Security Risk Severity

High Security Risks — Page 15

Published vulnerability pages grouped by high severity. Use this page to review risks that need similar prioritization.

872 published high risks

High severity

Showing 505–540 of 872 published risks.

Clear
highEPSS 0.002

CVE-2026-48363 in Adobe ColdFusion

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

CVE-2026-48363supply-chainweb-applicationremote-code-executionprivilege-escalation

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-48364 in Adobe ColdFusion

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

CVE-2026-48364supply-chainweb-applicationremote-code-executionprivilege-escalation

Updated Jul 15, 2026

highEPSS 0.004

CVE-2026-15685 in Ollama

Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Ollama. Authentication is not required to exploit this vulnerability. The specific flaw exists within the downloadBlob function. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated array. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-27277.

CVE-2026-15685input-validationdenial-of-servicememory-corruption

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-62186 in OpenClaw

OpenClaw versions before 2026.6.8 contain an authorization bypass vulnerability in OpenAI-compatible HTTP model overrides that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input paths to bypass admin authorization policies and execute restricted operations.

CVE-2026-62186npmapi-securityauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-62187 in OpenClaw Feishu

OpenClaw Feishu tools (npm package @openclaw/feishu) in versions <= 2026.6.6 could ignore per-account disablement. A lower-trust caller or a configured input path could perform actions that should have required a stronger authorization or policy check, resulting in unauthorized operations. The issue is fixed in version 2026.6.9. Impact depends on the operator's configuration and whether lower-trust input can reach the affected feature.

CVE-2026-62187npmapi-securityauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-62188 in OpenClaw Feishu

OpenClaw @openclaw/feishu versions 2026.6.6 and earlier contain an incorrect authorization vulnerability in which the Feishu permission tools could ignore per-account disablement settings. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could perform actions that should have required a stronger authorization or policy check. The issue is fixed in version 2026.6.9.

CVE-2026-62188npmapi-securityauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-62189 in OpenClaw

OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows lower-trust callers to perform actions requiring stronger authorization. Attackers can exploit remote symlink parents to bypass policy checks and authorization boundaries when the feature is enabled and reachable.

CVE-2026-62189npmauthorization-bypasspath-traversalfile-write

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-62190 in OpenClaw

OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can leverage configured input paths to bypass durable exec approval binding and perform unauthorized operations when the affected feature is enabled.

CVE-2026-62190npmapi-securityauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-62191 in OpenClaw

OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message mutation handling that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input paths to skip requester authorization and execute privileged operations when the affected feature is enabled and reachable.

CVE-2026-62191npmapi-securityauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-62192 in OpenClaw

OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in Discord guild actions that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input paths to skip cross-provider requester authorization and execute restricted operations.

CVE-2026-62192npmapi-securityauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-62194 in OpenClaw

OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install commands that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can exploit misconfigured input paths or enabled features to escalate privileges and perform unauthorized actions when the feature is reachable.

CVE-2026-62194npmapi-securityauthorization-bypassprivilege-escalation

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-62195 in OpenClaw

OpenClaw versions 2026.5.20 before 2026.6.6 contain an authorization bypass vulnerability in the MCP loopback feature that allows lower-trust callers to execute owner-only tools. Attackers can bypass authorization checks through configured input paths to execute or persist actions beyond their intended permissions.

CVE-2026-62195npmapi-securityauthorization-bypassprivilege-escalation

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-62196 in OpenClaw

OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowlists. Attackers with lower-trust access can perform actions requiring stronger authorization by leveraging group ID validation in the affected feature.

CVE-2026-62196npmapi-securityauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-62199 in OpenClaw

OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that can miss interpreter startup variables. When the affected feature is enabled and reachable, a lower-trust caller or configured input path can supply crafted environment variables to execute or persist actions beyond the caller's intended authorization.

CVE-2026-62199npmapi-securityremote-code-executionauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-62200 in OpenClaw

OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that could allow Git ext transport to be abused. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the caller's intended authorization.

CVE-2026-62200npmapi-securityremote-code-executionauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-62240 in CrewAI

CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original URL unchanged. Attackers can bypass the security filter by supplying URLs that redirect to internal addresses or use DNS rebinding techniques to access internal services and cloud metadata endpoints.

CVE-2026-62240pythoninput-validationssrf

Updated Jul 15, 2026

highEPSS 0.003

CVE-2024-7708 in Eclipse Jetty

For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is particularly the case for 100-Continue, but any request where the network is slow can leak.

CVE-2024-7708javaweb-applicationdenial-of-service

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-15075 in Eclipse Vert.x

In Eclipse Vert.x versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), DefaultRedirectHandler (vertx-core) propagates all request headers as-is across cross-origin HTTP 30x redirects. Only Content-Length is stripped; no origin comparison (scheme, host, port) is performed before copying headers to the redirect target. As a result, credential headers, including Authorization, Cookie, Proxy-Authorization, and arbitrary custom headers such as X-API-Token, are forwarded to the redirect destination without the caller's knowledge. An attacker who can cause a Vert.x HttpClient to issue a request that is redirected to an attacker-controlled host (for example, by supplying a URL to a webhook dispatcher, image proxy, or microservice URL fetcher) can capture bearer tokens, basic-auth credentials, session cookies, and API keys attached to the original request.

CVE-2026-15075javaapi-securityinformation-disclosure

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-15076 in Eclipse Vert.x

In versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), the WebClientSession component of Eclipse Vert.x Web Client does not validate that the Domain attribute of a Set-Cookie response header matches the originating server's domain, in violation of RFC 6265 section 5.3. An attacker who controls any server that the victim application contacts can inject a cookie scoped to an arbitrary third-party domain; because the session store performs no cross-domain ownership check, it stores and later transmits that cookie to the targeted domain. When the victim application subsequently sends a request to the targeted domain using the same WebClientSession, it presents the attacker-injected cookie, causing the receiving service to process the request under the attacker's account. Sensitive data included in the victim application's requests, such as payment amounts, card details, or other API payloads, may then be accessible to the attacker through their own account on that service.

CVE-2026-15076javaapi-securityinformation-disclosure

Updated Jul 15, 2026

high

CVE-2026-58476 in Sustainable Irrigation Platform

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a cross-site request forgery vulnerability that allows remote attackers to perform state-changing administrative actions by luring a logged-in administrator into visiting a malicious page that issues HTTP GET requests without CSRF token validation or origin verification. Attackers can trigger actions such as disabling the passphrase, rebooting the device, deleting programs, or installing plugins, with the default configuration exposing these endpoints to unauthenticated users due to no required passphrase and a default credential of 'opendoor'.

CVE-2026-58476industrial-controlcsrf

Updated Jul 15, 2026

high

CVE-2026-58477 in Sustainable Irrigation Platform

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a mass assignment vulnerability that allows unauthenticated attackers to overwrite sensitive configuration settings by supplying arbitrary parameter names in HTTP requests. Attackers can manipulate parameters corresponding to sensitive values such as the passphrase and listening port, and can also achieve the same result through cross-site request forgery due to the absence of adequate request validation.

CVE-2026-58477industrial-controlauthorization-bypasscsrf

Updated Jul 15, 2026

high

CVE-2026-59199 in Pillow

Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0.

CVE-2026-59199pythoninput-validationmemory-corruption

Updated Jul 15, 2026

high

CVE-2026-59204 in Pillow

Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient memory usage and trigger out-of-memory failures during decoding. This issue is fixed in version 12.3.0.

CVE-2026-59204pythoninput-validationdenial-of-service

Updated Jul 15, 2026

high

CVE-2026-59205 in Pillow

Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.

CVE-2026-59205pythonapi-securityinput-validationmemory-corruption

Updated Jul 15, 2026

high

CVE-2026-59841 in FortiSIEM Windows Agent

A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to escalation of privilege via <insert attack vector here>

CVE-2026-59841windowsnetwork-securityprivilege-escalation

Updated Jul 15, 2026

high

CVE-2026-47967 in Adobe Audition

Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-47967remote-code-executionmemory-corruption

Updated Jul 15, 2026

high

CVE-2026-47968 in Adobe Audition

Audition is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2026-47968remote-code-executionmemory-corruption

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-57516 in Ray

Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attackers to achieve remote code execution by supplying a malicious tar archive to the read_webdataset() function. The _default_decoder() function in webdataset_datasource.py unconditionally calls pickle.loads() on tar entries with .pkl/.pickle extensions and torch.load() with weights_only=False on .pt/.pth entries, executing arbitrary code inside Ray remote workers on every worker that processes the malicious archive.

CVE-2026-57516pythonremote-code-executionunsafe-deserialization

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-46680 in containerd

containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leading to runAsNonRoot evasion. If a crafted image provides an /etc/passwd file mapping this large numeric string to root, the container ultimately runs as root (UID 0). This allows the Kubernetes runAsNonRoot restriction to be bypassed, causing unexpected behavior for environments that require containers to run as a non-root user. This issue has been fixed in versions 1.7.32, 2.0.9, 2.2.4 and 2.3.1.

CVE-2026-46680cloud-securitydevopsprivilege-escalation

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-49091 in Kibana

Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log Injection-Tampering-Forging (CAPEC-93). An attacker can supply specially crafted input that is written to log files without proper neutralization. When the log files are subsequently viewed in a terminal that interprets control sequences, the injected content may alter the displayed log data.

CVE-2026-49091web-applicationinput-validationinformation-disclosure

Updated Jul 15, 2026

highEPSS 0.006

CVE-2026-54428 in Apache HttpComponents Core

Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized compressed header blocks before the HTTP/2 SETTINGS acknowledgement causes the configured header list size limit to be applied.

CVE-2026-54428javanetwork-securitydenial-of-service

Updated Jul 15, 2026

highEPSS 0.001

CVE-2026-41121 in Dell Device Management Agent

Dell Device Management Agent, versions prior to DDMA 26.05, contain an Improper Link Resolution Before File Access ('Link Following’) vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

CVE-2026-41121windowspath-traversalfile-writeprivilege-escalation

Updated Jul 15, 2026

highEPSS 0.007

CVE-2026-49119 in Gradio

Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticated attackers to escape the configured root directory by supplying path segments containing directory traversal sequences or absolute paths. Attackers can provide crafted path segments that cause os.path.join to discard the root_dir prefix entirely, resulting in arbitrary file read or exposure of sensitive files outside the intended directory.

CVE-2026-49119pythonweb-applicationinformation-disclosurepath-traversal

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-53489 in containerd

containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a bug where the CRI plugin restores container.log from a checkpoint image without validating a symlinked path. This could result in reading an arbitrary file on the host via kubectl logs. This issue has been fixed in versions 2.3.2, 2.2.5 and 2.1.9.

CVE-2026-53489cloud-securitydevopsinformation-disclosurepath-traversal

Updated Jul 15, 2026

highEPSS 0.004

CVE-2026-53492 in containerd

containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation improperly trusts Container Device Interface (CDI) annotations found within untrusted checkpoint image metadata during container restoration. When restoring a container from a checkpoint, containerd preserves CDI-related annotations from the checkpoint archive rather than relying solely on the pod's create-time specification. This allows a user with pod creation permissions to bypass standard Kubernetes resource allocation and device plugin enforcement, injecting arbitrary CDI edits (such as device nodes and host mounts) into the restored container. Successful exploitation requires that the node has CDI enabled and contains a matching host CDI specification for the requested device; environments where CDI is disabled or lacking sensitive device specifications are not affected. This issue has been fixed in versions 2.3.2, 2.2.5 and 2.1.9.

CVE-2026-53492cloud-securitydevopsinput-validationauthorization-bypass

Updated Jul 15, 2026

high

CVE-2026-14265 in AWS Advanced JDBC Wrapper

Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced JDBC Wrapper 3.3.0 through 4.0.0 might allow an actor with write access to the shared cache infrastructure to execute arbitrary code on application servers that read cached query results via a crafted serialized Java object. The RemoteQueryCachePlugin uses ObjectInputStream without class filtering when deserializing cached query results from Redis or Valkey, enabling gadget chain execution when cache entries are poisoned. We recommend upgrading to AWS Advanced JDBC Wrapper version 4.0.1 or later.

CVE-2026-14265javaremote-code-executionunsafe-deserialization

Updated Jul 14, 2026