Total CVEs

132,202

Critical Severity

2,836

High Severity

10,146

Last 7 Days

1,628
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,901 - 3,920 of 28,607 CVEs
CVE-2026-4892 HIGH - 8.4

A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet.

Published: May 11, 2026
Source: NVD
CVE-2026-4891 MEDIUM - 5.3

A heap-based out-of-bounds read vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.

Published: May 11, 2026
Source: NVD
CVE-2026-4890 HIGH - 7.5

A Denial of Service (DoS) vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.

Published: May 11, 2026
Source: NVD
CVE-2026-45006 HIGH - 8.8

OpenClaw before 2026.4.23 contains an improper access control vulnerability in the gateway tool's config.apply and config.patch operations that allows compromised models to write unsafe configuration changes by bypassing an incomplete denylist protection. Attackers can persist malicious config ...

Vendor: OpenClaw
Product: OpenClaw
Published: May 11, 2026
Source: NVD
CVE-2026-45005 MEDIUM - 6.0

OpenClaw before 2026.4.23 caches resolved webhook route secrets backed by SecretRef values, allowing stale secrets to remain valid after rotation and reload. Attackers with previously valid webhook route secrets can continue authenticating requests and invoking configured webhook task flows until ga...

Vendor: OpenClaw
Product: OpenClaw
Published: May 11, 2026
Source: NVD
CVE-2026-45004 HIGH - 7.8

OpenClaw before 2026.4.23 contains an arbitrary code execution vulnerability in the bundled plugin setup resolver that loads setup-api.js from process.cwd() during provider setup metadata resolution. Attackers can execute arbitrary JavaScript under the current user account by placing a malicious ext...

Vendor: OpenClaw
Product: OpenClaw
Published: May 11, 2026
Source: NVD
CVE-2026-45003 MEDIUM - 5.0

OpenClaw before 2026.4.22 allows workspace dotenv files to override connector endpoint hosts for Matrix, Mattermost, IRC, and Synology connectors. Attackers with workspace access can redirect runtime traffic to malicious endpoints by setting endpoint variables in dotenv files.

Vendor: OpenClaw
Product: OpenClaw
Published: May 11, 2026
Source: NVD
CVE-2026-45002 MEDIUM - 5.3

OpenClaw before 2026.4.20 contains a hook session-key bypass vulnerability that allows attackers to circumvent the hooks.allowRequestSessionKey opt-in restriction. Attackers can render externally influenced session keys through templated hook mappings to bypass webhook routing isolation controls.

Vendor: OpenClaw
Product: OpenClaw
Published: May 11, 2026
Source: NVD
CVE-2026-45001 HIGH - 7.1

OpenClaw before 2026.4.20 contains a guard bypass vulnerability in the agent-facing gateway config.patch and config.apply endpoints that fails to protect operator-trusted settings including sandbox policy, plugin enablement, gateway auth/TLS, hook routing, MCP server configuration, SSRF policy, and ...

Vendor: OpenClaw
Product: OpenClaw
Published: May 11, 2026
Source: NVD
CVE-2026-45000 MEDIUM - 5.0

OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skips strict-mode SSRF policy checks. Attackers can create stored profiles pointing to private-network or metadata endpoints that bypass security policies and are later probed during n...

Vendor: OpenClaw
Product: OpenClaw
Published: May 11, 2026
Source: NVD
CVE-2026-44999 MEDIUM - 5.3

OpenClaw before 2026.4.20 fails to properly preserve untrusted labels for isolated cron awareness events, allowing webhook-triggered cron agent output to be recorded as trusted system events. Attackers can exploit this trust-labeling issue to strengthen prompt-injection attacks by rendering untruste...

Vendor: OpenClaw
Product: OpenClaw
Published: May 11, 2026
Source: NVD
CVE-2026-44998 MEDIUM - 5.4

OpenClaw before 2026.4.20 contains a tool policy bypass vulnerability allowing bundled MCP and LSP tools to circumvent configured tool restrictions. Attackers with local agent access can append restricted tools to the effective tool set after policy filtering, bypassing profile policies, allow/deny ...

Vendor: OpenClaw
Product: OpenClaw
Published: May 11, 2026
Source: NVD
CVE-2026-44997 MEDIUM - 4.3

OpenClaw before 2026.4.22 contains a security envelope constraint bypass vulnerability allowing restricted subagents to spawn ACP child sessions that fail to inherit depth, child-count limits, control scope, or target-agent restrictions. Attackers can exploit this by spawning child sessions that byp...

Vendor: OpenClaw
Product: OpenClaw
Published: May 11, 2026
Source: NVD

OpenClaw before 2026.4.15 contains an arbitrary local file read vulnerability in the webchat audio embedding helper that fails to apply local media root containment checks. Attackers can influence agent or tool-produced ReplyPayload.mediaUrl parameters to resolve absolute local paths or file URLs, r...

Vendor: OpenClaw
Product: OpenClaw
Published: May 11, 2026
Source: NVD
CVE-2026-44995 HIGH - 7.3

OpenClaw before 2026.4.20 contains an improper environment variable validation vulnerability in MCP stdio server configuration that allows attackers to execute arbitrary code. Malicious workspace configurations can pass dangerous startup variables like NODE_OPTIONS, LD_PRELOAD, or BASH_ENV to spawne...

Vendor: OpenClaw
Product: OpenClaw
Published: May 11, 2026
Source: NVD
CVE-2026-44994 MEDIUM - 5.3

OpenClaw before 2026.4.22 contains an authentication bypass vulnerability in the Control UI bootstrap config endpoint that allows unauthenticated attackers to read sensitive configuration fields. Attackers can access the bootstrap config route without a valid Gateway token to expose sensitive bootst...

Vendor: OpenClaw
Product: OpenClaw
Published: May 11, 2026
Source: NVD
CVE-2026-44993 MEDIUM - 5.4

OpenClaw before 2026.4.20 contains a message classification vulnerability in Feishu card-action callbacks that misclassifies direct messages as group conversations. Attackers can bypass dmPolicy enforcement by triggering card-action flows in direct message conversations that should have been blocked...

Vendor: OpenClaw
Product: OpenClaw
Published: May 11, 2026
Source: NVD
CVE-2026-44992 MEDIUM - 5.0

OpenClaw versions 2026.4.5 before 2026.4.20 contain an environment variable injection vulnerability allowing workspace dotenv to override MINIMAX_API_HOST. Attackers can redirect credentialed MiniMax API requests to attacker-controlled origins, exposing the MiniMax API key in Authorization headers.

Vendor: OpenClaw
Product: OpenClaw
Published: May 11, 2026
Source: NVD
CVE-2026-44991 MEDIUM - 4.2

OpenClaw before 2026.4.21 contains an authorization bypass vulnerability in command-auth.ts that allows non-owner senders to execute owner-enforced slash commands when wildcard inbound senders are configured without explicit owner allowFrom settings. Attackers can exploit this by sending commands li...

Vendor: OpenClaw
Product: OpenClaw
Published: May 11, 2026
Source: NVD
CVE-2026-44777 MEDIUM - 5.5

jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two otherwise valid modules include each other.

Vendor: jqlang
Product: jq
Published: May 11, 2026
Source: NVD