Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

51943
Total
4127
Critical
15407
High
15098
Medium
CVE ID Severity Score Description Published
CVE-2026-62219 HIGH 7.1 OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds validation. A lower-trust caller or configured input path can bypass agent ID … Jul 17, 2026
CVE-2026-62218 HIGH 8.8 OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature that allows lower-trust callers to bypass role-management checks. Attackers can perform actions … Jul 17, 2026
CVE-2026-62217 HIGH 8.8 OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. When the feature is enabled and reachable, a lower-trust caller or … Jul 17, 2026
CVE-2026-62216 MEDIUM 5.0 OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media upload feature. A lower-trust caller or configured input path could cause the media … Jul 17, 2026
CVE-2026-62215 HIGH 8.0 OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability in HTTP Canvas responses that allows lower-trust callers to forge trusted A2UI actions. Attackers can perform … Jul 17, 2026
CVE-2026-62214 MEDIUM 6.5 OpenClaw versions before 2026.5.28 Bot Framework contains an improper input validation vulnerability that allows lower-trust callers to expose bot tokens and credentials by failing to … Jul 17, 2026
CVE-2026-62213 MEDIUM 6.5 OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower-trust callers to expose Bot Framework tokens. Attackers can … Jul 17, 2026
CVE-2026-62212 HIGH 7.1 OpenClaw before 2026.5.28 contains a race condition in the MS Teams safeFetch DNS rebinding check. When the affected feature is enabled and reachable, a lower-trust … Jul 17, 2026
CVE-2026-62211 MEDIUM 5.0 OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature that allows lower-trust callers to access data that should remain … Jul 17, 2026
CVE-2026-62210 MEDIUM 6.5 OpenClaw versions before 2026.6.1 contain a denial of service vulnerability where remote media URLs can trigger slow-read attacks that exhaust gateway worker resources. Attackers with … Jul 17, 2026
CVE-2026-62209 HIGH 8.1 OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mode dispatch feature, which could ignore the toolsAllow policy check. When the affected … Jul 17, 2026
CVE-2026-62208 MEDIUM 6.5 OpenClaw before 2026.6.5 could forward Authorization headers during MCP SSE redirects. When the affected feature is enabled and reachable, a lower-trust caller or configured input … Jul 17, 2026
CVE-2026-62207 HIGH 8.8 OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability that allows lower-trust callers to reach admin-scoped tools. Attackers can perform actions requiring stronger authorization by … Jul 17, 2026
CVE-2026-62206 HIGH 7.1 OpenClaw versions before 2026.6.9 contain a missing authorization vulnerability in Discord moderation actions. In affected versions, a lower-trust caller or configured input path could perform … Jul 17, 2026
CVE-2026-62205 HIGH 7.1 OpenClaw versions 2026.4.12-beta.1 before 2026.6.6 contain a missing-authorization vulnerability in the MS Teams message actions feature. When the affected feature is enabled and reachable, a … Jul 17, 2026
CVE-2026-62203 HIGH 8.8 OpenClaw versions before 2026.6.6 contain an environment variable filtering vulnerability in host exec that fails to properly sanitize rustup startup variables. Attackers with lower-trust caller … Jul 17, 2026
CVE-2026-62202 HIGH 8.8 OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that allows lower-trust callers to regain denied execution tools. Attackers can … Jul 17, 2026
CVE-2026-62201 HIGH 7.7 OpenClaw versions before 2026.6.6 contain a network policy bypass vulnerability in the sandbox exec-server that allows lower-trust callers to reach internal network destinations blocked by … Jul 17, 2026
CVE-2026-44251 MEDIUM 6.5 Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.0.0 and above, prior to 4.14.5, a size_t … Jul 17, 2026
CVE-2026-40106 MEDIUM 4.7 Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.6.0 and above prior to 4.14.5 contain a heap-based … Jul 17, 2026
CVE-2026-2594 MEDIUM 6.4 The Smart Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.7. This is due to insufficient … Jul 17, 2026
CVE-2026-14956 CRITICAL 9.8 The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper validation of … Jul 17, 2026
CVE-2026-54340 HIGH 7.5 h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 9265bdd, there is an HTTP/2 state amplification issue that combines … Jul 17, 2026
CVE-2026-39359 HIGH 7.5 Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.0.0 through 4.10.3 and 4.11.0 through 4.14.4, a … Jul 17, 2026
CVE-2026-34150 HIGH 7.5 Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 1.0.0 and above, prior to 4.14.5, a heap … Jul 17, 2026