Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-26323 — OpenClaw has a command injection in maintainer clawtributors updater

OpenClaw is a personal AI assistant. Versions 2026.1.8 through 2026.2.13 have a command injection in the maintainer/dev script `scripts/update-clawtributors.ts`. The issue affects contributors/mainta…

openclaw | Remote | Injection
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
7.6 HIGH
CVE-2026-26322 — OpenClaw Gateway tool allowed unrestricted gatewayUrl override

OpenClaw is a personal AI assistant. Prior to OpenClaw version 2026.2.14, the Gateway tool accepted a tool-supplied `gatewayUrl` without sufficient restrictions, which could cause the OpenClaw host t…

openclaw | Remote | Server-Side Request Forgery
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
7.5 HIGH
CVE-2026-26321 — OpenClaw has a local file disclosure via sendMediaFeishu in Feishu extension

OpenClaw is a personal AI assistant. Prior to OpenClaw version 2026.2.14, the Feishu extension previously allowed `sendMediaFeishu` to treat attacker-controlled `mediaUrl` values as local filesystem …

openclaw | Remote | Path Traversal
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
7.1 HIGH
CVE-2026-26320 — OpenClaw macOS deep link confirmation truncation can conceal executed agent message

OpenClaw is a personal AI assistant. OpenClaw macOS desktop client registers the `openclaw://` URL scheme. For `openclaw://agent` deep links without an unattended `key`, the app shows a confirmation …

macos openclaw | Remote | Information Disclosure
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
7.5 HIGH
CVE-2026-26319 — OpenClaw has Missing Webhook Authentication in Telnyx Provider Allowing Unauthenticated R…

OpenClaw is a personal AI assistant. Versions 2026.2.13 and below allow the optional @openclaw/voice-call plugin Telnyx webhook handler to accept unsigned inbound webhook requests when telnyx.publicK…

openclaw | Remote | Authentication
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
3.7 LOW
CVE-2026-24122 — Cosign Certificate Chain Expiry Validation Issue Allows Issuing Certificate Expiry to Be …

Cosign provides code signing and transparency for containers and binaries. In versions 3.0.4 and below, an issuing certificate with a validity that expires before the leaf certificate will be conside…

cosign | Remote | Cryptography
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
8.2 HIGH
CVE-2026-21535 — Microsoft Teams Information Disclosure Vulnerability

Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network.

Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
5.3 MEDIUM
CVE-2026-1658 — Content spoofing vulnerability discovered in OpenText™ Directory Services

User Interface (UI) Misrepresentation of Critical Information vulnerability in OpenText™ Directory Services allows Cache Poisoning.  The vulnerability could be exploited by a bad actor to inject man…

directory_services | Remote | Misconfiguration
Feb 19, 2026 Feb 26, 2026
Feb 19, 2026
Feb 26, 2026
7.5 HIGH
CVE-2025-9208 — Stored-XSS vulnerability discovered in OpenText WSM Management Server.

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Web Site Management Server allows Stored XSS. The vulnerability could execute ma…

web_site_management_server | Remote | Cross-Site Scripting
Feb 19, 2026 Feb 27, 2026
Feb 19, 2026
Feb 27, 2026
5.3 MEDIUM
CVE-2025-8055 — SSRF vulnerability have been discovered in OpenText™ XM Fax

Server-Side Request Forgery (SSRF) vulnerability in OpenText™ XM Fax allows Server Side Request Forgery.  The vulnerability could allow an attacker to perform blind SSRF to other systems accessib…

xm_fax | Remote | Server-Side Request Forgery
Feb 19, 2026 Feb 27, 2026
Feb 19, 2026
Feb 27, 2026
7.5 HIGH
CVE-2025-8054 — Path Traversal vulnerability have been discovered in OpenText™ XM Fax.

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText™ XM Fax allows Path Traversal.  The vulnerability could allow an attacker to arbitrarily disc…

xm_fax | Remote | Path Traversal
Feb 19, 2026 Feb 27, 2026
Feb 19, 2026
Feb 27, 2026
7.0 HIGH
CVE-2025-13672 — Reflected Cross-Site Scripting discovered in OpenText WSM Management Server.

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Web Site Management Server allows Reflected XSS. The vulnerability could allow i…

web_site_management_server | Remote | Cross-Site Scripting
Feb 19, 2026 Feb 27, 2026
Feb 19, 2026
Feb 27, 2026
6.5 MEDIUM
CVE-2025-13671 — Cross Site request forgery vulnerability discovered in OpenText WSM Management Server.

Cross-Site Request Forgery (CSRF) vulnerability in OpenText™ Web Site Management Server allows Cross Site Request Forgery. The vulnerability could make a user, with active session inside the product,…

web_site_management_server | Remote | Cross-Site Request Forgery
Feb 19, 2026 Feb 27, 2026
Feb 19, 2026
Feb 27, 2026
5.3 MEDIUM
CVE-2026-26744 — FormaLMS User Enumeration Vulnerability

A user enumeration vulnerability exists in FormaLMS 4.1.18 and below in the password recovery functionality accessible via the /lostpwd endpoint. The application returns different error messages for …

formalms | Remote | Information Disclosure
Feb 19, 2026 Feb 26, 2026
Feb 19, 2026
Feb 26, 2026
7.1 HIGH
CVE-2026-26317 — OpenClaw affected by cross-site request forgery (CSRF) through loopback browser mutation …

OpenClaw is a personal AI assistant. Prior to 2026.2.14, browser-facing localhost mutation routes accepted cross-origin browser requests without explicit Origin/Referer validation. Loopback binding r…

openclaw | Remote | Cross-Site Request Forgery
Feb 19, 2026 Feb 26, 2026
Feb 19, 2026
Feb 26, 2026
7.5 HIGH
CVE-2026-26316 — OpenClaw has BlueBubbles webhook auth bypass via loopback proxy trust

OpenClaw is a personal AI assistant. Prior to 2026.2.13, the optional BlueBubbles iMessage channel plugin could accept webhook requests as authenticated based only on the TCP peer address being loopb…

openclaw | Remote | Authentication
Feb 19, 2026 Feb 24, 2026
Feb 19, 2026
Feb 24, 2026
7.5 HIGH
CVE-2026-26315 — Go Ethereum Improperly Validates the ECIES Public Key in RLPx Handshake

go-ethereum (Geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, through a flaw in the ECIES cryptography implementation, an attacker may be able to ex…

go_ethereum | Remote | Cryptography
Feb 19, 2026 Feb 23, 2026
Feb 19, 2026
Feb 23, 2026
8.7 HIGH
CVE-2026-26314 — Go Ethereum affected by DoS via malicious p2p message

go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.16.9, a vulnerable node can be forced to shutdown/crash using a specially crafted message. T…

go_ethereum | Remote | Denial of Service
Feb 19, 2026 Feb 23, 2026
Feb 19, 2026
Feb 23, 2026
7.5 HIGH
CVE-2026-26275 — httpsig-hyper has Improper Digest Verification that May Allow Message Integrity Bypass

httpsig-hyper is a hyper extension for http message signatures. An issue was discovered in `httpsig-hyper` prior to version 0.0.23 where Digest header verification could incorrectly succeed due to mi…

httpsig-hyper | Remote | Cryptography
Feb 19, 2026 Mar 03, 2026
Feb 19, 2026
Mar 03, 2026
5.6 MEDIUM
CVE-2026-2738 — OpenVPN Buffer Overflow Denial of Service

Buffer overflow in ovpn‑dco‑win version 2.8.0 allows local attackers to cause a system crash by sending too large packets to the remote peer when the AEAD tag appears at the end of the encrypted pack…

ovpn-dco-win | Memory Corruption
Feb 19, 2026 Feb 20, 2026
Feb 19, 2026
Feb 20, 2026
Showing 20 of 5066 Results