HIGH7.5Stanza: Remote Code Execution via Unsafe Pickle Deserialization in Model Loaders
HIGH7.6Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN
HIGH8.0py7zr: Arbitrary File Write Vulnerability
HIGH7.3Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()
HIGH8.8CedarJava has policy injection vulnerability
HIGH8.8CedarJava has type confusion vulnerability
HIGH8.3libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sf…
CRITICAL9.0HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allo…
LOW1.8A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation.
HIGH8.8An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial-of-service and, in…
HIGH8.7HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tb…
HIGH7.1OpenClaw: Workspace-derived service PATH could influence trash command selection
HIGH7.1OpenClaw: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots
HIGH8.1OpenClaw: Discord allowFrom could bind to mutable display names
HIGH7.1OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency install
HIGH7.1OpenClaw: Linux and macOS exec allowlists skipped configured argument patterns
HIGH8.1OpenClaw: Zalo allowFrom could bind to mutable display names
HIGH8.1OpenClaw: Shell positional parameters could weaken strict inline-eval checks