Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2 CVE-2026-43529

OpenClaw < 2026.4.10 - Time-of-Check-Time-of-Use (TOCTOU) Race Condition in exec Script Preflight Validator_CVE-2026-43529

OpenClaw before 2026.4.10 contains a time-of-check-time-of-use vulnerability in the validateScriptFileForShellBleed function that allows local atta...

OpenClaw OpenClaw CVE
LOW 3.7 CVE-2026-43964

CVE-2026-43964_CVE-2026-43964

Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code ...

Postfix Postfix 2.3 CVE
LOW 2.4 CVE-2026-6499

CVE-2026-6499_CVE-2026-6499

Incorrect Permission Assignment for Critical Resource vulnerability in ILM Informatique OpenConcerto allows Replace Binaries. This issue affects O...

ILM Informatique OpenConcerto 1.7.5 CVE
LOW 2.5 CVE-2026-43864

CVE-2026-43864_CVE-2026-43864

mutt before 2.3.2 has a show_sig_summary NULL pointer dereference.

mutt mutt CVE
LOW 3.7 CVE-2026-43863

CVE-2026-43863_CVE-2026-43863

mutt before 2.3.2 has an infinite loop in data_object_to_stream in crypt-gpgme.c.

mutt mutt CVE
LOW 3.7 CVE-2026-43862

CVE-2026-43862_CVE-2026-43862

In mutt before 2.3.2, the imap_auth_gss security level is mishandled.

mutt mutt CVE
LOW 3.7 CVE-2026-43861

CVE-2026-43861_CVE-2026-43861

mutt before 2.3.2 does not check for '\0' in url_pct_decode.

mutt mutt CVE
LOW 3.7 CVE-2026-43860

CVE-2026-43860_CVE-2026-43860

mutt before 2.3.2 sometimes truncates the hash_passwd by one byte for IMAP auth_cram MD5 digest.

mutt mutt CVE
LOW 3.7 CVE-2026-43859

CVE-2026-43859_CVE-2026-43859

mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.

mutt mutt CVE
LOW 2.3 CVE-2026-7724

PrefectHQ prefect Webhook/Notification validate_restricted_url toctou_CVE-2026-7724

A vulnerability has been found in PrefectHQ prefect up to 3.6.28.dev1. Affected by this vulnerability is the function validate_restricted_url of th...

PrefectHQ prefect 3.6.28.dev1 CVE