Total CVEs

138,574

Critical Severity

3,576

High Severity

12,840

Last 7 Days

2,055
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 2,121 - 2,140 of 34,979 CVEs

An authorization flaw in MISP’s object add/edit handling allowed an authenticated user with object editing permissions to assign a MISP object, or attributes contained within an object, to a sharing group that the user was not authorized to use or view. When editing objects, the sharing group valida...

Vendor: misp
Product: misp
Published: Jun 12, 2026
Source: NVD

Rejected reason: CVE ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-53826. Reason: This candidate is a duplicate of CVE-2025-53826. Notes: All CVE users should reference CVE-2025-53826 instead of this candidate

Published: Jun 12, 2026
Source: NVD
CVE-2026-53868 HIGH - 7.5

Capgo before 12.128.2 contains a denial of service vulnerability allowing attackers to register accounts using arbitrary email addresses without verification, then initiate deletion to lock emails in pending deletion state. Attackers can permanently lock legitimate users out of the platform for 30 d...

Vendor: Capgo
Product: Capgo
Published: Jun 12, 2026
Source: NVD
CVE-2026-53867 MEDIUM - 4.3

Capgo before 12.128.2 fails to delete previously uploaded profile images from backend storage when users replace or remove them. Attackers can access orphaned image files through previously generated URLs, allowing unauthorized retrieval of user-uploaded content.

Vendor: Cap-go
Product: capgo
Published: Jun 12, 2026
Source: NVD
CVE-2026-53839 MEDIUM - 6.5

OpenClaw before 2026.5.7 contains a hostname validation vulnerability in retry endpoint checks that allows matching hostname prefixes instead of exact hostnames. Attackers can exploit this by crafting a hostname prefix resembling a trusted host to send authentication material to untrusted endpoints.

Vendor: OpenClaw
Product: OpenClaw
Published: Jun 12, 2026
Source: NVD
CVE-2026-53838 CRITICAL - 9.8

OpenClaw before 2026.5.27 contains a state mutation vulnerability in node pairing reconnection that allows paired nodes to confuse approval scope decisions. Attackers can exploit reconnection logic to restore or present broader node authority than intended, potentially bypassing approval restriction...

Vendor: OpenClaw
Product: OpenClaw
Published: Jun 12, 2026
Source: NVD

OpenClaw before 2026.5.6 contains an improper access control vulnerability in Mattermost event handlers that fails to validate channel type metadata. Attackers can bypass intended DM policy decisions by sending crafted Mattermost events missing channel type information to process restricted content.

Vendor: OpenClaw
Product: OpenClaw
Published: Jun 12, 2026
Source: NVD
CVE-2026-53836 HIGH - 8.8

OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in PowerShell encoded-command handling that allows attackers to execute encoded commands using abbreviated flag aliases not recognized by the allowlist parser. Remote authenticated operators can bypass execution allowlist checks by...

Vendor: OpenClaw
Product: OpenClaw
Published: Jun 12, 2026
Source: NVD
CVE-2026-53835 MEDIUM - 4.3

OpenClaw before 2026.5.6 contains a configuration enforcement bypass vulnerability in Feishu dynamic-agent bindings that allows authenticated senders to create or update bindings without honoring configured config-write controls. Attackers can exploit this by leveraging the dynamic-agent binding fea...

Vendor: OpenClaw
Product: OpenClaw
Published: Jun 12, 2026
Source: NVD
CVE-2026-53834 HIGH - 7.5

OpenClaw before 2026.4.27 contains an authorization bypass vulnerability in QQBot pre-dispatch slash commands that allows authenticated senders to skip allowFrom policy checks. Attackers can invoke slash commands before configured access control policies are applied, potentially triggering command h...

Vendor: OpenClaw
Product: OpenClaw
Published: Jun 12, 2026
Source: NVD
CVE-2026-53833 HIGH - 7.7

OpenClaw before 2026.4.29 contains an authorization bypass vulnerability in the QQBot streaming command that allows authenticated senders to mutate configuration without explicit allowFrom restrictions. Attackers can modify QQBot streaming configuration outside intended admin policy by reaching the ...

Vendor: QQBot
Product: QQBot
Published: Jun 12, 2026
Source: NVD
CVE-2026-53832 HIGH - 7.7

OpenClaw before 2026.5.18 contains an identity header validation vulnerability allowing local same-host callers to forge trusted-proxy identity headers. Attackers with access to the proxy-facing Gateway port can supply forged identity headers to assume operator identity and potentially escalate priv...

Vendor: OpenClaw
Product: OpenClaw
Published: Jun 12, 2026
Source: NVD
CVE-2026-53831 HIGH - 8.3

OpenClaw before 2026.5.18 contains a policy enforcement vulnerability in system.run safe-bin allowlist validation that allows shell expansion to modify command interpretation on POSIX nodes. Authenticated operators can exploit shell metacharacters in approved commands to read unintended node-local f...

Vendor: OpenClaw
Product: OpenClaw
Published: Jun 12, 2026
Source: NVD
CVE-2026-53830 MEDIUM - 6.5

OpenClaw before 2026.4.22 contains a webhook secret revocation bypass vulnerability allowing callers with old Slack and Zalo webhook secrets to remain active after secrets.reload. Attackers can exploit the stale-secret window to deliver webhook events after operator-expected secret revocation, poten...

Vendor: OpenClaw
Product: OpenClaw
Published: Jun 12, 2026
Source: NVD
CVE-2026-53829 HIGH - 8.0

OpenClaw before 2026.5.18 contains an approval display truncation vulnerability allowing authenticated users to hide command suffixes from approvers. Attackers can submit oversized exec commands with benign prefixes and malicious suffixes to execute unauthorized operations after approval.

Vendor: OpenClaw
Product: OpenClaw
Published: Jun 12, 2026
Source: NVD
CVE-2026-53828 HIGH - 8.8

OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in native command handling that allows authenticated senders to execute owner-only commands without proper policy enforcement. Attackers can trigger native command handling to bypass the configured owner-command access control, ...

Vendor: OpenClaw
Product: OpenClaw
Published: Jun 12, 2026
Source: NVD
CVE-2026-53827 MEDIUM - 6.5

OpenClaw before 2026.5.2 contains a credential exposure vulnerability in message.action forwarding that allows model-controlled metadata to forward action payloads with Gateway credentials to attacker-supplied loopback URLs. Remote attackers can intercept Gateway tokens and action payloads by provid...

Vendor: OpenClaw
Product: OpenClaw
Published: Jun 12, 2026
Source: NVD
CVE-2026-53826 MEDIUM - 4.3

OpenClaw before 2026.4.26 contains an information disclosure vulnerability in sandboxed session spawning that exposes the real workspace path to child prompts. Attackers can exploit this by spawning child sessions from sandboxed parents to reveal host workspace location or related memory context to ...

Vendor: OpenClaw
Product: OpenClaw
Published: Jun 12, 2026
Source: NVD
CVE-2026-53825 MEDIUM - 6.5

OpenClaw before 2026.4.7 contains an arbitrary file read vulnerability in the memory-wiki ingest feature that allows authenticated Gateway operators with operator.write scope to read local files outside intended ingest sources. Attackers with operator.write access can specify arbitrary local file pa...

Vendor: OpenClaw
Product: OpenClaw
Published: Jun 12, 2026
Source: NVD
CVE-2026-53824 MEDIUM - 6.5

OpenClaw before 2026.4.24 contains a token revocation vulnerability allowing callers with revoked slash tokens to continue executing commands during monitor refresh windows. Attackers can exploit stale token acceptance to invoke slash command behavior briefly after token revocation, potentially exec...

Vendor: OpenClaw
Product: OpenClaw
Published: Jun 12, 2026
Source: NVD