Total CVEs

137,241

Critical Severity

3,307

High Severity

12,254

Last 7 Days

1,423
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 301 - 320 of 11,951 CVEs
CVE-2026-12068 HIGH - 7.4

Information disclosure vulnerability in Avira Password Manager when used with Mozilla Firefox may allow a remote attacker operating a cross-origin iframe to obtain credentials autofilled for the parent web page via incorrect autofill field selection. This issue affects Avira Password Manager when u...

Vendor: Gen Digital
Product: Avira Password Manager
Published: Jun 12, 2026
Source: NVD
CVE-2025-9033 HIGH - 7.8

Heap buffer out-of-bounds read vulnerability in Avira Antivirus engine when scanning a malformed PDF file may allow Local Execution of Code or Denial-of-Service of the antivirus engine process. This issue affects Avira Antivirus on Windows, macOS, and Linux for engine builds before 8.3.70.76.

Published: Jun 12, 2026
Source: NVD
CVE-2025-9032 HIGH - 7.8

Heap buffer out-of-bounds read vulnerability in Avira Antivirus engine when scanning a malformed Windows PE file may allow Local Execution of Code or Denial-of-Service of the antivirus engine process. This issue affects Avira Antivirus on Windows, macOS, and Linux for engine builds before 8.3.70.98...

Published: Jun 12, 2026
Source: NVD
CVE-2025-14098 HIGH - 7.8

Heap buffer out-of-bounds write vulnerability due to integer overflow in Avira Antivirus engine when scanning a malformed MS-DOS executable file may allow Local Execution of Code or Denial-of-Service of the antivirus engine process. This issue affects Avira Antivirus on Windows, macOS, and Linux fo...

Vendor: Gen Digital
Product: Avira Antivirus
Published: Jun 12, 2026
Source: NVD

File Browser has a Command Execution Allowlist Bypass via Shell Metacharacter Injection

Vendor: go
Product: github.com/filebrowser/filebrowser/v2
Published: Jun 12, 2026
Source: GitHub
CVE-2026-53868 HIGH - 7.5

Capgo before 12.128.2 contains a denial of service vulnerability allowing attackers to register accounts using arbitrary email addresses without verification, then initiate deletion to lock emails in pending deletion state. Attackers can permanently lock legitimate users out of the platform for 30 d...

Vendor: Capgo
Product: Capgo
Published: Jun 12, 2026
Source: NVD
CVE-2026-53836 HIGH - 8.8

OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in PowerShell encoded-command handling that allows attackers to execute encoded commands using abbreviated flag aliases not recognized by the allowlist parser. Remote authenticated operators can bypass execution allowlist checks by...

Vendor: OpenClaw
Product: OpenClaw
Published: Jun 12, 2026
Source: NVD
CVE-2026-53834 HIGH - 7.5

OpenClaw before 2026.4.27 contains an authorization bypass vulnerability in QQBot pre-dispatch slash commands that allows authenticated senders to skip allowFrom policy checks. Attackers can invoke slash commands before configured access control policies are applied, potentially triggering command h...

Vendor: OpenClaw
Product: OpenClaw
Published: Jun 12, 2026
Source: NVD
CVE-2026-53833 HIGH - 7.7

OpenClaw before 2026.4.29 contains an authorization bypass vulnerability in the QQBot streaming command that allows authenticated senders to mutate configuration without explicit allowFrom restrictions. Attackers can modify QQBot streaming configuration outside intended admin policy by reaching the ...

Vendor: QQBot
Product: QQBot
Published: Jun 12, 2026
Source: NVD
CVE-2026-53832 HIGH - 7.7

OpenClaw before 2026.5.18 contains an identity header validation vulnerability allowing local same-host callers to forge trusted-proxy identity headers. Attackers with access to the proxy-facing Gateway port can supply forged identity headers to assume operator identity and potentially escalate priv...

Vendor: OpenClaw
Product: OpenClaw
Published: Jun 12, 2026
Source: NVD
CVE-2026-53831 HIGH - 8.3

OpenClaw before 2026.5.18 contains a policy enforcement vulnerability in system.run safe-bin allowlist validation that allows shell expansion to modify command interpretation on POSIX nodes. Authenticated operators can exploit shell metacharacters in approved commands to read unintended node-local f...

Vendor: OpenClaw
Product: OpenClaw
Published: Jun 12, 2026
Source: NVD
CVE-2026-53829 HIGH - 8.0

OpenClaw before 2026.5.18 contains an approval display truncation vulnerability allowing authenticated users to hide command suffixes from approvers. Attackers can submit oversized exec commands with benign prefixes and malicious suffixes to execute unauthorized operations after approval.

Vendor: OpenClaw
Product: OpenClaw
Published: Jun 12, 2026
Source: NVD
CVE-2026-53828 HIGH - 8.8

OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in native command handling that allows authenticated senders to execute owner-only commands without proper policy enforcement. Attackers can trigger native command handling to bypass the configured owner-command access control, ...

Vendor: OpenClaw
Product: OpenClaw
Published: Jun 12, 2026
Source: NVD
CVE-2026-53823 HIGH - 8.1

OpenClaw before 2026.5.3 contains a privilege escalation vulnerability in the allowFrom feature that binds to mutable Slack display names. Attackers with Slack account access can change display name metadata to match policy entries, potentially gaining unauthorized agent access intended for other id...

Vendor: OpenClaw
Product: OpenClaw
Published: Jun 12, 2026
Source: NVD
CVE-2026-53822 HIGH - 8.8

OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between approval and execution. Attackers can rebuild command arguments after allowlist approval to execute unapproved command shapes, potentially bypassing security controls.

Vendor: OpenClaw
Product: OpenClaw
Published: Jun 12, 2026
Source: NVD
CVE-2026-53821 HIGH - 8.8

OpenClaw before 2026.5.18 accepts WebSocket client-declared operator scopes before binding to server-approved pairing or trusted-proxy authorization baseline. Unpaired or restricted trusted-proxy Control UI clients can obtain cached operator.admin authority on live WebSocket connections to execute a...

Vendor: OpenClaw
Product: OpenClaw
Published: Jun 12, 2026
Source: NVD
CVE-2026-53608 HIGH - 8.7

ApostropheCMS is an open-source Node.js content management system. Versions up to and including 1.4.2 of the `@apostrophecms/seo` package injects the Google Analytics Tracking ID (`seoGoogleTrackingId`) and Google Tag Manager ID (`seoGoogleTagManager`) directly into `<script>` tag bodies using...

Vendor: apostrophecms
Product: @apostrophecms/seo
Published: Jun 12, 2026
Source: NVD
CVE-2026-41158 HIGH - 7.8

Software installed and run as a non-privileged user may conduct GPU system calls to write to arbitrary freed physical pages. Physical memory allocated and freed, without the deferred free mechanism can lead to those resources being used for read/write by the GPU after the kernel module has freed ...

Vendor: Imagination Technologies
Product: Graphics DDK
Published: Jun 12, 2026
Source: NVD
CVE-2026-34195 HIGH - 8.8

Software installed and run as a non-privileged user may conduct intentional GPU sparse memory API calls to cause out of bounds write in the kernel. The product incorrectly indexes internal state when performing sparse allocation remapping.

Vendor: Imagination Technologies
Product: Graphics DDK
Published: Jun 12, 2026
Source: NVD
CVE-2025-7017 HIGH - 7.8

Heap buffer out-of-bounds read vulnerability in Avira Antivirus engine when scanning a malformed Windows MSI file may allow Local Execution of Code or Denial-of-Service of the antivirus engine process. This issue affects Avira Antivirus on Windows, macOS, and Linux for engine builds before 8.3.70.5...

Published: Jun 12, 2026
Source: NVD