|
311
|
6.5 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.4.27 contains an authorization bypass vulnerability in QQBot pre-dispatch slash commands that allows authenticated senders to skip allowFrom policy checks. Attackers can invoke s…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-53834
|
2026-06-16 09:28 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312
|
4.3 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.5.6 contains a configuration enforcement bypass vulnerability in Feishu dynamic-agent bindings that allows authenticated senders to create or update bindings without honoring con…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-53835
|
2026-06-16 09:25 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313
|
8.8 |
HIGH
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in PowerShell encoded-command handling that allows attackers to execute encoded commands using abbreviated flag aliases not recogn…
New
|
CWE-184
Incomplete Blacklist
|
CVE-2026-53836
|
2026-06-16 09:22 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314
|
5.3 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.5.6 contains an improper access control vulnerability in Mattermost event handlers that fails to validate channel type metadata. Attackers can bypass intended DM policy decisions…
New
|
CWE-636
Not Failing Securely ('Failing Open')
|
CVE-2026-53837
|
2026-06-16 09:21 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
315
|
5.8 |
MEDIUM
Local
|
spearman
|
unbounded-spsc
|
unbounded_spsc is an "unbounded" extension of bounded_spsc_queue. In versions 0.2.0 and prior, sender::send pointer-as-value transmute causes OOB read and fake-Arc drop under TX/RX race. At time of p…
Update
|
CWE-125 CWE-415 CWE-704 CWE-787
Out-of-bounds Read Double Free Incorrect Type Conversion or Cast Out-of-bounds Write
|
CVE-2026-46690
|
2026-06-16 09:07 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
316
|
6.8 |
MEDIUM
Network
|
-
|
-
|
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to before version 2.2.0, the getRedirectURL function in oauth2.go:22-29 constructs t…
New
|
CWE-601
Open Redirect
|
CVE-2026-53523
|
2026-06-16 07:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
317
|
7.3 |
HIGH
Network
|
-
|
-
|
KanaDojo contains a command injection vulnerability that allows an attacker with pull request access to execute arbitrary shell commands by inserting shell metacharacters into the version or changes …
Update
|
CWE-78
OS Command
|
CVE-2026-48547
|
2026-06-16 07:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
318
|
7.5 |
HIGH
Network
|
-
|
-
|
Custom role Insecure Direct Object References (IDOR) in Projectopia <= 5.1.25.2 versions.
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2025-59133
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319
|
4.4 |
MEDIUM
Network
|
-
|
-
|
Administrator Server Side Request Forgery (SSRF) in PopAd <= 1.0.4 versions.
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2025-60175
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Subscriber Broken Access Control in bunny.net <= 2.3.6 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2025-68049
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|