Known Vulnerabilities for Api Gateway by Ca
Listed below are 10 of the newest known vulnerabilities associated with "Api Gateway" by "Ca".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-107177 json | Express Gateway through 1.16.11 contains a hardcoded cryptographic key vulnerability that allows attackers with datastore acc... | Not Provided | 2026-10-07 | 2026-10-07 |
| CVE-2026-107162 json | Express Gateway through 1.16.11 contains an authentication bypass vulnerability in the OAuth 2.0 refresh_token grant that fai... | Not Provided | 2026-10-07 | 2026-10-07 |
| CVE-2026-105689 json | Penpot is an open-source design and prototyping platform. Prior to 2.18.0, app.util.ssrf/blocked-address? relies on Java Inet... | Not Provided | 2026-10-05 | 2026-10-05 |
| CVE-2026-104651 json | The Yaad Sarig Payment Gateway For WC WordPress plugin before 2.2.13 does not verify authorization or that the requesting use... | Not Provided | 2026-10-07 | 2026-10-07 |
| CVE-2026-104480 json | Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized ... | Not Provided | 2026-10-02 | 2026-10-02 |
| CVE-2026-103346 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tomlister Payflex Payme... | Not Provided | 2026-10-06 | 2026-10-06 |
| CVE-2026-103102 json | Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote att... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-102806 json | OpenClaw before 2026.9.5 contains an incorrect authorization vulnerability in the Gateway's local media root allowlist that b... | Not Provided | 2026-09-29 | 2026-09-29 |
| CVE-2026-102294 json | TP-Link TL-WR841N contains an authenticated OS command injection vulnerability in the IPv6 WAN configuration. A crafted IPv6 ... | Not Provided | 2026-10-01 | 2026-10-02 |
| CVE-2026-102162 json | On affected Arista Wi-Fi access points with captive portal, or application firewall enabled on at least one SSID, a vulnerabi... | Not Provided | 2026-10-06 | 2026-10-06 |