5.4

CVSS3.1

CVE-2026-27693 - traccar allows XML injection in KML and GPX exports

Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the KML and GPX export functionality writes device names to XML output without proper escaping. An attacker with low privileges can create a device with a crafted name that injects XML c…

πŸ“… Published: May 5, 2026, 12:17 p.m. πŸ”„ Last Modified: May 6, 2026, 12:43 p.m.

7.3

CVSS4.0

CVE-2026-7832 - IObit Advanced SystemCare Service ASC.exe symlink

A security flaw has been discovered in IObit Advanced SystemCare 19. This affects an unknown part of the file ASC.exe of the component Service. The manipulation results in symlink following. Attacking locally is a requirement. This attack is characterized by high complexity. It is indicated that th…

πŸ“… Published: May 5, 2026, 12:15 p.m. πŸ”„ Last Modified: May 5, 2026, 2:30 p.m.

6.5

CVSS3.1

CVE-2026-27644 - traccar allows CSV formula injection via exported position data

Traccar is an open source GPS tracking system. In versions between 6.11.1 and 6.13.0, the CSV export functionality writes position data, including user-controlled device and computed attributes, to CSV output without proper escaping. An attacker can inject spreadsheet formulas through exported fiel…

πŸ“… Published: May 5, 2026, 12:12 p.m. πŸ”„ Last Modified: May 5, 2026, 2:30 p.m.

6

CVSS4.0

CVE-2026-43574 - OpenClaw < 2026.4.12 - Improper Authorization via Empty Approver Lists

OpenClaw before 2026.4.12 contains an improper authorization vulnerability in helper-backed channels where empty resolved approver lists are interpreted as explicit approval authorization. Attackers can resolve pending approvals without proper authorization by exploiting this logic flaw if they kno…

πŸ“… Published: May 5, 2026, 11:25 a.m. πŸ”„ Last Modified: May 5, 2026, 12:45 p.m.

4.9

CVSS4.0

CVE-2026-43573 - OpenClaw < 2026.4.10 - SSRF Policy Bypass in Existing-Session Browser Interaction Routes

OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in existing-session browser interaction routes. Attackers can bypass SSRF navigation guards to interact with or navigate to unauthorized targets without policy enforcement.

πŸ“… Published: May 5, 2026, 11:25 a.m. πŸ”„ Last Modified: May 5, 2026, 2:30 p.m.

6.3

CVSS4.0

CVE-2026-43572 - OpenClaw 2026.4.10 < 2026.4.14 - Missing Sender Authorization in Microsoft Teams SSO Invoke Handler

OpenClaw versions 2026.4.10 before 2026.4.14 contain a missing authorization vulnerability in the Microsoft Teams SSO invoke handler that fails to apply sender allowlist checks. Attackers can bypass sender authorization by sending SSO invoke requests that are processed without proper validation, al…

πŸ“… Published: May 5, 2026, 11:25 a.m. πŸ”„ Last Modified: May 5, 2026, 2:24 p.m.

7.7

CVSS4.0

CVE-2026-43571 - OpenClaw < 2026.4.10 - Untrusted Workspace Plugin Shadow Resolution in Channel Setup

OpenClaw before 2026.4.10 contains a plugin trust bypass vulnerability that allows channel setup catalog lookups to resolve workspace plugin shadows before bundled channel plugins. Attackers can exploit this by crafting malicious workspace plugins that bypass intended trust gates during setup-time …

πŸ“… Published: May 5, 2026, 11:25 a.m. πŸ”„ Last Modified: May 5, 2026, 11:58 a.m.

6

CVSS4.0

CVE-2026-43570 - OpenClaw 2026.3.22 < 2026.4.5 - Symlink Traversal in Remote Marketplace Repository Path Handling

OpenClaw versions 2026.3.22 before 2026.4.5 contain a symlink traversal vulnerability in remote marketplace repository path handling that allows attackers to escape the expected repository root. Attackers can exploit this by providing crafted symlink paths to access files outside the intended repos…

πŸ“… Published: May 5, 2026, 11:25 a.m. πŸ”„ Last Modified: May 6, 2026, 2:13 p.m.

7.7

CVSS4.0

CVE-2026-43569 - OpenClaw < 2026.4.9 - Untrusted Provider Plugin Auto-enablement via Workspace Provider Auth

OpenClaw before 2026.4.9 contains an authentication bypass vulnerability allowing untrusted workspace plugins to be auto-enabled during non-interactive onboarding when provider auth choices are shadowed. Attackers can exploit this by crafting malicious workspace plugins that are automatically selec…

πŸ“… Published: May 5, 2026, 11:25 a.m. πŸ”„ Last Modified: May 6, 2026, 12:42 p.m.

7.1

CVSS4.0

CVE-2026-43568 - OpenClaw 2026.4.5 < 2026.4.10 - Privilege Escalation via Memory Dreaming Configuration in /dreaming…

OpenClaw versions 2026.4.5 before 2026.4.10 contain a privilege escalation vulnerability allowing write-scoped operators to modify persistent memory dreaming settings. Attackers with write-scoped gateway access can toggle admin-class configuration mutations through the /dreaming endpoint to escalat…

πŸ“… Published: May 5, 2026, 11:25 a.m. πŸ”„ Last Modified: May 5, 2026, 12:45 p.m.
Total resulsts: 349182
Page 113 of 34,919
Β« previous page Β» next page
Filters