CVE Database

114851+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-0129
3.5 LOW

In RtcpByePacket::decodeByePacket, there is a possible due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. …

Jun 16, 2026
CVE-2026-0128

In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional …

Jun 16, 2026
CVE-2026-0127
6.5 MEDIUM

In NrmmMsgCodec::DecodeUPUTransparentContext of cn_NrmmDecoder.cpp, there is a possible out-of-bounds read due to memory corruption. This could lead to remote denial of service causing a communication …

Jun 16, 2026
CVE-2026-0126

In WC-Radio, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no …

Jun 16, 2026
CVE-2026-0125
7.0 HIGH

In multiple functions of vpu_ioctl.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege …

Jun 16, 2026
CVE-2026-53866
8.1 HIGH

OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing that allows authenticated operators to execute unapproved commands. A command request using shell …

Jun 16, 2026
CVE-2026-53865
7.1 HIGH

OpenClaw before 2026.5.2 contains a path traversal vulnerability in maintenance task execution that allows workspace-derived service paths to influence trash command selection. Attackers can execute …

Jun 16, 2026
CVE-2026-53864
8.1 HIGH

OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables to bypass validation. Attackers with access to …

Jun 16, 2026
CVE-2026-53863
7.1 HIGH

OpenClaw before 2026.4.25 contains an input validation vulnerability in tool group policy callers that accept unvalidated group IDs. Attackers who can supply a group ID …

Jun 16, 2026
CVE-2026-53862
4.2 MEDIUM

OpenClaw before 2026.5.12 contains a bootstrap token replay vulnerability allowing callers with pending token access to reuse tokens with broader requested scopes. Attackers can replay …

Jun 16, 2026
CVE-2026-53861
6.6 MEDIUM

OpenClaw before 2026.5.6 contains an allowlist bypass vulnerability in the macOS Swift exec feature that misses combined POSIX inline-command flags. Attackers can execute shell content …

Jun 16, 2026
CVE-2026-53860
4.2 MEDIUM

OpenClaw before 2026.5.7 contains a sender policy bypass vulnerability in BlueBubbles that allows participants to match allowlist entries through conversation metadata rather than stable sender …

Jun 16, 2026
CVE-2026-53859
6.5 MEDIUM

OpenClaw before 2026.5.26 contains a hostname validation vulnerability allowing attackers to bypass blocklist comparisons using trailing-dot notation in model or workspace-derived URLs. Attackers can exploit …

Jun 16, 2026
CVE-2026-53858
7.1 HIGH

OpenClaw before 2026.5.2 contains an environment variable injection vulnerability where workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots. Attackers can manipulate the STATE_DIRECTORY variable …

Jun 16, 2026
CVE-2026-53857
8.1 HIGH

OpenClaw before 2026.5.3 contains a policy enforcement vulnerability where Zalo contacts with mutable display metadata could match allowFrom policy entries through display name changes. Attackers …

Jun 16, 2026
CVE-2026-53856
5.5 MEDIUM

OpenClaw 2026.4.23 before 2026.4.24 contains an insecure file permissions vulnerability in config recovery that restores OpenClaw.json with overly broad permissions. Local attackers on shared hosts …

Jun 16, 2026
CVE-2026-53855
8.1 HIGH

OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing authenticated operators to weaken strict allowlist checks via shell positional parameters. Attackers can combine allowlisted tools …

Jun 16, 2026
CVE-2026-53854
6.5 MEDIUM

OpenClaw before 2026.4.25 contains a privilege escalation vulnerability in internal and webchat command authentication that allows senders to inherit wildcard ownerAllowFrom state across channel boundaries. …

Jun 16, 2026
CVE-2026-53853
8.3 HIGH

OpenClaw before 2026.5.12 contains an argument pattern validation bypass in the exec allowlist that allows attackers to execute disallowed arguments for allowlisted executables on Linux …

Jun 16, 2026
CVE-2026-53852
5.4 MEDIUM

OpenClaw before 2026.4.25 contains a scope containment bypass vulnerability in device re-pairing that allows authenticated operators to restore broader scopes than intended by submitting empty-scope …

Jun 16, 2026
CVE-2026-53851
5.3 MEDIUM

OpenClaw before 2026.5.12 contains a notification bypass vulnerability allowing Slack reaction events to enter the agent pipeline despite disabled reaction notifications. Attackers can trigger unintended …

Jun 16, 2026
CVE-2026-53850
5.5 MEDIUM

OpenClaw before 2026.4.25 contains a control scope enforcement bypass vulnerability in the focus command that allows authenticated callers to execute the command without proper authorization …

Jun 16, 2026
CVE-2026-53849
8.1 HIGH

OpenClaw before 2026.5.7 contains a privilege escalation vulnerability where the allowFrom feature improperly validates Discord account identity using mutable display names instead of immutable user …

Jun 16, 2026
CVE-2026-53848
4.3 MEDIUM

OpenClaw before 2026.5.26 contains an exec allowlist bypass vulnerability allowing authenticated operators to execute wrapper-level side effects outside allowlisted command intent. Attackers can craft command …

Jun 16, 2026
CVE-2026-53847
5.4 MEDIUM

OpenClaw before 2026.5.6 contains a privilege escalation vulnerability in the Active Memory write scope that allows Gateway operators with operator.write access to modify global configuration …

Jun 16, 2026
CVE-2026-53846
7.1 HIGH

OpenClaw before 2026.4.29 contains a path traversal vulnerability in the install helper that allows workspace .env files to override the npm_execpath configuration used for bundled …

Jun 16, 2026
CVE-2026-53845
4.3 MEDIUM

OpenClaw before 2026.5.6 contains a hook bypass vulnerability where skill commands routed through the affected dispatch path skip before-tool-call hook coverage. Attackers can exploit this …

Jun 16, 2026
CVE-2026-53844
6.5 MEDIUM

OpenClaw before 2026.4.29 contains a session visibility check bypass vulnerability in shared memory search that allows authenticated callers to access memory entries without proper authorization. …

Jun 16, 2026
CVE-2026-53843
8.8 HIGH

OpenClaw before 2026.5.26 contains an authorization bypass vulnerability where a surviving pairing-scoped device session can re-establish node token authority after revocation. Attackers with a paired …

Jun 16, 2026
CVE-2026-53842
7.1 HIGH

OpenClaw before 2026.5.2 contains an environment variable injection vulnerability allowing workspace .env files to influence Python runtime selection through CLOUDSDK_PYTHON during Gmail setup gcloud execution. …

Jun 16, 2026
CVE-2026-53841
6.1 MEDIUM

OpenClaw before 2026.5.12 contains a cross-site scripting vulnerability in exported session HTML that preserves unsafe javascript: and data: links in generated content. Attackers can execute …

Jun 16, 2026
CVE-2026-53840
7.1 HIGH

OpenClaw before 2026.5.12 contains an information disclosure vulnerability in streamable-http MCP servers that forwards operator-configured custom headers during cross-origin redirects. Attackers controlling or compromising an …

Jun 16, 2026
CVE-2026-50656
7.8 HIGH

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". We are …

Jun 16, 2026
CVE-2026-4367
5.5 MEDIUM

A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `xpmNextWord()` function by processing a …

Jun 16, 2026
CVE-2026-48775
6.8 MEDIUM

LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In versions 4.1.0 and prior, the …

Jun 16, 2026
CVE-2026-47964
7.8 HIGH

DNG SDK versions 1.7.1 2536 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Jun 16, 2026
CVE-2026-47963
5.5 MEDIUM

DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Jun 16, 2026
CVE-2026-47934
5.5 MEDIUM

DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Jun 16, 2026
CVE-2026-47927
5.5 MEDIUM

DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Jun 16, 2026
CVE-2026-47749
7.8 HIGH

stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. Versions prior to master-584-0a7ae07 are …

Jun 16, 2026
CVE-2026-47748
5.5 MEDIUM

stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. Versions prior to master-584-0a7ae07 are …

Jun 16, 2026
CVE-2026-10748

An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating system commands as the Nexus process user …

Jun 16, 2026
CVE-2024-39575
7.4 HIGH

update_disk_psu_baseline.sh requires password in plain text

Jun 16, 2026
CVE-2026-53776
9.1 CRITICAL

Perry before 0.5.1166 contains a JWT validation vulnerability that allows remote attackers to bypass token expiration by exploiting the unconditional setting of validate_exp = false …

Jun 16, 2026
CVE-2026-44932
8.8 HIGH

Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attackers operating a malicious DHCP server …

Jun 16, 2026
CVE-2026-42089
8.6 HIGH

Yeoman Environment provides an API to discover, create, and run generators, and to configure where and how a generator is resolved. Versions 2.9.0 through 6.0.0 …

Jun 16, 2026
CVE-2026-39927

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 16, 2026
CVE-2026-39926

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 16, 2026
CVE-2026-24228
7.8 HIGH

NVIDIA NeMo Framework for Linux contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploit of this vulnerability may lead …

Jun 16, 2026
CVE-2026-24155
7.8 HIGH

NVIDIA NeMo Framework for all platforms contains a code injection vulnerability. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, …

Jun 16, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.