Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.4 CVE-2026-39118

CVE-2026-39118_CVE-2026-39118

An issue in Iru, Inc Kandji Agent before v.4.7.5(5374) allows a local attacker to escalate privileges via a client validation gap to invoke restric...

n/a n/a n/a CVE
HIGH 7.3 CVE-2026-12318

Incorrect boundary conditions in the Libraries component in NSS_CVE-2026-12318

Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Mozilla Firefox 152 CVE
HIGH 7.5 CVE-2026-12317

Memory safety bug fixed in Thunderbird 152_CVE-2026-12317

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Mozilla Firefox 152 CVE
HIGH 7.5 CVE-2026-12314

Memory safety bug fixed in Thunderbird 152_CVE-2026-12314

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Mozilla Firefox 140.12 CVE
HIGH 7.5 CVE-2026-12312

Memory safety bug fixed in Thunderbird 152_CVE-2026-12312

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Mozilla Firefox 140.12 CVE
HIGH 7.5 CVE-2026-12310

Memory safety bug fixed in Thunderbird 152_CVE-2026-12310

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Mozilla Firefox 140.12 CVE
HIGH 7.5 CVE-2026-12305

Memory safety bug fixed in Thunderbird 152_CVE-2026-12305

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Mozilla Firefox 140.12 CVE
HIGH 7.6 CVE-2026-53866

OpenClaw < 2026.5.12 - Allowlist Bypass in Shell Inline-Command Parsing_CVE-2026-53866

OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing that allows authenticated operators to execute...

OpenClaw OpenClaw CVE
HIGH 7.2 CVE-2026-53865

OpenClaw < 2026.5.2 - Arbitrary Command Execution via Workspace-Derived Service PATH_CVE-2026-53865

OpenClaw before 2026.5.2 contains a path traversal vulnerability in maintenance task execution that allows workspace-derived service paths to influ...

OpenClaw OpenClaw CVE
HIGH 7.6 CVE-2026-53864

OpenClaw < 2026.5.26 - Insufficient Environment Variable Sanitization in Node.js Control Variables_CVE-2026-53864

OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variabl...

OpenClaw OpenClaw CVE