0.0

CVE-2026-32012 -

This CVE ID has been rejected.

πŸ“… Published: March 23, 2026, 9:36 p.m. πŸ”„ Last Modified: March 23, 2026, 11:17 p.m.

0.0

CVE-2026-28483 -

This CVE ID has been rejected.

πŸ“… Published: March 23, 2026, 9:36 p.m. πŸ”„ Last Modified: March 23, 2026, 11:17 p.m.

0.0

CVE-2026-28455 -

This CVE ID has been rejected.

πŸ“… Published: March 23, 2026, 9:36 p.m. πŸ”„ Last Modified: March 23, 2026, 11:17 p.m.

5.8

CVSS4.0

CVE-2026-27646 - OpenClaw < 2026.3.7 - Sandbox Escape via /acp spawn Command

OpenClaw versions prior to 2026.3.7 contain a sandbox escape vulnerability in the /acp spawn command that allows authorized sandboxed sessions to initialize host-side ACP runtime. Attackers can bypass sandbox restrictions by invoking the /acp spawn slash-command to cross from sandboxed chat context…

πŸ“… Published: March 23, 2026, 9:36 p.m. πŸ”„ Last Modified: March 25, 2026, 8:36 p.m.

2.1

CVSS4.0

CVE-2026-27183 - OpenClaw < 2026.3.7 - Shell Approval Gating Bypass via Dispatch Wrapper Depth Mismatch

OpenClaw versions prior to 2026.3.7 contain a shell approval gating bypass vulnerability in system.run dispatch-wrapper handling that allows attackers to skip shell wrapper approval requirements. The approval classifier and execution planner apply different depth-boundary rules, permitting exactly …

πŸ“… Published: March 23, 2026, 9:35 p.m. πŸ”„ Last Modified: March 25, 2026, 8:36 p.m.

0.0

CVE-2026-22173 -

This CVE ID has been rejected.

πŸ“… Published: March 23, 2026, 9:35 p.m. πŸ”„ Last Modified: March 23, 2026, 11:17 p.m.

8.2

CVSS3.1

CVE-2026-32278 - Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin

Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, a Stored Cross-site Scripting (XSS) issue exists in the file field of the Form Plugin. Versions 1.41.1 and 2.41.1 contain a patch.

πŸ“… Published: March 23, 2026, 9:28 p.m. πŸ”„ Last Modified: March 25, 2026, 8:36 p.m.

8.7

CVSS3.1

CVE-2026-32277 - Connect-CMS has DOM-based Cross-Site Scripting (XSS) in the Cabinet Plugin List View

Connect-CMS is a content management system. In versions 1.35.0 through 1.41.0 and 2.35.0 through 2.41.0, a DOM-based Cross-Site Scripting (XSS) issue exists in the Cabinet Plugin list view. Versions 1.41.1 and 2.41.1 contain a patch.

πŸ“… Published: March 23, 2026, 9:22 p.m. πŸ”„ Last Modified: March 25, 2026, 8:36 p.m.

8.6

CVSS4.0

CVE-2026-4611 - TOTOLINK X6000R shttpd setLanCfg privilege escalation

A flaw has been found in TOTOLINK X6000R 9.4.0cu.1360_B20241207/9.4.0cu.1498_B20250826. Affected by this issue is the function setLanCfg of the file /usr/sbin/shttpd. Executing a manipulation of the argument Hostname can lead to os command injection. The attack may be launched remotely.

πŸ“… Published: March 23, 2026, 9:13 p.m. πŸ”„ Last Modified: March 25, 2026, 7:14 p.m.

8.8

CVSS3.1

CVE-2026-32276 - Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin

Connect-CMS is a content management system. In versions on the 1.x series up to and including 1.41.0 and versions on the 2.x series up to and including 2.41.0, an authenticated user may be able to execute arbitrary code in the Code Study Plugin. Versions 1.41.1 and 2.41.1 contain a patch.

πŸ“… Published: March 23, 2026, 9:06 p.m. πŸ”„ Last Modified: March 25, 2026, 8:36 p.m.
Total resulsts: 340823
Page 130 of 34,083
Β« previous page Β» next page
Filters