Skip to main content

CWE archive

CWE-807 CVEs

Programmatic archive

85 CVEs tagged with CWE-80713 Critical, 31 High, 37 Medium, 4 Low, 0 Unrated.

CVE-2026-13059

Published Jul 22, 2026

An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role-based query-level access controls, due to insufficient val…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-16093

Published Jul 17, 2026

Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discover…

CVSS 5.4 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-9561

Published Jul 14, 2026

Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP address in audit log entries. The org.eclip…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-48491

Published Jun 23, 2026

Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity vulnerability in Traefik's domain-fronting protection (SNICheck) that allows a…

CVSS 7.8 · High
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort

CVE-2026-48980

Published Jun 18, 2026

pam_usb provides hardware authentication for Linux using removable media. In versions prior to 0.9.2, getenv() environment variables XRDP_SESSION, DISPLAY and TMUX allow environm…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-53860

Published Jun 16, 2026

OpenClaw before 2026.5.7 contains a sender policy bypass vulnerability in BlueBubbles that allows participants to match allowlist entries through conversation metadata rather than…

CVSS 2.3 · Low
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-12058

Published Jun 12, 2026

The connection confirmation pop-up of a specific feature in the PcSuite can be bypassed.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-44649

Published May 29, 2026

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice mode…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-43935

Published May 26, 2026

e107 is a content management system (CMS). Prior to 2.3.4, a Host Header Injection vulnerability in the password reset page allows attackers to manipulate the Host header to gener…

CVSS 8.1 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-6213

Published May 8, 2026

A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check and achieve arbitrary code execution as root on the server si…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-24120

Published May 4, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.10.5, the fix for CVE-2023-37466 is insufficient and can be circumvented allowing attackers to write code which ca…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort

CVE-2026-39807

Published May 1, 2026

Reliance on Untrusted Inputs in a Security Decision vulnerability in mtrudel bandit allows unauthenticated transport-state spoofing on plaintext HTTP connections. 'Elixir.Bandit.…

CVSS 6.3 · Medium
evidence mentions
4
Buzz score
27.6

CVE-2026-41403

Published Apr 28, 2026

OpenClaw before 2026.3.31 misclassifies proxied remote requests as loopback connections in the diffs viewer when allowRemoteViewer is disabled, allowing unauthorized access. Attac…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-41390

Published Apr 28, 2026

OpenClaw before 2026.3.28 contains an exec allowlist bypass vulnerability where allow-always persistence fails to unwrap /usr/bin/script and similar wrappers before storing trust…

CVSS 7.0 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-41380

Published Apr 28, 2026

OpenClaw before 2026.3.28 contains an execution approval vulnerability in exec-approvals-allowlist.ts that allows allow-always persistence to trust wrapper carrier executables ins…

CVSS 7.0 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-1789

Published Apr 24, 2026

A vulnerability in the browser-based remote management interface may allow an administrator to access sensitive information on the device via crafted requests, affecting certain p…

CVSS 6.9 · Medium
evidence mentions
4
Buzz score
25.6

CVE-2026-41299

Published Apr 21, 2026

OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the chat.send gateway method where ACP-only provenance fields are gated by self-declared client metadat…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2019-25711

Published Apr 12, 2026

SpotFTP Password Recover 2.4.2 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized buffer in the Name field d…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-35670

Published Apr 10, 2026

OpenClaw before 2026.3.22 contains a webhook reply delivery vulnerability that allows attackers to rebind chat replies to unintended users by exploiting mutable username matching…

CVSS 6.0 · Medium
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-35655

Published Apr 10, 2026

OpenClaw before 2026.3.22 contains an identity spoofing vulnerability in ACP permission resolution that trusts conflicting tool identity hints from rawInput and metadata. Attacker…

CVSS 6.9 · Medium
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-35624

Published Apr 9, 2026

OpenClaw before 2026.3.22 contains a policy confusion vulnerability in room authorization that matches colliding room names instead of stable room tokens. Attackers can exploit si…

CVSS 2.3 · Low
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2026-35617

Published Apr 9, 2026

OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Google Chat group policy enforcement that relies on mutable space display names. Attackers can rebind g…

CVSS 2.3 · Low
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-34486

Published Apr 9, 2026

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tom…

CVSS 7.5 · High
evidence mentions
19
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2025-13926

Published Apr 9, 2026

An attacker could use data obtained by sniffing the network traffic to forge packets in order to make arbitrary requests to Contemporary Controls BASC 20T.

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
28.9
Showing 1-25 of 85 CVEsPage 1 of 4