Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Malicious code in rtms-manager (npm)
Malicious code in vinext-monorepo (npm)
Malicious code in @shoobx/types (npm)
Malicious code in @source-row/source-container (npm)
Malicious code in @ataslkit/profilecard (npm)
Malicious code in react-resource-router-next (npm)
Malicious code in react-hook-form (npm)
Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability
OpenClaw: QMD memory_get restricts reads to canonical or indexed memory paths
OpenClaw: Webchat media embedding enforces local-root containment for tool-result files
OpenClaw: Feishu webhook and card-action validation now fail closed
OpenClaw: Gateway HTTP endpoints re-resolve bearer auth after SecretRef rotation
Remote Code Execution (RCE) via String Literal Injection into math-codegen
CVE-2026-35603
Claude Code: Insecure System-Wide Configuration Loading Enables Local Privilege Escalation on Windows
OpenClaw: CDP /json/version WebSocket URL could pivot to untrusted second-hop targets
OpenClaw: Sender policy bypass in host media attachment reads allows unauthorized local file disclosure
OpenClaw: QQBot media tags could read arbitrary local files through reply text
OpenClaw: busybox and toybox applet execution weakened exec approval binding
OpenClaw: Matrix profile config persistence was reachable from operator.write message tools
OpenClaw: Sandboxed agents could escape exec routing via host=node override
Showing 1 - 20 of 1,000+ results