🔓 VULNERABILITIES & CVEs
-
CVE-2026-16200 zevorn rt-claw RPC authorization vulnerability — CVSS 7.3 — zevorn rt-claw RPC claw_tool_invoke authorization
A vulnerability has been identified in zevorn rt-claw's RPC claw_tool_invoke component that allows unauthorized actions due to improper authorization checks. -
CVE-2026-16199 nextlevelbuilder GoClaw ExecTool.Execute improper authorization — CVSS 6.3
nextlevelbuilder GoClaw's ExecTool.Execute function suffers from improper authorization, potentially allowing unauthorized command execution. -
CVE-2026-16198 Sipeed PicoClaw First Run Setup authentication bypass — CVSS 5.6
An authentication bypass vulnerability exists in Sipeed PicoClaw's First Run Setup access_control.go, enabling unauthorized access. -
CVE-2026-16201 zevorn rt-claw http_request information disclosure — CVSS 5.3
zevorn rt-claw http_request net.c claw_net_post component leaks sensitive information due to an information disclosure vulnerability. -
CVE-2026-16203 SourceCodester Class and Exam Timetabling System CYS.php cross site scripting
Cross-site scripting vulnerabilities have been found in SourceCodester Class and Exam Timetabling System's CYS.php file. -
CVE-2026-16202 SourceCodester Class and Exam Timetabling System CYS.php cross site scripting
Additional cross-site scripting issues are present in the same SourceCodester system affecting the CYS.php script.