Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.5 CVE-2025-30459

CVE-2025-30459_CVE-2025-30459

A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive us...

Apple macOS CVE
MEDIUM 5.5 CVE-2025-30431

CVE-2025-30431_CVE-2025-30431

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app...

Apple macOS CVE
MEDIUM 5.5 CVE-2025-24268

CVE-2025-24268_CVE-2025-24268

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.4. An app m...

Apple macOS CVE
MEDIUM 6.3 CVE-2026-53782

Summarize < 0.17.0 SSRF via podcast:transcript URL fetch_CVE-2026-53782

Summarize before 0.17.0 contains a server-side request forgery vulnerability that allows attackers who control a podcast RSS feed to direct the hos...

steipete summarize CVE
MEDIUM 5.3 CVE-2026-53781

Summarize < 0.17.0 Disk Exhaustion via Uncapped Media Download_CVE-2026-53781

Summarize before 0.17.0 contains a resource exhaustion vulnerability that allows remote attackers to cause disk exhaustion by serving media respons...

steipete summarize CVE
MEDIUM 6 CVE-2026-49949

CodexBar < 0.33.0 Credential Leakage via HTTP Redirect_CVE-2026-49949

CodexBar before 0.33.0 contains a credential forwarding vulnerability that allows network-adjacent attackers to intercept sensitive credentials by ...

steipete CodexBar CVE
MEDIUM 6 CVE-2026-45802

FPDI: Memory Exhaustion and Endless Loop in FPDI leads to Denial of Service_CVE-2026-45802

FPDI is a collection of PHP classes that facilitate reading pages from existing PDF documents and using them as templates in FPDF. Prior to version...

Setasign FPDI < 2.6.7 CVE
MEDIUM 6.9 CVE-2026-53818

OpenClaw < 2026.4.24 - Owner-Only Tool Policy Bypass via MCP Loopback_CVE-2026-53818

OpenClaw before 2026.4.24 contains an authorization bypass vulnerability in the MCP loopback feature that allows non-owner callers to skip owner-on...

OpenClaw OpenClaw CVE
MEDIUM 4.9 CVE-2026-53812

OpenClaw < 2026.5.18 - Private-Network Navigation Bypass via Browser Act Interactions_CVE-2026-53812

OpenClaw before 2026.5.18 contains a server-side request forgery vulnerability in browser control that allows authenticated users to bypass private...

OpenClaw OpenClaw CVE
MEDIUM 4.8 CVE-2026-53809

OpenClaw < 2026.4.25 - Provider Alias Confusion in Embedded Runner Policy_CVE-2026-53809

OpenClaw before 2026.4.25 contains a policy bypass vulnerability in embedded runner policy that allows requests using provider aliases to compare a...

OpenClaw OpenClaw CVE