🛡️ CVE Vulnerability Database
CVE vulnerabilities with bilingual AI analysis tailored for Saudi Arabia
| CVE ID | Title / Description | Severity | CVSS | Status | Published |
|---|---|---|---|---|---|
| CVE-2026-40901 |
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below shi…
|
HIGH |
8.8
|
⚡ | Apr 16, 2026 |
| CVE-2026-40900 |
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below con…
|
HIGH |
8.8
|
⚡ | Apr 16, 2026 |
| CVE-2026-33207 |
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below con…
|
HIGH |
8.8
|
⚡ | Apr 16, 2026 |
| CVE-2026-33121 |
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below con…
|
HIGH |
8.8
|
⚡ | Apr 16, 2026 |
| CVE-2026-33084 |
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below con…
|
HIGH |
8.8
|
⚡ | Apr 16, 2026 |
| CVE-2026-33083 |
DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below con…
|
HIGH |
8.8
|
⚡ | Apr 16, 2026 |
| CVE-2019-25713 |
MyT-PM 1.5.1 contains an SQL injection vulnerability that allows authenticated attackers to execute …
|
HIGH |
7.1
|
⚡ | Apr 12, 2026 |
| CVE-2019-25707 |
eBrigade ERP 4.5 contains an SQL injection vulnerability that allows authenticated attackers to exec…
|
HIGH |
7.1
|
⚡ | Apr 12, 2026 |
| CVE-2019-25705 |
Echo Mirage 3.1 contains a stack buffer overflow vulnerability that allows local attackers to crash …
|
HIGH |
8.4
|
⚡ | Apr 12, 2026 |
| CVE-2019-25703 |
ImpressCMS 1.3.11 contains a time-based blind SQL injection vulnerability that allows authenticated …
|
HIGH |
7.1
|
⚡ | Apr 12, 2026 |
| CVE-2019-25701 |
Easy Video to iPod Converter 1.6.20 contains a local buffer overflow vulnerability in the user regis…
|
HIGH |
8.4
|
⚡ | Apr 12, 2026 |
| CVE-2019-25699 |
Newsbull Haber Script 1.0.0 contains multiple SQL injection vulnerabilities in the search parameter …
|
HIGH |
7.1
|
⚡ | Apr 12, 2026 |
| CVE-2019-25689 |
HTML5 Video Player 1.2.5 contains a local buffer overflow vulnerability that allows attackers to exe…
|
HIGH |
8.4
|
⚡ | Apr 12, 2026 |
| CVE-2026-35668 |
OpenClaw before 2026.3.24 contains a path traversal vulnerability in sandbox enforcement allowing sa…
|
HIGH |
7.7
|
⚡ | Apr 10, 2026 |
| CVE-2026-35653 |
OpenClaw before 2026.3.24 contains an incorrect authorization vulnerability in the POST /reset-profi…
|
HIGH |
8.1
|
⚡ ✅ | Apr 10, 2026 |
| CVE-2026-35641 |
OpenClaw before 2026.3.24 contains an arbitrary code execution vulnerability in local plugin and hoo…
|
HIGH |
7.8
|
⚡ | Apr 10, 2026 |
| CVE-2026-29002 |
CouchCMS contains a privilege escalation vulnerability that allows authenticated Admin-level users t…
|
HIGH |
7.2
|
⚡ | Apr 10, 2026 |
| CVE-2026-35632 |
OpenClaw through 2026.2.22 contains a symlink traversal vulnerability in agents.create and agents.up…
|
HIGH |
7.1
|
⚡ | Apr 9, 2026 |
| CVE-2026-39883 |
OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2…
|
HIGH |
7.0
|
⚡ | Apr 8, 2026 |
| CVE-2026-35525 |
LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3…
|
HIGH |
7.5
|
⚡ | Apr 8, 2026 |
| CVE-2026-39355 |
Genealogy is a family tree PHP application. Prior to 5.9.1, a critical broken access control vulnera…
|
CRITICAL |
9.9
|
⚡ AI | Apr 7, 2026 |
| CVE-2026-39342 |
ChurchCRM is an open-source church management system. Prior to 7.1.0, the searchwhat parameter via Q…
|
HIGH |
8.8
|
⚡ | Apr 7, 2026 |
| CVE-2026-30460 |
Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE…
|
HIGH |
8.8
|
⚡ | Apr 7, 2026 |
| CVE-2026-35394 |
Mobile Next is an MCP server for mobile development and automation. Prior to 0.0.50, the mobile_open…
|
HIGH |
8.3
|
⚡ ✅ | Apr 6, 2026 |
| CVE-2026-34589 |
OpenEXR provides the specification and reference implementation of the EXR file format, an image sto…
|
MEDIUM |
5.0
|
⚡ | Apr 6, 2026 |