CVE Vulnerability Database
Search and browse 394,832 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-53855 | HIGH | 8.1 | 0.3% | Jun 16, 2026 | OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing authenticated operators to weaken strict ... |
| CVE-2026-53854 | MEDIUM | 6.5 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.4.25 contains a privilege escalation vulnerability in internal and webchat command authentication t... |
| CVE-2026-53853 | HIGH | 8.3 | 0.3% | Jun 16, 2026 | OpenClaw before 2026.5.12 contains an argument pattern validation bypass in the exec allowlist that allows attackers to ... |
| CVE-2026-53852 | MEDIUM | 5.4 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.4.25 contains a scope containment bypass vulnerability in device re-pairing that allows authenticat... |
| CVE-2026-53851 | MEDIUM | 6.3 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.5.12 contains a notification bypass vulnerability allowing Slack reaction events to enter the agent... |
| CVE-2026-53850 | MEDIUM | 6.8 | 0.1% | Jun 16, 2026 | OpenClaw before 2026.4.25 contains a control scope enforcement bypass vulnerability in the focus command that allows aut... |
| CVE-2026-53849 | HIGH | 8.6 | 0.3% | Jun 16, 2026 | OpenClaw before 2026.5.7 contains a privilege escalation vulnerability where the allowFrom feature improperly validates ... |
| CVE-2026-53848 | MEDIUM | 4.3 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.5.26 contains an exec allowlist bypass vulnerability allowing authenticated operators to execute wr... |
| CVE-2026-53847 | MEDIUM | 5.4 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.5.6 contains a privilege escalation vulnerability in the Active Memory write scope that allows Gate... |
| CVE-2026-53846 | HIGH | 7.1 | 0.1% | Jun 16, 2026 | OpenClaw before 2026.4.29 contains a path traversal vulnerability in the install helper that allows workspace .env files... |
| CVE-2026-53845 | MEDIUM | 4.3 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.5.6 contains a hook bypass vulnerability where skill commands routed through the affected dispatch ... |
| CVE-2026-53844 | MEDIUM | 6.5 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.4.29 contains a session visibility check bypass vulnerability in shared memory search that allows a... |
| CVE-2026-53843 | HIGH | 8.8 | 0.3% | Jun 16, 2026 | OpenClaw before 2026.5.26 contains an authorization bypass vulnerability where a surviving pairing-scoped device session... |
| CVE-2026-53842 | HIGH | 7.1 | 0.1% | Jun 16, 2026 | OpenClaw before 2026.5.2 contains an environment variable injection vulnerability allowing workspace .env files to influ... |
| CVE-2026-53841 | MEDIUM | 6.1 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.5.12 contains a cross-site scripting vulnerability in exported session HTML that preserves unsafe j... |
| CVE-2026-53840 | HIGH | 7.1 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.5.12 contains an information disclosure vulnerability in streamable-http MCP servers that forwards ... |
| CVE-2026-50656 | HIGH | 7 | 10.7% | Jun 16, 2026 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicl... |
| CVE-2026-4367 | MEDIUM | 5.5 | 0.1% | Jun 16, 2026 | A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `x... |
| CVE-2026-48775 | MEDIUM | 6.8 | 0.2% | Jun 16, 2026 | LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, ... |
| CVE-2026-47964 | HIGH | 7.8 | 0.2% | Jun 16, 2026 | DNG SDK versions 1.7.1 2536 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in ... |
| CVE-2026-47963 | MEDIUM | 5.5 | 0.2% | Jun 16, 2026 | DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosur... |
| CVE-2026-47934 | MEDIUM | 5.5 | 0.2% | Jun 16, 2026 | DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosur... |
| CVE-2026-47927 | MEDIUM | 5.5 | 0.2% | Jun 16, 2026 | DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosur... |
| CVE-2026-47749 | HIGH | 7.8 | 0.2% | Jun 16, 2026 | stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Ima... |
| CVE-2026-47748 | MEDIUM | 5.5 | 0.2% | Jun 16, 2026 | stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Ima... |
