CVE.report search for "CVE-2026-71102"

Listed below are 50 relevant search results for "CVE-2026-71102" based on Vendor, Software, and CVE description

These results are gathered from attempted matches with listed vendor and software data, as well as a keyword search in the description of all known CVEs.

If you notice a "Not Listed" in either the vendor or software columns, the underlying source record does not currently include normalized affected-product data.

Search Results

CVE ID Vendor Software Description
CVE-2026-103432apcupsd through 3.14.14 has an sscanf stack-based buffer overflow in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi,...
CVE-2026-103088Handlebars.java before 4.5.5 allows directory traversal. In handlebars-springmvc 4.5.3 and 4.5.4, the path-containment fix fo...
CVE-2026-102807OpenClaw before 2026.9.4 contains an incorrect authorization vulnerability in the mcp.app.view method that allows read-scoped...
CVE-2026-102806OpenClaw before 2026.9.5 contains an incorrect authorization vulnerability in the Gateway's local media root allowlist that b...
CVE-2026-102675Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42....
CVE-2026-102510Integer Overflow, Improper Validation of Array Index, Uncontrolled Recursion and Memory Allocation with Excessive Size Value ...
CVE-2026-102509Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits, and Uncontrolled Recursion in the Java i...
CVE-2026-102422shell-quote's `quote()` function emits a `{ comment }` token as `#` followed by its text, which comments out the rest of the ...
CVE-2026-101894The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API r...
CVE-2026-101884OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block...
CVE-2026-101883OpenClaw Windows Node through 2026.9.4 contains a server-side request forgery vulnerability in the canvas.present capability ...
CVE-2026-101882OpenClaw Windows Node before 2026.7.1 contains an incomplete validation vulnerability in system.execApprovals.set that accept...
CVE-2026-101881OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits vulnerability in the gateway WebSock...
CVE-2026-101880OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval polic...
CVE-2026-101879OpenClaw Windows Node before 2026.7.1-3 contains a missing authorization vulnerability in NodeService capture handlers that a...
CVE-2026-101878Bitwarden Server 2025.6.0 before 2026.5.0 declares the @ExternalId parameter of the User_ReadBySsoUserOrganizationIdExternalI...
CVE-2026-101101A vulnerability has been found in ag-ui-protocol ag-ui up to 2026-09-07. This issue affects the function JSON.parse of the fi...
CVE-2026-101100A flaw has been found in ag-ui-protocol ag-ui up to 2026-09-07. This vulnerability affects the function FilterToolCallsMiddle...
CVE-2026-101099A vulnerability was detected in ag-ui-protocol ag-ui up to 2026-09-23. This affects an unknown part of the file SseParser.kt ...
CVE-2026-101098A security vulnerability has been detected in ag-ui-protocol ag-ui up to 2026-09-23. Affected by this issue is the function r...
CVE-2026-101088Nezha is a server and website monitoring tool. In versions >= 2.2.11 and < 2.3.1, the service sentinel worker (service/single...
CVE-2026-101061utcp-gql before 1.1.1 and utcp-websocket before 1.1.1 contain server-side request forgery vulnerabilities due to incomplete a...
CVE-2026-101045Fleet-maintained app install and uninstall scripts for macOS are generated from Homebrew cask metadata. In manifests generate...
CVE-2026-100903A vulnerability was identified in ООО НПО Ритм GEOritm up to 2.45.1. This affects an unknown part of the file /rest...
CVE-2026-100881A security vulnerability has been detected in zhistaredu StarTraining up to 3.8.1. This issue affects some unknown processing...
CVE-2026-100848AzuraCast (Composer package azuracast/azuracast) before 0.23.8 validates a station's "Remote Relay" URL only for URL syntax a...
CVE-2026-100653vLLM is an inference and serving engine for large language models. In versions from 0.22.1 through 0.28.0, the operator-suppl...
CVE-2026-100604ClawHub (openclaw/clawhub) contains an incorrect authorization vulnerability in the ClawHub application/backend: an organizat...
CVE-2026-100602ClawHub (openclaw/clawhub application/backend) contains a missing authorization check in the changelog preview feature. A sig...
CVE-2026-100601ClawHub (openclaw/clawhub) application/backend contains a server-side request forgery vulnerability in the public profile pre...
CVE-2026-100599OpenClaw versions 2026.5.1 through 2026.7.0 fail to apply the configured exec approval path to Google Meet node commands. The...
CVE-2026-100598OpenClaw (npm package openclaw) before 2026.7.1 incorrectly binds Signal approval reactions. In affected versions, a reaction...
CVE-2026-100597OpenClaw (npm package 'openclaw') before 2026.7.1 is vulnerable to a time-of-check time-of-use race condition in OpenShell lo...
CVE-2026-100596OpenClaw versions before 2026.7.1 fail to properly authorize non-owner users executing MCP configuration changes through /mcp...
CVE-2026-100595OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the diagnostics export command that allows...
CVE-2026-100594OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability in the /export-trajectory endpoint that allow...
CVE-2026-100593OpenClaw (npm package `openclaw`) before 2026.7.1 does not enforce the documented owner-only requirement for persistent `/act...
CVE-2026-100592OpenClaw is an agent gateway distributed via npm. In versions >= 2026.4.10 and < 2026.7.1, persistent memory dreaming mutatio...
CVE-2026-100591OpenClaw is an npm-distributed agent gateway. In versions before 2026.7.1, the global Active Memory toggle mutations could om...
CVE-2026-100590OpenClaw before 2026.7.1 contains an authorization bypass vulnerability in the /voice set command that allows non-owner exter...
CVE-2026-100589OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability in the browser tool that allows sandboxed sessions t...
CVE-2026-100588OpenClaw (npm package 'openclaw') before 2026.7.1 does not enforce the administrator scope requirement on browser control whe...
CVE-2026-100587OpenClaw versions before 2026.7.1 fail to properly validate owner authorization in the Codex computer-use installation comman...
CVE-2026-100586OpenClaw Codex before 2026.7.1 fails to properly enforce owner authorization when creating native conversation bindings. Non-...
CVE-2026-100585OpenClaw (npm package `openclaw`) before 2026.7.1 fails to enforce the owner-only authorization requirement for Claude Code p...
CVE-2026-100584OpenClaw is an npm-distributed agent runtime. In versions >= 2026.2.26 and < 2026.7.1, PowerShell command analysis on Windows...
CVE-2026-100583OpenClaw Discord versions before 2026.7.1 contain an authorization bypass vulnerability in guild metadata read actions that a...
CVE-2026-100582OpenClaw channel plugins (@openclaw/msteams, @openclaw/feishu, @openclaw/matrix, and @openclaw/googlechat) before 2026.8.1 do...
CVE-2026-100581OpenClaw for iOS before 2026.8.11 stores Gateway credentials as cleartext JSON in App Group UserDefaults instead of the devic...
CVE-2026-100580OpenClaw (npm package 'openclaw') before 2026.7.1 improperly handles case sensitivity in the model-facing cron tool: a mixed-...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report