CVE Vulnerability Database

Search and browse 389,978 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-62193MEDIUM6.5OpenClaw versions 2026.6.5 before 2026.6.9 contain a vulnerability in the plugin install wrappers that could skip the in...
CVE-2026-62192HIGH8.1OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in Discord guild actions that a...
CVE-2026-62191HIGH7.1OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message mutation handling th...
CVE-2026-62190HIGH8.8OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that allows lower-t...
CVE-2026-62189HIGH7.6OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows lower...
CVE-2026-62188HIGH8.6OpenClaw @openclaw/feishu versions 2026.6.6 and earlier contain an incorrect authorization vulnerability in which the Fe...
CVE-2026-62187HIGH8.6OpenClaw Feishu tools (npm package @openclaw/feishu) in versions <= 2026.6.6 could ignore per-account disablement. A low...
CVE-2026-62186HIGH7.6OpenClaw versions before 2026.6.8 contain an authorization bypass vulnerability in OpenAI-compatible HTTP model override...
CVE-2026-62185HIGH8.6Argo CD Helm Chart before 10.0.0 fails to install network policies by default, allowing any pod on a cluster to access r...
CVE-2026-62184HIGH8.7luci-app-banip contains a log parsing vulnerability where the awk-based parser extracts the first IPv4 address from log ...
CVE-2026-61458HIGH8.7PasswordPusher before 2.9.2 contains a brute-force vulnerability in the POST /p/:token/access endpoint that lacks route-...
CVE-2026-59801CRITICAL9.89Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact...
CVE-2026-58500HIGH8.2MCP Appium is an MCP server that provides AI assistants with tools to automate mobile app testing on Android and iOS. In...
CVE-2026-58488MEDIUM6.9HedgeDoc is an open source, real-time, collaborative, markdown notes application. Versions prior to 1.11.0 allowed attac...
CVE-2026-58487MEDIUM5.1HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to version 1.11.0, due to unsafe...
CVE-2026-58411HIGH7ChurchCRM is an open-source church management system. Prior to version 7.4.0, Cross-Site Scripting (XSS) vulnerabilities...
CVE-2026-56877MEDIUM6.3The SCORM lab launch endpoint in Skillable (scorm.skillable.com) through 2026-07-13 does not validate the client-supplie...
CVE-2026-52533CRITICAL9.8An issue in D-Link DIR-1253 v.1.0.1.250923.142435 allows an attacker to escalate privileges via the etc/shadow component...
CVE-2026-51821CRITICAL9.8SQL Injection vulnerability in Shenzhou Shihan Video Conference System v.1.0 allows a remote attacker to execute arbitra...
CVE-2026-51541CRITICAL9.1OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message parsing when handling malformed explicit re...
CVE-2026-51540CRITICAL9.8OpENer 2.3.0 (master branch up to commit 76b95cf) is vulnerable to a severe memory corruption issue caused by an integer...
CVE-2026-51539HIGH7.5A Denial of Service (DoS) vulnerability exists in the receive loop of libmodbus 3.1.12 when running on Windows. The issu...
CVE-2026-51538CRITICAL9.1EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability in its handling of en...
CVE-2026-51537CRITICAL9.1EIPStackGroup OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in Connection Manager handling of ForwardOpe...
CVE-2026-51536CRITICAL9.1In OpENer 2.3.0 (commit 76b95cf) when parsing incoming CIP (Common Industrial Protocol) network packets, the length para...