Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 CVE-2025-46315

CVE-2025-46315_CVE-2025-46315

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to access protected use...

Apple macOS CVE
HIGH 7.8 CVE-2025-31272

CVE-2025-31272_CVE-2025-31272

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to bypass launch constraint protections...

Apple macOS CVE
HIGH 8.8 CVE-2025-24284

CVE-2025-24284_CVE-2025-24284

This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in macOS Sequoia 15.4. An app may be able to bre...

Apple macOS CVE
HIGH 8.1 CVE-2026-46622

SolidInvoice: API tokens stored as plaintext in the database allowing full credential compromise on database breach_CVE-2026-46622

SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authenticate all REST API requests are stored as pla...

SolidInvoice SolidInvoice < 2.3.17 CVE
HIGH 8.1 CVE-2026-46489

SolidInvoice: Unrestricted file upload with no MIME validation allows stored XSS via malicious SVG logo_CVE-2026-46489

SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, the company logo upload feature accepts any file type without validatio...

SolidInvoice SolidInvoice < 2.3.17 CVE
HIGH 8.5 CVE-2026-45175

Idira Endpoint Privilege Manager Agent: Security Control and Cryptographic Validation Bypass in Internal Agent Validation Processes_CVE-2026-45175

Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local a...

CyberArk Software, a Palo Alto Networks Company Idira Endpoint Privilege Manager 26.0 CVE
HIGH 8.7 CVE-2026-53819

OpenClaw < 2026.5.27 - Arbitrary Homebrew Executable Execution via Workspace .env Override_CVE-2026-53819

OpenClaw before 2026.5.27 contains an arbitrary code execution vulnerability in skill install flows where workspace .env files can override the Hom...

OpenClaw OpenClaw CVE
HIGH 8.7 CVE-2026-53817

OpenClaw < 2026.5.22 - Control UI Locality Spoofing in Device Pairing_CVE-2026-53817

OpenClaw before 2026.5.22 contains a locality validation vulnerability in Control UI pairing that allows attackers with network access to spoof loc...

OpenClaw OpenClaw CVE
HIGH 8.6 CVE-2026-53816

OpenClaw < 2026.5.18 - Exec Lifecycle Event Forgery via Paired Node_CVE-2026-53816

OpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event handling that allows paired nodes to forge exe...

OpenClaw OpenClaw CVE
HIGH 7.1 CVE-2026-53815

OpenClaw < 2026.5.19 - Channel Allowlist Bypass in Message Read Actions_CVE-2026-53815

OpenClaw before 2026.5.19 contains an authorization bypass vulnerability in message read actions that skips channel allowlist checks. Lower-trust c...

OpenClaw OpenClaw CVE