CVE Vulnerability Database

Search and browse 389,943 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-62220MEDIUM6.3OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass non-browser rate limit...
CVE-2026-62219HIGH7.1OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds validatio...
CVE-2026-62218HIGH8.8OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature tha...
CVE-2026-62217HIGH8.8OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. When the f...
CVE-2026-62216MEDIUM5OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media upload feature. A lower-trust caller or c...
CVE-2026-62215HIGH8OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability in HTTP Canvas responses that allows lo...
CVE-2026-62214MEDIUM6.5OpenClaw versions before 2026.5.28 Bot Framework contains an improper input validation vulnerability that allows lower-t...
CVE-2026-62213MEDIUM6.5OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower...
CVE-2026-62212HIGH7.1OpenClaw before 2026.5.28 contains a race condition in the MS Teams safeFetch DNS rebinding check. When the affected fea...
CVE-2026-62211MEDIUM5OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature t...
CVE-2026-62210MEDIUM6.5OpenClaw versions before 2026.6.1 contain a denial of service vulnerability where remote media URLs can trigger slow-rea...
CVE-2026-62209HIGH8.1OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mode dispatch...
CVE-2026-62208MEDIUM6.5OpenClaw before 2026.6.5 could forward Authorization headers during MCP SSE redirects. When the affected feature is enab...
CVE-2026-62207HIGH8.8OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability that allows lower-trust callers to reac...
CVE-2026-62206HIGH7.1OpenClaw versions before 2026.6.9 contain a missing authorization vulnerability in Discord moderation actions. In affect...
CVE-2026-62205HIGH7.1OpenClaw versions 2026.4.12-beta.1 before 2026.6.6 contain a missing-authorization vulnerability in the MS Teams message...
CVE-2026-62203HIGH8.8OpenClaw versions before 2026.6.6 contain an environment variable filtering vulnerability in host exec that fails to pro...
CVE-2026-62202HIGH8.8OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that allow...
CVE-2026-62201HIGH7.7OpenClaw versions before 2026.6.6 contain a network policy bypass vulnerability in the sandbox exec-server that allows l...
CVE-2026-44251MEDIUM6.5Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.0.0 and abov...
CVE-2026-40106HIGH7.8Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.6.0 and above p...
CVE-2026-2594MEDIUM6.4The Smart Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi...
CVE-2026-14956CRITICAL9.8The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6...
CVE-2026-54340HIGH7.5h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 9265bdd, there is an HTTP/2 state am...
CVE-2026-39359HIGH7.5Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.0.0 through ...