Oracle VM VirtualBox | CWE-269 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-47927 | 5.5 | 6.2 | Adobe | DNG SDK | CWE-125 | DNG SDK | Out-of-bounds Read (CWE-125) |
| CVE-2026-47934 | 5.5 | 6.2 | Adobe | DNG SDK | CWE-125 | DNG SDK | Out-of-bounds Read (CWE-125) |
| CVE-2026-47963 | 5.5 | 6.2 | Adobe | DNG SDK | CWE-125 | DNG SDK | Out-of-bounds Read (CWE-125) |
| CVE-2026-10635 | 6.3 | 6.0 | zephyrproject | zephyr | CWE-416 | Dangling memory-domain pointer (use-after-free) in Xtensa MMU page-table code… |
| CVE-2026-12330 | 5.4 | 6.1 | Mozilla | Firefox | CWE-119 | Incorrect boundary conditions in the Internationalization component |
| CVE-2026-47748 | 5.5 | 6.0 | leejet | stable-diffusion.cpp | CWE-125 | stable-diffusion.cpp: Out-of-bounds reads in PyTorch checkpoint pickle opcode… |
| CVE-2026-46815 | 3.2 | 5.9 | Oracle Corporation | Oracle VM VirtualBox | CWE-200 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-46816 | 3.2 | 5.9 | Oracle Corporation | Oracle VM VirtualBox | CWE-200 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-46977 | 3.2 | 5.9 | Oracle Corporation | Oracle VM VirtualBox | CWE-200 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-24228 | 7.8 | 5.8 | NVIDIA | NeMo Framework | CWE-502 | NVIDIA NeMo Framework for Linux contains a vulnerability where an attacker ma… |
| CVE-2026-46787 | 8.0 | 5.7 | Oracle Corporation | Oracle WebCenter Content | CWE-352 | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middle… |
| CVE-2026-46825 | 6.0 | 5.6 | Oracle Corporation | Oracle VM VirtualBox | CWE-284 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-12321 | 5.4 | 5.6 | Mozilla | Firefox | CWE-670 | JIT miscompilation in the JavaScript: WebAssembly component |
| CVE-2026-1766 | 6.1 | 5.5 | Red Hat | Red Hat Enterprise Linux 10 | CWE-805 | Localsearch: tracker-miners: gnome localsearch mp3 extractor: denial of servi… |
| CVE-2026-46955 | 7.5 | 5.3 | Oracle Corporation | Oracle Human Resources | CWE-79 | Vulnerability in the Oracle Human Resources product of Oracle E-Business Suit… |
| CVE-2026-46914 | 7.1 | 5.1 | Oracle Corporation | Oracle Solaris | CWE-269 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Fil… |
| CVE-2026-42014 | 6.6 | 4.7 | Red Hat | Red Hat Enterprise Linux 10 | CWE-825 | Gnutls: gnutls: use-after-free in gnutls_pkcs11_token_set_pin |
| CVE-2026-46768 | 6.0 | 4.7 | Oracle Corporation | Oracle VM VirtualBox | CWE-284 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-12425 | 5.7 | 4.6 | PowerSchool | Employee Access Center | CWE-79 | Reflected / DOM cross-site scripting (XSS) in PowerSchool ERP / Employee Acce… |
| CVE-2026-35275 | 7.5 | 4.5 | Oracle Corporation | Oracle VM VirtualBox | CWE-284 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-12003 | 5.3 | 4.4 | Python Software Foundation | CPython | CWE-427 | CPython >3.11 Insecure Input Validation resulting in privilege escalation |
| CVE-2026-39437 | 7.1 | 4.0 | WPFactory | Min Max Step Quantity Limits Manager for WooCommerce | CWE-79 | WordPress Min Max Step Quantity Limits Manager for WooCommerce plugin <= 5.2.… |
| CVE-2026-46848 | 7.9 | 4.0 | Oracle Corporation | WebLogic Server | CWE-284 | Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (com… |
| CVE-2026-46913 | 9.3 | 3.9 | Oracle Corporation | JD Edwards EnterpriseOne Tools | CWE-284 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwa… |
| CVE-2026-46974 | 7.5 | 3.9 | Oracle Corporation | Oracle VM VirtualBox | CWE-284 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-8484 | 4.8 | 3.9 | FuseSource | jansi | CWE-122 | Heap buffer overflow in Jansi |
| CVE-2026-1765 | 5.6 | 3.7 | Red Hat | Red Hat Enterprise Linux 10 | CWE-125 | Localsearch: tracker-miners: gnome localsearch mp3 extractor: denial of servi… |
| CVE-2026-46771 | 4.1 | 3.4 | Oracle Corporation | Oracle Application Development Framework (ADF) | CWE-284 | Vulnerability in the Oracle Application Development Framework (ADF) product o… |
| CVE-2026-53842 | 7.0 | 3.3 | OpenClaw | OpenClaw | CWE-426 | OpenClaw < 2026.5.2 - Arbitrary Python Runtime Execution via CLOUDSDK_PYTHON … |
| CVE-2026-46772 | 4.7 | 3.2 | Oracle Corporation | Oracle Application Development Framework (ADF) | CWE-284 | Vulnerability in the Oracle Application Development Framework (ADF) product o… |
| CVE-2026-4367 | 5.5 | 2.9 | Red Hat | Red Hat Hardened Images | CWE-125 | Libxpm: libxpm: denial of service via out-of-bounds read in xpm file parsing |
| CVE-2026-46874 | 3.2 | 3.0 | Oracle Corporation | Oracle VM VirtualBox | CWE-200 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2026-53858 | 7.0 | 2.6 | OpenClaw | OpenClaw | CWE-426 | OpenClaw < 2026.5.2 - Arbitrary Runtime Dependency Loading via STATE_DIRECTOR… |
| CVE-2026-53865 | 7.2 | 2.5 | OpenClaw | OpenClaw | CWE-426 | OpenClaw < 2026.5.2 - Arbitrary Command Execution via Workspace-Derived Servi… |
| CVE-2026-46926 | 8.8 | 2.1 | Oracle Corporation | Siebel CRM Cloud Applications | CWE-284 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel C… |
| CVE-2026-46888 | 7.8 | 2.1 | Oracle Corporation | Siebel CRM Deployment | CWE-284 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (comp… |
| CVE-2026-53846 | 7.0 | 2.0 | OpenClaw | OpenClaw | CWE-426 | OpenClaw < 2026.4.29 - Arbitrary Package Manager Execution via Workspace .env… |
| CVE-2025-10262 | 6.3 | 1.9 | Nokia | SR Linux | CWE-134 | An unsanitized format validation vulnerability in Nokia SR Linux |
| CVE-2026-46873 | 7.5 | 1.7 | Oracle Corporation | Oracle VM VirtualBox | CWE-269 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (c… |
| CVE-2025-9912 | 6.3 | 1.5 | Nokia | Nokia SR Linux | CWE-269 | A local privilege escalation vulnerability in Nokia SR Linux |
| CVE-2026-0135 | 7.8 | 1.1 | Android | CWE-125 | In Modem, there is a possible out of bounds read due to a missing bounds chec… | |
| CVE-2026-53900 | 4.3 | 1.0 | Mozilla | Firefox for iOS | CWE-345 | Cookie injection was possible when opening a PDF link |
| CVE-2024-22451 | 6.7 | 0.9 | Dell | Peripheral Manager | CWE-427 | Dell Peripheral Manager, versions from 1.5.1 to 1.7.2, contain an uncontrolle… |
| CVE-2024-22447 | 7.8 | 0.9 | Dell | Peripheral Manager | CWE-427 | Dell Peripheral Manager, versions prior to 1.7.3, contain an uncontrolled sea… |
| CVE-2024-39575 | 7.4 | 0.8 | Dell | Dell EMC VxRail Appliance | CWE-256 | update_disk_psu_baseline.sh requires password in plain text |
| CVE-2026-53899 | 6.5 | 0.8 | Mozilla | Firefox for iOS | CWE-345 | Cross-origin cookies could be leaked when opening a PDF link |
| CVE-2026-53856 | 5.7 | 0.7 | OpenClaw | OpenClaw | CWE-732 | OpenClaw 2026.4.23 < 2026.4.24 - Insecure File Permissions in Config Recovery… |
| CVE-2026-53850 | 6.8 | 0.7 | OpenClaw | OpenClaw | CWE-862 | OpenClaw < 2026.4.25 - Control Scope Enforcement Bypass in Focus Command |
| CVE-2026-50255 | 5.4 | 0.5 | Sony Corporation | Optical Disc Archive Software for Windows | CWE-276 | Incorrect default permissions issue exists in Optical Disc Archive Software f… |
| CVE-2026-53862 | 2.3 | 0.5 | OpenClaw | OpenClaw | CWE-266 | OpenClaw < 2026.5.12 - Bootstrap Token Replay via Pending Pairing Scope Widening |
| CVE-2024-38487 | 7.0 | 0.2 | Dell | EMC VxRail Appliance | CWE-269 | api-gateway container running with root privilege would allow an attacker to … |
| CVE-2026-0137 | 7.8 | 0.1 | Android | CWE-416 | In edgetpu_sync_fence_group_shutdown() of edgetpu-dmabuf.c, there is a possib… | |
| CVE-2026-0138 | 7.8 | 0.1 | Android | CWE-120 | In lwis_io_buffer_write of lwis_io_buffer.c, there is a possible out of bound… | |
| CVE-2026-0143 | 7.8 | 0.1 | Android | CWE-416 | In lwis_device_external_event_emit of lwis_event.c, there is a possible memor… | |
| CVE-2026-0131 | 7.3 | 0.1 | Android | CWE-125 | In RtpPacket::decodePacket, there is a possible out of bounds access due to a… | |
| CVE-2026-0134 | 3.3 | 0.1 | Android | CWE-1188 | In PostWipeData of recovery_ui.cpp, there is a possible data persistence issu… | |
| CVE-2026-0152 | 7.8 | 0.1 | Android | CWE-119 | In OSMMapPMRGeneric of pmr_os.c, there is a possible way to leverage a system… | |
| CVE-2026-0142 | 3.3 | 0.0 | Android | CWE-20 | In iavb_parse_key_data of avb_rsa.c, there is a possible out of bounds read d… | |
| CVE-2026-0153 | 7.8 | 0.0 | Android | CWE-787 | In Write of msg_to_host_buffer.cc, there is a possible out of bounds write du… | |
| CVE-2026-0145 | 3.3 | 0.0 | Android | CWE-862 | In keymint, there is a possible Permission Bypass due to a logic error in the… | |
| CVE-2026-0133 | 7.8 | 0.0 | Android | CWE-862 | In smmu_attach_dev of arm-smmu-v3.c, there is a possible way to sign maliciou… | |
| CVE-2026-0150 | 7.8 | 0.0 | Android | CWE-190 | In ExecuteGraph command handler of EdgeTPU firmware, there is a possible out … | |
| CVE-2026-0125 | 7.0 | 0.0 | Android | CWE-416 | In multiple functions of vpu_ioctl.c, there is a possible use after free due … | |
| CVE-2026-0158 | 3.3 | 0.0 | Android | CWE-862 | In Camera, there is a possible unauthorized way to access photos due to a mis… |