Common Vulnerabilities and Exposures (CVE)

CVE-2026-62213

Jul 20, 2026 23:34:19 UTC

OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower-trust callers to expose Bot Framework tokens. Attackers can access configured input paths to retrieve credentials that ...

CVE-2026-63728

Jul 20, 2026 23:32:34 UTC

Gitleaks prior to 8.30.1 contains a template injection vulnerability that allows attackers who can supply or influence report templates to read arbitrary environment variables and exfiltrate sensitive data by leveraging non-hermetic Sprig t...

CVE-2026-46579

Jul 20, 2026 23:22:48 UTC

A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated attacker to send plai...

CVE-2026-1784

Jul 20, 2026 23:22:32 UTC

The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlle...

CVE-2026-55833

Jul 20, 2026 23:18:07 UTC

Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed header blocks after the raw header parser has ...

CVE-2026-57980

Jul 20, 2026 23:13:46 UTC

Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.

CVE-2026-56171

Jul 20, 2026 23:13:45 UTC

Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.

CVE-2026-58529

Jul 20, 2026 23:13:45 UTC

Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network.

CVE-2026-62826

Jul 20, 2026 23:13:44 UTC

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVE-2026-55121

Jul 20, 2026 23:13:43 UTC

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVE-2026-56181

Jul 20, 2026 23:13:43 UTC

Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.

CVE-2026-58638

Jul 20, 2026 23:13:42 UTC

Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.

CVE-2026-58637

Jul 20, 2026 23:13:42 UTC

Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.

CVE-2026-58634

Jul 20, 2026 23:13:41 UTC

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

CVE-2026-58633

Jul 20, 2026 23:13:41 UTC

Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.