Skip to content

Menu
  • Home
Menu

CVE-2026-66421 – OpenClaw Dashboard Stored XSS via lastMessage Session Field

Posted on July 31, 2026

CVE ID :CVE-2026-66421 Published : July 30, 2026, 11:16 p.m. | 25 minutes ago Description :OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in…

CVE-2026-66420 – MeshCentral Cross-Site WebSocket Hijacking via Origin Validation Bypass on Self-Signed Certificate Deployments

Posted on July 31, 2026

CVE ID :CVE-2026-66420 Published : July 30, 2026, 11:16 p.m. | 25 minutes ago Description :MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated…

CVE-2026-66360 – MZ Automation libiec61850 Out-of-bounds Read

Posted on July 31, 2026

CVE ID :CVE-2026-66360 Published : July 30, 2026, 11:16 p.m. | 25 minutes ago Description :The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation. A…

CVE-2026-65423 – o6 Automation open62541 Integer Overflow or Wraparound

Posted on July 31, 2026

CVE ID :CVE-2026-65423 Published : July 30, 2026, 11:16 p.m. | 25 minutes ago Description :An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to trigger…

CVE-2026-63362 – o6 Automation open62541 Integer Underflow

Posted on July 31, 2026

CVE ID :CVE-2026-63362 Published : July 30, 2026, 11:16 p.m. | 25 minutes ago Description :An unsigned integer underflow in the PubSub signature verification path in open62541 may allow a remote attacker to…

CVE-2026-67595 – VaahCMS 2.0.0 – 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php

Posted on July 30, 2026

CVE ID :CVE-2026-67595 Published : July 29, 2026, 10:16 p.m. | 2 hours, 21 minutes ago Description :VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible…

CVE-2026-13308 – Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability

Posted on July 30, 2026

CVE ID :CVE-2026-13308 Published : July 29, 2026, 9:17 p.m. | 3 hours, 20 minutes ago Description :Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers…

CVE-2026-6267 – Insertion of Sensitive Information Into Sent Data in GitLab

Posted on July 30, 2026

CVE ID :CVE-2026-6267 Published : July 29, 2026, 8:17 p.m. | 4 hours, 21 minutes ago Description :GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before…

CVE-2026-67436 – Linuxfabrik monitoring-plugins: SSRF and auth-token disclosure via unvalidated @odata.id link in redfish-* plugins

Posted on July 30, 2026

CVE ID :CVE-2026-67436 Published : July 29, 2026, 8:17 p.m. | 4 hours, 21 minutes ago Description :Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In 6.0.0 and earlier,…

CVE-2026-67431 – MCP Ruby SDK: Ruby SSE Session Poisoning

Posted on July 30, 2026

CVE ID :CVE-2026-67431 Published : July 29, 2026, 8:17 p.m. | 4 hours, 21 minutes ago Description :MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to…

Posts pagination

1 2 … 118 Next

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme