Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-1292 — Tanium addressed an insertion of sensitive information into log file vulnerability in Tre…

Tanium addressed an insertion of sensitive information into log file vulnerability in Trends.

service_trends trends | Remote | Information Disclosure
Feb 20, 2026 Feb 27, 2026
Feb 20, 2026
Feb 27, 2026
1.7 LOW
CVE-2026-26958 — filippo.io/edwards25519 MultiScalarMult function produces invalid results or undefined be…

filippo.io/edwards25519 is a Go library implementing the edwards25519 elliptic curve with APIs for building cryptographic primitives. In versions 1.1.0 and earlier, MultiScalarMult produces invalid r…

Remote | Cryptography
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
5.4 MEDIUM
CVE-2026-26953 — Pi-hole Web Interface has Stored HTML Injection via X-Forwarded-For Header in Active Sess…

Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions 6.0 and above have a Stored HTML Injection vulnerability in th…

web_interface | Remote | Cross-Site Scripting
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
5.4 MEDIUM
CVE-2026-26952 — Pi-hole Web Interface has Stored HTML Injection via Local DNS Records (CNAME/Hosts) in da…

Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions 6.4 and below are vulnerable to stored HTML injection through t…

web_interface | Remote | Cross-Site Scripting
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
7.1 HIGH
CVE-2026-26327 — OpenClaw allows unauthenticated discovery TXT records to steer routing and TLS pinning

OpenClaw is a personal AI assistant. Discovery beacons (Bonjour/mDNS and DNS-SD) include TXT records such as `lanHost`, `tailnetDns`, `gatewayPort`, and `gatewayTlsSha256`. TXT records are unauthenti…

openclaw | Information Disclosure
Feb 19, 2026 Feb 23, 2026
Feb 19, 2026
Feb 23, 2026
5.3 MEDIUM
CVE-2026-26326 — OpenClaw skills.status could leak secrets to operator.read clients

OpenClaw is a personal AI assistant. Prior to version 2026.2.14, `skills.status` could disclose secrets to `operator.read` clients by returning raw resolved config values in `configChecks` for skill …

openclaw | Remote | Information Disclosure
Feb 19, 2026 Feb 23, 2026
Feb 19, 2026
Feb 23, 2026
7.2 HIGH
CVE-2026-26325 — OpenClaw Node host system.run rawCommand/command mismatch can bypass allowlist/approvals

OpenClaw is a personal AI assistant. Prior to version 2026.2.14, a mismatch between `rawCommand` and `command[]` in the node host `system.run` handler could cause allowlist/approval evaluation to be …

openclaw | Remote | Misconfiguration
Feb 19, 2026 Feb 23, 2026
Feb 19, 2026
Feb 23, 2026
7.5 HIGH
CVE-2026-26324 — OpenClaw has a SSRF guard bypass via full-form IPv4-mapped IPv6 (loopback / metadata reac…

OpenClaw is a personal AI assistant. Prior to version 2026.2.14, OpenClaw's SSRF protection could be bypassed using full-form IPv4-mapped IPv6 literals such as `0:0:0:0:0:ffff:7f00:1` (which is `127.…

openclaw | Remote | Server-Side Request Forgery
Feb 19, 2026 Feb 23, 2026
Feb 19, 2026
Feb 23, 2026
8.8 HIGH
CVE-2026-26323 — OpenClaw has a command injection in maintainer clawtributors updater

OpenClaw is a personal AI assistant. Versions 2026.1.8 through 2026.2.13 have a command injection in the maintainer/dev script `scripts/update-clawtributors.ts`. The issue affects contributors/mainta…

openclaw | Remote | Injection
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
7.6 HIGH
CVE-2026-26322 — OpenClaw Gateway tool allowed unrestricted gatewayUrl override

OpenClaw is a personal AI assistant. Prior to OpenClaw version 2026.2.14, the Gateway tool accepted a tool-supplied `gatewayUrl` without sufficient restrictions, which could cause the OpenClaw host t…

openclaw | Remote | Server-Side Request Forgery
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
7.5 HIGH
CVE-2026-26321 — OpenClaw has a local file disclosure via sendMediaFeishu in Feishu extension

OpenClaw is a personal AI assistant. Prior to OpenClaw version 2026.2.14, the Feishu extension previously allowed `sendMediaFeishu` to treat attacker-controlled `mediaUrl` values as local filesystem …

openclaw | Remote | Path Traversal
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
7.1 HIGH
CVE-2026-26320 — OpenClaw macOS deep link confirmation truncation can conceal executed agent message

OpenClaw is a personal AI assistant. OpenClaw macOS desktop client registers the `openclaw://` URL scheme. For `openclaw://agent` deep links without an unattended `key`, the app shows a confirmation …

macos openclaw | Remote | Information Disclosure
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
7.5 HIGH
CVE-2026-26319 — OpenClaw has Missing Webhook Authentication in Telnyx Provider Allowing Unauthenticated R…

OpenClaw is a personal AI assistant. Versions 2026.2.13 and below allow the optional @openclaw/voice-call plugin Telnyx webhook handler to accept unsigned inbound webhook requests when telnyx.publicK…

openclaw | Remote | Authentication
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
3.7 LOW
CVE-2026-24122 — Cosign Certificate Chain Expiry Validation Issue Allows Issuing Certificate Expiry to Be …

Cosign provides code signing and transparency for containers and binaries. In versions 3.0.4 and below, an issuing certificate with a validity that expires before the leaf certificate will be conside…

cosign | Remote | Cryptography
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
8.2 HIGH
CVE-2026-21535 — Microsoft Teams Information Disclosure Vulnerability

Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network.

Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
5.3 MEDIUM
CVE-2026-1658 — Content spoofing vulnerability discovered in OpenText™ Directory Services

User Interface (UI) Misrepresentation of Critical Information vulnerability in OpenText™ Directory Services allows Cache Poisoning.  The vulnerability could be exploited by a bad actor to inject man…

directory_services | Remote | Misconfiguration
Feb 19, 2026 Feb 26, 2026
Feb 19, 2026
Feb 26, 2026
7.5 HIGH
CVE-2025-9208 — Stored-XSS vulnerability discovered in OpenText WSM Management Server.

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Web Site Management Server allows Stored XSS. The vulnerability could execute ma…

web_site_management_server | Remote | Cross-Site Scripting
Feb 19, 2026 Feb 27, 2026
Feb 19, 2026
Feb 27, 2026
5.3 MEDIUM
CVE-2025-8055 — SSRF vulnerability have been discovered in OpenText™ XM Fax

Server-Side Request Forgery (SSRF) vulnerability in OpenText™ XM Fax allows Server Side Request Forgery.  The vulnerability could allow an attacker to perform blind SSRF to other systems accessib…

xm_fax | Remote | Server-Side Request Forgery
Feb 19, 2026 Feb 27, 2026
Feb 19, 2026
Feb 27, 2026
7.5 HIGH
CVE-2025-8054 — Path Traversal vulnerability have been discovered in OpenText™ XM Fax.

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText™ XM Fax allows Path Traversal.  The vulnerability could allow an attacker to arbitrarily disc…

xm_fax | Remote | Path Traversal
Feb 19, 2026 Feb 27, 2026
Feb 19, 2026
Feb 27, 2026
7.0 HIGH
CVE-2025-13672 — Reflected Cross-Site Scripting discovered in OpenText WSM Management Server.

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Web Site Management Server allows Reflected XSS. The vulnerability could allow i…

web_site_management_server | Remote | Cross-Site Scripting
Feb 19, 2026 Feb 27, 2026
Feb 19, 2026
Feb 27, 2026
Showing 20 of 5068 Results