VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
17,661 CVE recordsPage 28 of 1178 · EPSS data 2026.08.06
ReviewCritical
CVE-2026-66418

tugcantopaloglu openclaw-dashboard

OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, which is recorded verbatim in the audit log. When an administrator opens the notification panel, the unescaped log entry is rendered via innerHTML with a permissive Content-Security-Policy allowing inline event handlers, enabling the attacker-supplied payload to execute in the administrator's session and interact with authenticated endpoints including agent ins...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-55768

allinurl goaccess

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to version 1.11, the built-in WebSocket server narrows a 64-bit extended frame length into the signed 32-bit WSFrame.payloadlen field before enforcing the maximum frame size, allowing an unauthenticated remote client to bypass the guard and force an approximately 18-exabyte allocation request that terminates the process. This issue is fixed in version 1.11.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-54715

allinurl goaccess

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. In version 1.10.2, parse_browser assumes the matched browser token begins with Opera and moves a trailing version substring to match plus five, allowing a crafted User-Agent in a processed access log to write one to four attacker-influenced bytes beyond the heap allocation and corrupt or crash GoAccess. This issue is fixed in version 1.11.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-52539

the affected product

Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back to the default value which is publicly visible in the source code repository. An unauthenticated remote attacker can exploit this by forging JWT session tokens with arbitrary user data and full administrative permissions.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-35847

the affected product

An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the CheckUils.php file

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2025-69947

the affected product

SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2025-69941

the affected product

SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2025-69938

the affected product

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2025-69937

the affected product

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2025-69936

the affected product

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2025-69935

the affected product

CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2025-69934

the affected product

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2025-69933

the affected product

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2025-69931

the affected product

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2025-69930

the affected product

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1.

The CVSS severity warrants an early asset and exposure review.