Security Advisories
open_in_newView CVE open_in_newView allA list of vulnerabilities (CVE / GHSA) publicly disclosed by Tencent Zhuque Lab.
bug_report
Vulnerabilities
69
deployed_code
Products
23
leaderboard
Severity Breakdown
-
open_in_newHigh CVE-2026-64564 CWE-416
[SCTPhantom] sctp: don't free the ASCONF's own transport in DEL-IP processing
deployed_code Affected: linux >= 2.6.25 calendar_today Published: August 04, 2026 -
open_in_newHigh CVE-2026-69257 CWE-918/CWE-1389
Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses
deployed_code Affected: flowise <= 3.1.2 calendar_today Published: August 04, 2026 -
open_in_newMedium CVE-2026-12491 CWE-436
vLLM: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations
deployed_code Affected: vllm >= 0.11.0, <= 0.23.0 calendar_today Published: June 17, 2026 -
open_in_newMedium CVE-2026-45386 CWE-639
An IDOR vulnerability exists in the pin_channel_message API endpoint
deployed_code Affected: open-webui < 0.9.5 calendar_today Published: May 11, 2026 -
open_in_newMedium CVE-2026-45385 CWE-639
An IDOR vulnerability exists in the update_message_by_id API endpoint
deployed_code Affected: open-webui < 0.9.5 calendar_today Published: May 11, 2026 -
open_in_newLow CVE-2026-43529 CWE-367
OpenClaw: TOCTOU read in exec script preflight
deployed_code Affected: OpenClaw < 2026.4.10 calendar_today Published: May 05, 2026 -
open_in_newMedium CVE-2026-42310 CWE-835
Pillow has a PDF Parsing Trailer Infinite Loop (DoS)
deployed_code Affected: pillow >= 4.2.0, < 12.2.0 calendar_today Published: May 04, 2026 -
open_in_newLow GHSA-j4c5-89f5-f3pm CWE-918
OpenClaw: Browser CDP profile creation skipped strict-mode SSRF checks
deployed_code Affected: openclaw < 2026.4.20 calendar_today Published: April 25, 2026 -
open_in_newMedium CVE-2026-42439 CWE-862/CWE-918
OpenClaw: Browser tabs action select and close routes bypassed SSRF policy
deployed_code Affected: openclaw < 2026.4.10 calendar_today Published: April 17, 2026 -
open_in_newMedium CVE-2026-43576 CWE-601/CWE-918
OpenClaw: CDP /json/version WebSocket URL could pivot to untrusted second-hop targets
deployed_code Affected: openclaw < 2026.4.5 calendar_today Published: April 17, 2026
Per page
