MEDIUM4.3CVE-2026-53845OpenClaw: Skill-command dispatch could skip before-tool-call hooks
MEDIUM6.1OpenClaw: Exported session HTML could keep unsafe markdown links
MEDIUM5.3OpenClaw: Slack reaction events could ignore reaction notification settings
MEDIUM4.2OpenClaw: Bootstrap token replay could widen pending pairing scopes
MEDIUM6.5OpenClaw: Hostname checks could treat trailing-dot hosts inconsistently
MEDIUM4.3OpenClaw: Exec allowlist could miss side effects from transparent command wrappers
MEDIUM6.5NL Portal Backend Libraries: Document contents remained downloadable by any logged-in user (incomplete fix of CVE-2026-49463)
MEDIUM6.6OpenClaw: macOS Swift exec allowlist missed combined POSIX inline flags
MEDIUM5.4Strimzi: Unrestricted access to all Secrets within namespace watched by the Topic operator
MEDIUM5.3joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards.
MEDIUM5.9undici vulnerable to HTTP header injection via Set-Cookie percent-decoding
MEDIUM5.9undici vulnerable to cross-user information disclosure via shared cache whitespace bypass
LOW3.7undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse
LOW3.7undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching
MEDIUM5.8Shaarli is a personal bookmarking service.
MEDIUM5.9libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO hand…
MEDIUM4.8Shaarli is a personal bookmarking service.
MEDIUM5.8Shaarli is a personal bookmarking service.
MEDIUM6.0OpenStack Horizon RC file generation does not escape special characters in project names
MEDIUM6.5Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.
MEDIUM6.5Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.
MEDIUM4.9Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects
MEDIUM5.3webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies
MEDIUM5.3Multer vulnerable to Denial of Service via incomplete cleanup of aborted uploads
MEDIUM5.4A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c.