🛡️ CVE Intelligence Center
Common Vulnerabilities & Exposures — Security Intelligence Database
| CVE ID | Severity | CVSS | Description | Status | Published |
|---|---|---|---|---|---|
| CVE-2026-32895 | Medium | 5.4 |
OpenClaw versions prior to 2026.2.26 fail to enforce sender authorization in member and message subtype system event han…
|
— | Mar 21, 2026 |
| CVE-2026-32898 | Medium | 5.4 |
OpenClaw versions prior to 2026.2.23 contain an authorization bypass vulnerability in the ACP client that auto-approves …
|
— | Mar 21, 2026 |
| CVE-2026-1253 | Medium | 5.3 |
The Group Chat & Video Chat by AtomChat plugin for WordPress is vulnerable to unauthorized modification of data due to a…
|
— | Mar 21, 2026 |
| CVE-2026-3570 | Medium | 5.3 |
The Smarter Analytics plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.…
|
— | Mar 21, 2026 |
| CVE-2026-32046 | Medium | 5.3 |
OpenClaw versions prior to 2026.2.21 contain an improper sandbox configuration vulnerability that allows attackers to ex…
|
— | Mar 21, 2026 |
| CVE-2026-3546 | Medium | 5.3 |
The e-shot form builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and …
|
— | Mar 21, 2026 |
| CVE-2026-3567 | Medium | 5.3 |
The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress is vulnerable to unauthorized access in all versions up…
|
— | Mar 21, 2026 |
| CVE-2026-3641 | Medium | 5.3 |
The Appmax plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.0.3. …
|
— | Mar 21, 2026 |
| CVE-2026-3651 | Medium | 5.3 |
The Build App Online plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0…
|
— | Mar 21, 2026 |
| CVE-2026-3460 | Medium | 5.3 |
The REST API TO MiniProgram plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to…
|
— | Mar 21, 2026 |
| CVE-2026-3335 | Medium | 5.3 |
The Canto plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.1.1 via th…
|
— | Mar 21, 2026 |
| CVE-2026-3506 | Medium | 5.3 |
The WP-Chatbot for Messenger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inclu…
|
— | Mar 21, 2026 |
| CVE-2026-3645 | Medium | 5.3 |
The Punnel – Landing Page Builder plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and…
|
— | Mar 21, 2026 |
| CVE-2026-4127 | Medium | 5.3 |
The Speedup Optimization plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including…
|
— | Mar 21, 2026 |
| CVE-2026-2756 | Medium | 5.0 |
A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308. This affects an unknown function of the…
|
— | Mar 21, 2026 |
| CVE-2025-54068 | Critical | 9.8 |
Laravel Livewire — CVE-2025-54068
Laravel Livewire contain a code injection vulnerability that could allow unauthenticat…
|
— | Mar 20, 2026 |
| CVE-2025-43520 | Critical | 9.8 |
Apple Multiple Products — CVE-2025-43520
Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain a classic buffer …
|
— | Mar 20, 2026 |
| CVE-2025-43510 | Critical | 9.8 |
Apple Multiple Products — CVE-2025-43510
Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locki…
|
— | Mar 20, 2026 |
| CVE-2025-32432 | Critical | 9.8 |
Craft CMS Craft CMS — CVE-2025-32432
Craft CMS contains a code injection vulnerability that allows a remote attacker to …
|
— | Mar 20, 2026 |
| CVE-2025-31277 | Critical | 9.8 |
Apple Multiple Products — CVE-2025-31277
Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer …
|
— | Mar 20, 2026 |