Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26401
Total
1955
Critical
7975
High
8228
Medium
CVE ID Severity Score Description Published
CVE-2026-12016 HIGH 8.3 Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox … Jun 11, 2026
CVE-2026-12015 MEDIUM 5.3 Use after free in Autofill in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive … Jun 11, 2026
CVE-2026-12014 HIGH 8.3 Use after free in Cast in Google Chrome prior to 149.0.7827.115 allowed an attacker on the local network segment to potentially perform a sandbox escape … Jun 11, 2026
CVE-2026-12013 HIGH 8.8 Use after free in Media in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruption via a crafted … Jun 11, 2026
CVE-2026-12012 HIGH 8.1 Use after free in Network in Google Chrome prior to 149.0.7827.115 allowed an attacker in a privileged network position to potentially exploit heap corruption via … Jun 11, 2026
CVE-2026-12011 HIGH 8.3 Use after free in WebMIDI in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially … Jun 11, 2026
CVE-2026-12010 HIGH 8.3 Heap buffer overflow in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially … Jun 11, 2026
CVE-2026-12009 HIGH 8.3 Insufficient validation of untrusted input in Accessibility in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process … Jun 11, 2026
CVE-2026-12008 HIGH 8.3 Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a … Jun 11, 2026
CVE-2026-12007 HIGH 8.8 Use after free in Core in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to execute arbitrary code via a crafted HTML … Jun 11, 2026
CVE-2026-53819 HIGH 8.8 OpenClaw before 2026.5.27 contains an arbitrary code execution vulnerability in skill install flows where workspace .env files can override the Homebrew executable selection. Attackers with … Jun 11, 2026
CVE-2026-53818 MEDIUM 6.6 OpenClaw before 2026.4.24 contains an authorization bypass vulnerability in the MCP loopback feature that allows non-owner callers to skip owner-only tool policies and before-tool-call hooks. … Jun 11, 2026
CVE-2026-53817 HIGH 8.8 OpenClaw before 2026.5.22 contains a locality validation vulnerability in Control UI pairing that allows attackers with network access to spoof locality information and obtain durable … Jun 11, 2026
CVE-2026-53816 HIGH 7.2 OpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event handling that allows paired nodes to forge exec lifecycle events without system.run authorization. … Jun 11, 2026
CVE-2026-53815 MEDIUM 6.5 OpenClaw before 2026.5.19 contains an authorization bypass vulnerability in message read actions that skips channel allowlist checks. Lower-trust callers can request messages from channels not … Jun 11, 2026
CVE-2026-53814 HIGH 8.3 OpenClaw before 2026.5.20 contains a privilege escalation vulnerability where hook-triggered agent runs incorrectly receive owner-scoped MCP loopback authority instead of hook-appropriate scope. Attackers with a … Jun 11, 2026
CVE-2026-53813 HIGH 7.8 OpenClaw before 2026.4.25 contains a path traversal vulnerability in memory-core artifact loading where workspace state influences local package root resolution. Attackers with access to affected … Jun 11, 2026
CVE-2026-53812 HIGH 7.7 OpenClaw before 2026.5.18 contains a server-side request forgery vulnerability in browser control that allows authenticated users to bypass private-network navigation checks through Playwright act interactions. … Jun 11, 2026
CVE-2026-53811 HIGH 8.8 OpenClaw before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom feature that allows authenticated accounts to match policy entries through mutable display name … Jun 11, 2026
CVE-2026-53810 HIGH 8.8 OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata can redirect loading toward unscanned package payloads. Attackers with trusted operator access … Jun 11, 2026
CVE-2026-53809 LOW 3.8 OpenClaw before 2026.4.25 contains a policy bypass vulnerability in embedded runner policy that allows requests using provider aliases to compare against aliases instead of canonical … Jun 11, 2026
CVE-2026-53808 MEDIUM 6.5 OpenClaw before 2026.5.6 contains an approval policy bypass vulnerability in the Skill Workshop apply flow that allows agent tool calls to set apply: true despite … Jun 11, 2026
CVE-2026-53807 HIGH 8.8 OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that allows authenticated users to skip commands.allowFrom validation. Attackers can invoke affected callbacks … Jun 11, 2026
CVE-2026-53806 HIGH 8.8 OpenClaw before 2026.5.12 contains a shell option parsing vulnerability that allows combined POSIX shell flags to bypass exec revalidation checks. Attackers can exploit this by … Jun 11, 2026
CVE-2026-50245 HIGH 7.7 Brickcom cameras allow unauthenticated access to live snapshot images via the /ONVIF endpoint and no authentication is required to retrieve still images from the camera … Jun 11, 2026