Tue, Mar 31 · 03:16 PM CDTCVE-2026-34162
10.0/10 · Must read/watchNVDvuln
Summary
FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/app/httpTools/runTool) is exposed without any authentication. This endpoint acts as a full HTTP proxy — it accepts a user-supplied baseUrl, toolPath, HTTP method, custom headers, and body, then makes
CVECVE-2026-34162
SeverityCRITICAL
TypeUPDATED
PublishedTue, Mar 31 · 03:16 PM CDT
ModifiedFri, Jul 24 · 09:10 PM CDT
Tue, Mar 31 · 03:16 PM CDTCVE-2026-33579
9.9/10 · Must read/watchNVDvuln
Summary
OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the /pair approve command path that fails to forward caller scopes into the core approval check. A caller with pairing privileges but without admin privileges can approve pending device requests asking for broader scopes including admin access b
CVECVE-2026-33579
SeverityCRITICAL
TypeUPDATED
PublishedTue, Mar 31 · 03:16 PM CDT
ModifiedFri, Jul 24 · 09:10 PM CDT
Tue, Mar 31 · 02:16 PM CDTCVE-2026-34156
9.9/10 · Must read/watchNVDvuln
Summary
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's Workflow Script Node executes user-supplied JavaScript inside a Node.js vm sandbox with a custom require allowlist (controlled by WORKFLOW_SCRIPT_MODULES env var). However
CVECVE-2026-34156
SeverityCRITICAL
TypeUPDATED
PublishedTue, Mar 31 · 02:16 PM CDT
ModifiedFri, Jul 24 · 10:10 PM CDT
Fri, Mar 06 · 07:16 PM CSTCVE-2026-29063
9.8/10 · Must read/watchNVDvuln
Summary
Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Pollution is possible in immutable via the mergeDeep(), mergeDeepWith(), merge(), Map.toJS(), and Map.toObject() APIs. This issue has been patched in versions 3.8.3, 4.3.7, and 5.1.5.
CVECVE-2026-29063
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 06 · 07:16 PM CST
ModifiedFri, Jul 24 · 01:17 PM CDT
Tue, Mar 31 · 04:16 PM CDTCVE-2026-30276
9.8/10 · Must read/watchNVDvuln
Summary
An arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.
CVECVE-2026-30276
SeverityCRITICAL
TypeUPDATED
PublishedTue, Mar 31 · 04:16 PM CDT
ModifiedFri, Jul 24 · 08:10 PM CDT
Tue, Mar 31 · 04:16 PM CDTCVE-2026-30281
9.8/10 · Must read/watchNVDvuln
Summary
An arbitrary file overwrite vulnerability in MaruNuri LLC v2.0.23 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.
CVECVE-2026-30281
SeverityCRITICAL
TypeUPDATED
PublishedTue, Mar 31 · 04:16 PM CDT
ModifiedFri, Jul 24 · 08:10 PM CDT
Tue, Mar 31 · 02:16 PM CDTCVE-2026-30310
9.8/10 · Must read/watchNVDvuln
Summary
In its design for automatic terminal command execution, Sixth offers two options: Execute safe commands and Execute all commands. The description for the former states that commands determined by the model to be safe will be automatically executed, whereas if the model judges a command to be potentially destructive, it
CVECVE-2026-30310
SeverityCRITICAL
TypeUPDATED
PublishedTue, Mar 31 · 02:16 PM CDT
ModifiedSat, Jul 25 · 10:10 AM CDT
Tue, Mar 31 · 12:16 PM CDTCVE-2026-32917
9.8/10 · Must read/watchNVDvuln
Summary
OpenClaw before 2026.3.13 contains a remote command injection vulnerability in the iMessage attachment staging flow that allows attackers to execute arbitrary commands on configured remote hosts. The vulnerability exists because unsanitized remote attachment paths containing shell metacharacters are passed directly to
CVECVE-2026-32917
SeverityCRITICAL
TypeUPDATED
PublishedTue, Mar 31 · 12:16 PM CDT
ModifiedSat, Jul 25 · 10:10 AM CDT
Tue, Mar 31 · 04:16 PM CDTCVE-2026-34220
9.8/10 · Must read/watchNVDvuln
Summary
MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, there is a SQL injection vulnerability when specially crafted objects are interpreted as raw SQL query fragments. This issue has been patched in versions 6.6.10 and 7.0.6.
CVECVE-2026-34220
SeverityCRITICAL
TypeUPDATED
PublishedTue, Mar 31 · 04:16 PM CDT
ModifiedFri, Jul 24 · 08:10 PM CDT
Tue, Mar 31 · 04:16 PM CDTCVE-2026-34243
9.8/10 · Must read/watchNVDvuln
Summary
wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title). In versions 0.3.1 and prior, a GitHub Actions workflow uses untrusted user input from issue_comment.body directly inside a shell command, allowing potential command injection and arbitrary code execution on the runn
CVECVE-2026-34243
SeverityCRITICAL
TypeUPDATED
PublishedTue, Mar 31 · 04:16 PM CDT
ModifiedFri, Jul 24 · 08:10 PM CDT
Wed, Jan 07 · 05:15 PM CSTCVE-2025-12543
9.6/10 · Must read/watchNVDvuln
Summary
A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling at
CVECVE-2025-12543
SeverityCRITICAL
TypeUPDATED
PublishedWed, Jan 07 · 05:15 PM CST
ModifiedFri, Jul 24 · 01:16 PM CDT
Fri, Mar 13 · 07:54 PM CDTCVE-2026-23941
9.4/10 · Must read/watchNVDvuln
Summary
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smuggling. This vulnerability is associated with program files lib/inets/src/http_server/httpd_request.erl and program routines httpd_request:parse_headers/7. The server does not
CVECVE-2026-23941
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 13 · 07:54 PM CDT
ModifiedFri, Jul 24 · 03:17 PM CDT
Tue, Mar 31 · 12:16 PM CDTCVE-2026-32916
9.4/10 · Must read/watchNVDvuln
Summary
OpenClaw versions 2026.3.7 before 2026.3.11 contain an authorization bypass vulnerability where plugin subagent routes execute gateway methods through a synthetic operator client with broad administrative scopes. Remote unauthenticated requests to plugin-owned routes can invoke runtime.subagent methods to perform privi
CVECVE-2026-32916
SeverityCRITICAL
TypeUPDATED
PublishedTue, Mar 31 · 12:16 PM CDT
ModifiedSat, Jul 25 · 10:10 AM CDT
Fri, Mar 20 · 11:16 PM CDTCVE-2026-33186
9.1/10 · Must read/watchNVDvuln
Summary
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g.,
CVECVE-2026-33186
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 20 · 11:16 PM CDT
ModifiedFri, Jul 24 · 01:17 PM CDT
Tue, Mar 31 · 04:16 PM CDTCVE-2026-34221
9.1/10 · Must read/watchNVDvuln
Summary
MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, a prototype pollution vulnerability exists in the Utils.merge helper used internally by MikroORM when merging object structures. The function did not prevent special keys such as __
CVECVE-2026-34221
SeverityCRITICAL
TypeUPDATED
PublishedTue, Mar 31 · 04:16 PM CDT
ModifiedFri, Jul 24 · 08:10 PM CDT
Tue, Mar 31 · 04:16 PM CDTCVE-2026-34235
9.1/10 · Must read/watchNVDvuln
Summary
PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap out-of-bounds read vulnerability exists in PJSIP's VP9 RTP unpacketizer that occurs when parsing crafted VP9 Scalability Structure (SS) data. Insufficient bounds checking on the payload descriptor length may cau
CVECVE-2026-34235
SeverityCRITICAL
TypeUPDATED
PublishedTue, Mar 31 · 04:16 PM CDT
ModifiedFri, Jul 24 · 08:10 PM CDT
Tue, Mar 31 · 03:16 PM CDTCVE-2026-34532
9.1/10 · Must read/watchNVDvuln
Summary
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, an attacker can bypass Cloud Function validator access controls by appending "prototype.constructor" to the function name in the URL. When a Cloud Function handler is decl
CVECVE-2026-34532
SeverityCRITICAL
TypeUPDATED
PublishedTue, Mar 31 · 03:16 PM CDT
ModifiedFri, Jul 24 · 08:10 PM CDT
Tue, Mar 31 · 03:16 PM CDTCVE-2026-34172
8.8/10 · Worth your timeNVDvuln
Summary
Giskard is an open-source Python library for testing and evaluating agentic systems. Prior to versions 0.3.4 and 1.0.2b1, ChatWorkflow.chat(message) passes its string argument directly as a Jinja2 template source to a non-sandboxed Environment. A developer who passes user input to this method enables full remote code e
CVECVE-2026-34172
SeverityHIGH
TypeUPDATED
PublishedTue, Mar 31 · 03:16 PM CDT
ModifiedFri, Jul 24 · 09:10 PM CDT
Tue, Mar 31 · 04:16 PM CDTCVE-2026-34227
8.8/10 · Worth your timeNVDvuln
Summary
Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to version 1.7.4, a single click on a malicious link gives an unauthenticated attacker immediate, silent control over every active C2 session or beacon, capable of exfiltrating all collected target data (e.g. SSH keys, ntds.dit) or d
CVECVE-2026-34227
SeverityHIGH
TypeUPDATED
PublishedTue, Mar 31 · 04:16 PM CDT
ModifiedFri, Jul 24 · 08:10 PM CDT
Tue, Mar 31 · 03:16 PM CDTCVE-2026-34373
8.8/10 · Worth your timeNVDvuln
Summary
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.66 and 9.7.0-alpha.10, the GraphQL API endpoint does not respect the allowOrigin server option and unconditionally allows cross-origin requests from any website. This bypasses origin restriction
CVECVE-2026-34373
SeverityHIGH
TypeUPDATED
PublishedTue, Mar 31 · 03:16 PM CDT
ModifiedFri, Jul 24 · 09:10 PM CDT
Thu, Feb 05 · 04:15 AM CSTCVE-2025-61732
8.6/10 · Worth your timeNVDvuln
Summary
A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.
CVECVE-2025-61732
SeverityHIGH
TypeUPDATED
PublishedThu, Feb 05 · 04:15 AM CST
ModifiedFri, Jul 24 · 01:17 PM CDT
Tue, Jan 27 · 01:16 AM CSTCVE-2026-24486
8.6/10 · Worth your timeNVDvuln
Summary
Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=True`. An attacker can write uploaded files to arbitrary locations on the filesystem by crafting a malicious fil
CVECVE-2026-24486
SeverityHIGH
TypeUPDATED
PublishedTue, Jan 27 · 01:16 AM CST
ModifiedFri, Jul 24 · 01:17 PM CDT
Tue, Mar 31 · 04:16 PM CDTCVE-2026-30284
8.6/10 · Worth your timeNVDvuln
Summary
An arbitrary file overwrite vulnerability in UXGROUP LLC Voice Recorder v10.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.
CVECVE-2026-30284
SeverityHIGH
TypeUPDATED
PublishedTue, Mar 31 · 04:16 PM CDT
ModifiedFri, Jul 24 · 08:10 PM CDT
Tue, Mar 31 · 12:16 PM CDTCVE-2026-32920
8.4/10 · Worth your timeNVDvuln
Summary
OpenClaw before 2026.3.12 automatically discovers and loads plugins from .OpenClaw/extensions/ without explicit trust verification, allowing arbitrary code execution. Attackers can execute malicious code by including crafted workspace plugins in cloned repositories that execute when users run OpenClaw from the director
CVECVE-2026-32920
SeverityHIGH
TypeUPDATED
PublishedTue, Mar 31 · 12:16 PM CDT
ModifiedSat, Jul 25 · 10:10 AM CDT
Tue, Mar 31 · 03:16 PM CDTCVE-2026-34504
8.3/10 · Worth your timeNVDvuln
Summary
OpenClaw before 2026.3.28 contains a server-side request forgery vulnerability in the fal provider image-generation-provider.ts component that allows attackers to fetch internal URLs. A malicious or compromised fal relay can exploit unguarded image download fetches to expose internal service metadata and responses thro
CVECVE-2026-34504
SeverityHIGH
TypeUPDATED
PublishedTue, Mar 31 · 03:16 PM CDT
ModifiedFri, Jul 24 · 09:10 PM CDT