CVE Vulnerability Database

Search and browse 395,260 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-12011HIGH8.3Use after free in WebMIDI in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromi...
CVE-2026-12010HIGH8.3Heap buffer overflow in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compro...
CVE-2026-12009HIGH8.3Insufficient validation of untrusted input in Accessibility in Google Chrome on Mac prior to 149.0.7827.115 allowed a re...
CVE-2026-12008HIGH8.3Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromi...
CVE-2026-12007HIGH8.8Use after free in Core in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to execute arbitrar...
CVE-2026-53819HIGH7.8OpenClaw before 2026.5.27 contains an arbitrary code execution vulnerability in skill install flows where workspace .env...
CVE-2026-53818MEDIUM6.9OpenClaw before 2026.4.24 contains an authorization bypass vulnerability in the MCP loopback feature that allows non-own...
CVE-2026-53817HIGH8.8OpenClaw before 2026.5.22 contains a locality validation vulnerability in Control UI pairing that allows attackers with ...
CVE-2026-53816HIGH8.6OpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event handling that allow...
CVE-2026-53815HIGH7.1OpenClaw before 2026.5.19 contains an authorization bypass vulnerability in message read actions that skips channel allo...
CVE-2026-53814HIGH8.7OpenClaw before 2026.5.20 contains a privilege escalation vulnerability where hook-triggered agent runs incorrectly rece...
CVE-2026-53813HIGH7.8OpenClaw before 2026.4.25 contains a path traversal vulnerability in memory-core artifact loading where workspace state ...
CVE-2026-53812HIGH7.7OpenClaw before 2026.5.18 contains a server-side request forgery vulnerability in browser control that allows authentica...
CVE-2026-53811HIGH8.8OpenClaw before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom feature that allows authe...
CVE-2026-53810HIGH8.8OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata can redir...
CVE-2026-53809MEDIUM4.8OpenClaw before 2026.4.25 contains a policy bypass vulnerability in embedded runner policy that allows requests using pr...
CVE-2026-53808MEDIUM6.5OpenClaw before 2026.5.6 contains an approval policy bypass vulnerability in the Skill Workshop apply flow that allows a...
CVE-2026-53807HIGH8.8OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that allows au...
CVE-2026-53806HIGH8.8OpenClaw before 2026.5.12 contains a shell option parsing vulnerability that allows combined POSIX shell flags to bypass...
CVE-2026-50245HIGH8.3Brickcom cameras allow unauthenticated access to live snapshot images via the /ONVIF endpoint and no authentication is r...
CVE-2026-50005HIGH8.3Brickcom cameras ship with default credentials that allows any unauthenticated remote attacker to silently access camera...
CVE-2026-41005CRITICAL9Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML s...
CVE-2026-53782HIGH7.4Summarize before 0.17.0 contains a server-side request forgery vulnerability that allows attackers who control a podcast...
CVE-2026-53781MEDIUM5.3Summarize before 0.17.0 contains a resource exhaustion vulnerability that allows remote attackers to cause disk exhausti...
CVE-2026-49973CRITICAL9.4Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remot...