A vulnerability categorized as problematic has been discovered in unitedbyai droidclaw up to 0.5.3. The affected element is an unknown function of the file server/src/routes/pairing.ts of the component claim Endpoint. The manipulation results in improper restriction of excessive authentication attempts.
This vulnerability is cataloged as CVE-2026-10216. The attack may be launched remotely. Furthermore, there is an exploit available.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability was found in Dolibarr ERP CRM up to 23.0.1. It has been rated as critical. Impacted is the function checkUserAccessToObject of the file htdocs/holiday/class/api_holidays.class.php of the component Leave Request REST API. The manipulation leads to improper authorization.
This vulnerability is listed as CVE-2026-10215. The attack may be initiated remotely. In addition, an exploit is available.
Upgrading the affected component is advised.
A vulnerability was found in zhayujie chatgpt-on-wechat up to 2.0.8. It has been declared as critical. This issue affects the function _get_safety_warning of the file agent/tools/bash/bash.py of the component Bash Tool. Executing a manipulation can lead to os command injection.
This vulnerability is tracked as CVE-2026-10214. The attack can be launched remotely. Moreover, an exploit is present.
It is recommended to upgrade the affected component.
A vulnerability was found in AstrBotDevs AstrBot 4.23.6. It has been classified as critical. This vulnerability affects unknown code of the file /api/skills/delete of the component API Endpoint. Performing a manipulation of the argument Name results in path traversal.
This vulnerability is identified as CVE-2026-10213. The attack can be initiated remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in AstrBotDevs AstrBot 4.24.2 and classified as critical. This affects the function astr_main_agent of the file astrbot/core/astr_main_agent.py. Such manipulation of the argument session_id leads to authorization bypass.
This vulnerability is referenced as CVE-2026-10212. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability has been found in AstrBotDevs AstrBot 4.23.6 and classified as critical. Affected by this issue is the function _normalize_rw_path of the file astrbot/core/tools/computer_tools/fs.py. This manipulation causes incorrect authorization.
The identification of this vulnerability is CVE-2026-10211. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability, which was classified as critical, was found in AstrBotDevs AstrBot 4.23.6. Affected by this vulnerability is the function _sanitize_prompt_description of the file astrbot/core/skills/skill_manager.py. The manipulation results in injection.
This vulnerability was named CVE-2026-10210. The attack may be performed from remote. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability, which was classified as critical, has been found in code-projects Online Hospital Management System 1.0. Affected is an unknown function of the file appointmentdetail.php of the component Appointment Handler. The manipulation of the argument editid leads to sql injection.
This vulnerability is uniquely identified as CVE-2026-10209. The attack is possible to be carried out remotely. Moreover, an exploit is present.