Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26387
Total
1955
Critical
7970
High
8222
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-0136 | UNKNOWN | — | In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with … | Jun 16, 2026 |
| CVE-2026-0135 | UNKNOWN | — | In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote code execution with no … | Jun 16, 2026 |
| CVE-2026-0134 | UNKNOWN | — | In PostWipeData of recovery_ui.cpp, there is a possible data persistence issue after a factory reset due to a logic error in the code. This could … | Jun 16, 2026 |
| CVE-2026-0133 | UNKNOWN | — | In smmu_attach_dev of arm-smmu-v3.c, there is a possible way to sign malicious Android Runtime bootclass artifacts due to a missing permission check. This could lead … | Jun 16, 2026 |
| CVE-2026-0132 | UNKNOWN | — | In Modem, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no … | Jun 16, 2026 |
| CVE-2026-0131 | UNKNOWN | — | In RtpPacket::decodePacket, there is a possible out of bounds access due to an integer overflow. This could lead to local escalation of privilege with no … | Jun 16, 2026 |
| CVE-2026-0130 | UNKNOWN | — | In RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no … | Jun 16, 2026 |
| CVE-2026-0129 | UNKNOWN | — | In RtcpByePacket::decodeByePacket, there is a possible due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. … | Jun 16, 2026 |
| CVE-2026-0128 | UNKNOWN | — | In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional … | Jun 16, 2026 |
| CVE-2026-0127 | UNKNOWN | — | In NrmmMsgCodec::DecodeUPUTransparentContext of cn_NrmmDecoder.cpp, there is a possible out-of-bounds read due to memory corruption. This could lead to remote denial of service causing a communication … | Jun 16, 2026 |
| CVE-2026-0126 | UNKNOWN | — | In WC-Radio, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no … | Jun 16, 2026 |
| CVE-2026-0125 | UNKNOWN | — | In multiple functions of vpu_ioctl.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege … | Jun 16, 2026 |
| CVE-2026-53866 | HIGH | 8.1 | OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing that allows authenticated operators to execute unapproved commands. A command request using shell … | Jun 16, 2026 |
| CVE-2026-53865 | HIGH | 7.1 | OpenClaw before 2026.5.2 contains a path traversal vulnerability in maintenance task execution that allows workspace-derived service paths to influence trash command selection. Attackers can execute … | Jun 16, 2026 |
| CVE-2026-53864 | HIGH | 8.1 | OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to … | Jun 16, 2026 |
| CVE-2026-53863 | HIGH | 7.1 | OpenClaw before 2026.4.25 contains an input validation vulnerability in tool group policy callers that accept unvalidated group IDs. Attackers who can supply a group ID … | Jun 16, 2026 |
| CVE-2026-53862 | MEDIUM | 4.2 | OpenClaw before 2026.5.12 contains a bootstrap token replay vulnerability allowing callers with pending token access to reuse tokens with broader requested scopes. Attackers can replay … | Jun 16, 2026 |
| CVE-2026-53861 | MEDIUM | 6.6 | OpenClaw before 2026.5.6 contains an allowlist bypass vulnerability in the macOS Swift exec feature that misses combined POSIX inline-command flags. Attackers can execute shell content … | Jun 16, 2026 |
| CVE-2026-53860 | MEDIUM | 4.2 | OpenClaw before 2026.5.7 contains a sender policy bypass vulnerability in BlueBubbles that allows participants to match allowlist entries through conversation metadata rather than stable sender … | Jun 16, 2026 |
| CVE-2026-53859 | MEDIUM | 6.5 | OpenClaw before 2026.5.26 contains a hostname validation vulnerability allowing attackers to bypass blocklist comparisons using trailing-dot notation in model or workspace-derived URLs. Attackers can exploit … | Jun 16, 2026 |
| CVE-2026-53858 | HIGH | 7.1 | OpenClaw before 2026.5.2 contains an environment variable injection vulnerability where workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots. Attackers can manipulate the STATE_DIRECTORY variable … | Jun 16, 2026 |
| CVE-2026-53857 | HIGH | 8.1 | OpenClaw before 2026.5.3 contains a policy enforcement vulnerability where Zalo contacts with mutable display metadata could match allowFrom policy entries through display name changes. Attackers … | Jun 16, 2026 |
| CVE-2026-53856 | MEDIUM | 5.5 | OpenClaw before 2026.4.24 contains an insecure file permissions vulnerability in config recovery that restores OpenClaw.json with overly broad permissions. Local attackers on shared hosts can … | Jun 16, 2026 |
| CVE-2026-53855 | HIGH | 8.1 | OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing authenticated operators to weaken strict allowlist checks via shell positional parameters. Attackers can combine allowlisted tools … | Jun 16, 2026 |
| CVE-2026-53854 | MEDIUM | 6.5 | OpenClaw before 2026.4.25 contains a privilege escalation vulnerability in internal and webchat command authentication that allows senders to inherit wildcard ownerAllowFrom state across channel boundaries. … | Jun 16, 2026 |