7.5

CVSS3.1

CVE-2026-25474 - OpenClaw has a Telegram webhook request forgery (missing `channels.telegram.webhookSecret`) → auth …

OpenClaw is a personal AI assistant. In versions 2026.1.30 and below, if channels.telegram.webhookSecret is not set when in Telegram webhook mode, OpenClaw may accept webhook HTTP requests without verifying Telegram’s secret token header. In deployments where the webhook endpoint is reachable by an…

📅 Published: Feb. 19, 2026, 2:38 a.m. 🔄 Last Modified: Feb. 19, 2026, 8:13 p.m.

5.3

CVSS4.0

CVE-2026-25229 - Gogs Authorization Bypass Allows Cross-Repository Label Modification

Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have a broken access control vulnerability which allows authenticated users with write access to any repository to modify labels belonging to other repositories. The UpdateLabel function in the Web UI (internal/route/repo/iss…

📅 Published: Feb. 19, 2026, 2:33 a.m. 🔄 Last Modified: Feb. 19, 2026, 7:45 p.m.

5.3

CVSS4.0

CVE-2026-2693 - CoCoTeaNet CyreneAdmin System Info Endpoint getCount improper authorization

A vulnerability was determined in CoCoTeaNet CyreneAdmin up to 1.3.0. This vulnerability affects unknown code of the file /api/system/dashboard/getCount of the component System Info Endpoint. Executing a manipulation can lead to improper authorization. The attack can be launched remotely. The explo…

📅 Published: Feb. 19, 2026, 2:32 a.m. 🔄 Last Modified: Feb. 24, 2026, 1:44 a.m.

6.9

CVSS4.0

CVE-2026-25242 - Gogs allows unauthenticated file uploads

Gogs is an open source self-hosted Git service. Versions 0.13.4 and below expose unauthenticated file upload endpoints by default. When the global RequireSigninView setting is disabled (default), any remote user can upload arbitrary files to the server via /releases/attachments and /issues/attachme…

📅 Published: Feb. 19, 2026, 2:28 a.m. 🔄 Last Modified: Feb. 19, 2026, 7:46 p.m.

7.1

CVSS4.0

CVE-2026-25232 - Gogs has a Protected Branch Deletion Bypass in Web Interface

Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have an access control bypass vulnerability which allows any repository collaborator with Write permissions to delete protected branches (including the default branch) by sending a direct POST request, completely bypassing th…

📅 Published: Feb. 19, 2026, 2:25 a.m. 🔄 Last Modified: Feb. 19, 2026, 7:44 p.m.

5.3

CVSS4.0

CVE-2026-2692 - CoCoTeaNet CyreneAdmin Image getAvatar path traversal

A vulnerability was found in CoCoTeaNet CyreneAdmin up to 1.3.0. This affects an unknown part of the file /api/system/user/getAvatar of the component Image Handler. Performing a manipulation of the argument Avatar results in path traversal. The attack can be initiated remotely. The exploit has been…

📅 Published: Feb. 19, 2026, 2:02 a.m. 🔄 Last Modified: Feb. 24, 2026, 1:45 a.m.

5.1

CVSS4.0

CVE-2026-25120 - Gogs Allows Cross-Repository Comment Deletion via DeleteComment

Gogs is an open source self-hosted Git service. In versions 0.13.4 and below, the DeleteComment API does not verify that the comment belongs to the repository specified in the URL. This allows a repository administrator to delete comments from any other repository by supplying arbitrary comment IDs…

📅 Published: Feb. 19, 2026, 1:59 a.m. 🔄 Last Modified: Feb. 19, 2026, 7:48 p.m.

7.8

CVSS3.1

CVE-2025-4960 - macOS Local Privilege Escalation via Improper Authorization Handling in EPSON Printer Controller In…

The com.epson.InstallNavi.helper tool, deployed with the EPSON printer driver installer, contains a local privilege escalation vulnerability due to multiple flaws in its implementation. It fails to properly authenticate clients over the XPC protocol and does not correctly enforce macOS’s authorizat…

📅 Published: Feb. 19, 2026, 1:37 a.m. 🔄 Last Modified: Feb. 24, 2026, 1:47 a.m.

6.9

CVSS4.0

CVE-2026-2691 - itsourcecode Event Management System manage_register.php sql injection

A vulnerability has been found in itsourcecode Event Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/manage_register.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been di…

📅 Published: Feb. 19, 2026, 1:32 a.m. 🔄 Last Modified: Feb. 24, 2026, 3:41 p.m.

3.7

CVSS3.1

CVE-2026-24764 - OpenClaw has Remote Code Execution via System Prompt Injection in Slack Channel Descriptions

OpenClaw (formerly Clawdbot) is a personal AI assistant users run on their own devices. In versions 2026.2.2 and below, when the Slack integration is enabled, channel metadata (topic/description) can be incorporated into the model's system prompt. Prompt injection is a documented risk for LLM-drive…

📅 Published: Feb. 19, 2026, 1:10 a.m. 🔄 Last Modified: Feb. 19, 2026, 6:30 p.m.
Total resulsts: 343984
Page 1061 of 34,399
« previous page » next page
Filters