Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26387
Total
1955
Critical
7970
High
8222
Medium
CVE ID Severity Score Description Published
CVE-2026-0136 UNKNOWN In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with … Jun 16, 2026
CVE-2026-0135 UNKNOWN In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote code execution with no … Jun 16, 2026
CVE-2026-0134 UNKNOWN In PostWipeData of recovery_ui.cpp, there is a possible data persistence issue after a factory reset due to a logic error in the code. This could … Jun 16, 2026
CVE-2026-0133 UNKNOWN In smmu_attach_dev of arm-smmu-v3.c, there is a possible way to sign malicious Android Runtime bootclass artifacts due to a missing permission check. This could lead … Jun 16, 2026
CVE-2026-0132 UNKNOWN In Modem, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no … Jun 16, 2026
CVE-2026-0131 UNKNOWN In RtpPacket::decodePacket, there is a possible out of bounds access due to an integer overflow. This could lead to local escalation of privilege with no … Jun 16, 2026
CVE-2026-0130 UNKNOWN In RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no … Jun 16, 2026
CVE-2026-0129 UNKNOWN In RtcpByePacket::decodeByePacket, there is a possible due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. … Jun 16, 2026
CVE-2026-0128 UNKNOWN In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional … Jun 16, 2026
CVE-2026-0127 UNKNOWN In NrmmMsgCodec::DecodeUPUTransparentContext of cn_NrmmDecoder.cpp, there is a possible out-of-bounds read due to memory corruption. This could lead to remote denial of service causing a communication … Jun 16, 2026
CVE-2026-0126 UNKNOWN In WC-Radio, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no … Jun 16, 2026
CVE-2026-0125 UNKNOWN In multiple functions of vpu_ioctl.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege … Jun 16, 2026
CVE-2026-53866 HIGH 8.1 OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing that allows authenticated operators to execute unapproved commands. A command request using shell … Jun 16, 2026
CVE-2026-53865 HIGH 7.1 OpenClaw before 2026.5.2 contains a path traversal vulnerability in maintenance task execution that allows workspace-derived service paths to influence trash command selection. Attackers can execute … Jun 16, 2026
CVE-2026-53864 HIGH 8.1 OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to … Jun 16, 2026
CVE-2026-53863 HIGH 7.1 OpenClaw before 2026.4.25 contains an input validation vulnerability in tool group policy callers that accept unvalidated group IDs. Attackers who can supply a group ID … Jun 16, 2026
CVE-2026-53862 MEDIUM 4.2 OpenClaw before 2026.5.12 contains a bootstrap token replay vulnerability allowing callers with pending token access to reuse tokens with broader requested scopes. Attackers can replay … Jun 16, 2026
CVE-2026-53861 MEDIUM 6.6 OpenClaw before 2026.5.6 contains an allowlist bypass vulnerability in the macOS Swift exec feature that misses combined POSIX inline-command flags. Attackers can execute shell content … Jun 16, 2026
CVE-2026-53860 MEDIUM 4.2 OpenClaw before 2026.5.7 contains a sender policy bypass vulnerability in BlueBubbles that allows participants to match allowlist entries through conversation metadata rather than stable sender … Jun 16, 2026
CVE-2026-53859 MEDIUM 6.5 OpenClaw before 2026.5.26 contains a hostname validation vulnerability allowing attackers to bypass blocklist comparisons using trailing-dot notation in model or workspace-derived URLs. Attackers can exploit … Jun 16, 2026
CVE-2026-53858 HIGH 7.1 OpenClaw before 2026.5.2 contains an environment variable injection vulnerability where workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots. Attackers can manipulate the STATE_DIRECTORY variable … Jun 16, 2026
CVE-2026-53857 HIGH 8.1 OpenClaw before 2026.5.3 contains a policy enforcement vulnerability where Zalo contacts with mutable display metadata could match allowFrom policy entries through display name changes. Attackers … Jun 16, 2026
CVE-2026-53856 MEDIUM 5.5 OpenClaw before 2026.4.24 contains an insecure file permissions vulnerability in config recovery that restores OpenClaw.json with overly broad permissions. Local attackers on shared hosts can … Jun 16, 2026
CVE-2026-53855 HIGH 8.1 OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing authenticated operators to weaken strict allowlist checks via shell positional parameters. Attackers can combine allowlisted tools … Jun 16, 2026
CVE-2026-53854 MEDIUM 6.5 OpenClaw before 2026.4.25 contains a privilege escalation vulnerability in internal and webchat command authentication that allows senders to inherit wildcard ownerAllowFrom state across channel boundaries. … Jun 16, 2026