Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
CVE-2026-27492
  • github.com/lettermint/lettermint-node
Lettermint Node.js SDK leaks email properties to unintended recipients when client instance is reused 22 hours ago
  • Fix available
  • Severity - 4.7 (Medium)
CVE-2026-27574
  • github.com/oneuptime/oneuptime
OneUptime: node:vm sandbox escape in probe allows any project member to achieve RCE 23 hours ago
  • Fix available
  • Severity - 9.9 (Critical)
CVE-2026-27576
  • github.com/openclaw/openclaw
OpenClaw: ACP prompt-size checks missing in local stdio bridge could reduce responsiveness with very large inputs 23 hours ago
  • Fix available
  • Severity - 4.8 (Medium)
CVE-2026-27488
  • github.com/openclaw/openclaw
OpenClaw hardened cron webhook delivery against SSRF 23 hours ago
  • Fix available
  • Severity - 6.9 (Medium)
CVE-2026-27487
  • github.com/openclaw/openclaw
OpenClaw: Prevent shell injection in macOS keychain credential write 23 hours ago
  • Fix available
  • Severity - 7.6 (High)
CVE-2026-27486
  • github.com/openclaw/openclaw
OpenClaw: Process Safety - Unvalidated PID Kill via SIGKILL in Process Cleanup 23 hours ago
  • Fix available
  • Severity - 4.3 (Medium)
CVE-2026-27485
  • github.com/openclaw/openclaw
OpenClaw affected by Stored XSS in Control UI via unsanitized assistant name/avatar in inline script injection 23 hours ago
  • Fix available
  • Severity - 4.6 (Medium)
CVE-2026-27482
  • github.com/ray-project/ray
Ray: Dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdown / job deletion) 23 hours ago
  • Fix available
  • Severity - 5.9 (Medium)
CVE-2026-27480
  • github.com/static-web-server/static-web-server
Static Web Server: Timing-Based Username Enumeration in Basic Authentication yesterday
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2026-27479
  • github.com/ellite/wallos
Wallos: SSRF via Redirect Bypass in Logo/Icon URL Fetch yesterday
  • Fix available
  • Severity - 7.7 (High)
CVE-2026-27470
  • github.com/zoneminder/zoneminder
ZoneMinder: Second-Order SQL Injection in `getNearEvents()` via Stored Event Name and Cause Fields yesterday
  • Fix available
  • Severity - 8.8 (High)
CVE-2026-27464
  • github.com/metabase/metabase
Metabase: Server-Side Template Injection via Notifications Endpoint Leads to RCE yesterday
  • Fix available
  • Severity - 7.7 (High)
CVE-2026-27467
  • github.com/bigbluebutton/bigbluebutton
BigBlueButton: Audio from participants to the server initially unmuted yesterday
  • Fix available
  • Severity - 2.0 (Low)
CVE-2026-27466
  • github.com/bigbluebutton/bigbluebutton
BigBlueButton: Exposed ClamAV port enables Denial of Service yesterday
  • Fix available
  • Severity - 7.2 (High)
CVE-2026-27206
  • github.com/zumba/json-serializer
Zumba Json Serializer has a potential PHP Object Injection via Unrestricted @type in unserialize() yesterday
  • Fix available
  • Severity - 8.1 (High)
CVE-2026-27458
  • github.com/kovah/linkace
LinkAce: Stored XSS in Atom Feed via CDATA Escape in List Description yesterday
  • Fix available
  • Severity - 8.7 (High)