Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
OpenClaw < 2026.4.8 - Remote Code Execution via Build Tool Environment Variable Injection
OpenClaw < 2026.4.8 - Git Environment Variable Injection via Unfiltered Exec Environment
OpenClaw < 2026.3.31 - Exec Allowlist Bypass via Shell Init-File Options
OpenClaw < 2026.3.31 - Environment Variable Bypass in Package Index URL Handling
Xibo CMS API has SQL Injection via DataSet Filter Parameter
OpenClaw < 2026.3.28 - SSRF Guard Bypass via IPv6 Special-Use Ranges
OpenClaw < 2026.3.28 - Code Execution via Missing Environment Variable Blocklist
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
PySpector has a Plugin Code Execution Bypass via Incomplete Static Analysis in PluginSecurity.validate_plugin_code
Xerte Online Toolkits File Upload RCE via elfinder Connector
October: Safe Mode Bypass via Twig Database Write Operations
October: Safe Mode Bypass via CSS Preprocessor Compilers
OpenMage LTS has Path Traversal Filter Bypass in Dataflow Module
Beszel has an IDOR in hub API endpoints that read system ID from URL parameter
Unhead has a hasDangerousProtocol() bypass via leading-zero padded HTML entities in useHeadSafe()
VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf
Directus has an Open Redirect via Parser Bypass in OAuth2/SAML Authentication Flow
OpenClaw - Approval Bypass via Environment Variable Normalization
OpenClaw - Shell-Bleed Protection Preflight Validation Bypass
ChangeDetection.io < 0.54.7 SafeXPath3Parser Bypass Arbitrary File Read
Showing 1 - 20 of 1,000+ results