Recent Advisories

Severity ID Title Vendor Product Date Type
NONE THN:D5D60D7DB19...

New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets_THN:D5D60D7DB19D929D8A808718ADD09C7F

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi6r68iB-MZv_eNGG3y0evEVbk7WXNkMzcKno1phHiSyOwfKd0G7bv8VCCrxQgmZOutmZdP1Nz-Xr1mxxUIx_...

N/A N/A THN
NONE PACKETSTORM:223278

📄 MEmu Android Emulator 9.2.7.0 Privilege Escalation_PACKETSTORM:223278

MEmu Android Emulator version 9.2.7.0 suffers from a local privilege escalation vulnerability via insecure permissions...

N/A N/A PACKETSTORM
NONE THN:0BD4A62DBE4...

The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm_THN:0BD4A62DBE41A6B9A27B7AEF56EC0C96

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiT390XWb8ahl36RgVGzdXiIpEJ43hxHfayY1i2C_rBLbVyu5A2Q-uOFptUFJL33Ehedvbx97RiUV2NivTy-F...

N/A N/A THN
HIGH 8.8 CVE-2026-50223

Apache OFBiz: DataResource Low-Privileged Authenticated FreeMarker Template Injection Leads to Remote Code Execution_CVE-2026-50223

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenticated user with Content/Dat...

Apache Software Foundation Apache OFBiz before 24.09.07 CVE
CRITICAL 9.8 CVE-2026-38581

CVE-2026-38581_CVE-2026-38581

SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attackers to execute arbitrary SQL commands via the idF...

damasac thaipalliative_lte 3.0 CVE
CRITICAL 9.1 CVE-2026-9648

CVE-2026-9648_CVE-2026-9648

The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept certificates whose Subject Alter...

Haskell Programming Language crypton-certificate CVE
HIGH 8.8 CVE-2026-7870

IBM i is Affected by Privilege Escalation []_CVE-2026-7870

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-...

IBM i 7.6 CVE
HIGH 7.5 CVE-2026-7787

Unauthenticated Session History Access via Public Flow Execution_CVE-2026-7787

IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive information by bypassing authentication using in...

IBM Langflow OSS 1.0.0 CVE
HIGH 8.6 CVE-2026-53777

Perry < 0.5.1159 Path Traversal via ArtifactReady WebSocket_CVE-2026-53777

Perry before 0.5.1159 contains a path traversal vulnerability that allows a malicious build server to write arbitrary content to any location writa...

PerryTS perry CVE
MEDIUM 6.5 CVE-2026-4096

A vulnerability has been identified in IBM DevOps Plan that allows a Host Header Injection attack due to improper handling of the Host header in HTTP requests._CVE-2026-4096

IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could ...

IBM DevOps Plan 3.0.0 CVE