Search
30,126 CVEs
CVEs (30,126, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 426–450 of 30,126 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-45802 | NONE | Patched | — | 2026-06-11 | FPDI is a collection of PHP classes that facilitate reading pages from existing PDF documents and using them as templates in FPDF. Prior to version 2.6.7, an attacker can u… |
| CVE-2026-46489 | HIGH | Patched | 8.1 | 2026-06-11 | SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, the company logo upload feature accepts any file type without validation. An authenticated admin… |
| CVE-2026-46622 | HIGH | Patched | 8.1 | 2026-06-11 | SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authenticate all REST API requests are stored as plaintext strings in the api… |
| CVE-2026-49949 | MEDIUM | Patched | 5.3 | 2026-06-11 | CodexBar before 0.33.0 contains a credential forwarding vulnerability that allows network-adjacent attackers to intercept sensitive credentials by issuing cross-origin or H… |
| CVE-2026-49973 | CRITICAL | 9.4 | 2026-06-11 | Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remote attackers to hijack initial setup by submitting th… | |
| CVE-2026-53781 | MEDIUM | Patched | 4.3 | 2026-06-11 | Summarize before 0.17.0 contains a resource exhaustion vulnerability that allows remote attackers to cause disk exhaustion by serving media responses that bypass the enforc… |
| CVE-2026-53782 | HIGH | Patched | 7.4 | 2026-06-11 | Summarize before 0.17.0 contains a server-side request forgery vulnerability that allows attackers who control a podcast RSS feed to direct the host to fetch transcript con… |
| CVE-2026-41005 | CRITICAL | 9.0 | 2026-06-11 | Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signatures from the Identity Provider (authenticity) … | |
| CVE-2026-50005 | HIGH | 7.7 | 2026-06-11 | Brickcom cameras ship with default credentials that allows any unauthenticated remote attacker to silently access camera feeds. | |
| CVE-2026-50245 | HIGH | 7.7 | 2026-06-11 | Brickcom cameras allow unauthenticated access to live snapshot images via the /ONVIF endpoint and no authentication is required to retrieve still images from the camera feed. | |
| CVE-2026-53806 | HIGH | Patched | 8.8 | 2026-06-11 | OpenClaw before 2026.5.12 contains a shell option parsing vulnerability that allows combined POSIX shell flags to bypass exec revalidation checks. Attackers can exploit thi… |
| CVE-2026-53807 | HIGH | Patched | 8.8 | 2026-06-11 | OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that allows authenticated users to skip commands.allowFrom validat… |
| CVE-2026-53808 | MEDIUM | Patched | 6.5 | 2026-06-11 | OpenClaw before 2026.5.6 contains an approval policy bypass vulnerability in the Skill Workshop apply flow that allows agent tool calls to set apply: true despite approvalP… |
| CVE-2026-53809 | LOW | Patched | 3.8 | 2026-06-11 | OpenClaw before 2026.4.25 contains a policy bypass vulnerability in embedded runner policy that allows requests using provider aliases to compare against aliases instead of… |
| CVE-2026-53810 | HIGH | Patched | 8.8 | 2026-06-11 | OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata can redirect loading toward unscanned package payloads. Attac… |
| CVE-2026-53811 | HIGH | Patched | 8.8 | 2026-06-11 | OpenClaw before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom feature that allows authenticated accounts to match policy entries through mu… |
| CVE-2026-53812 | HIGH | Patched | 7.7 | 2026-06-11 | OpenClaw before 2026.5.18 contains a server-side request forgery vulnerability in browser control that allows authenticated users to bypass private-network navigation check… |
| CVE-2026-53813 | HIGH | Patched | 7.8 | 2026-06-11 | OpenClaw before 2026.4.25 contains a path traversal vulnerability in memory-core artifact loading where workspace state influences local package root resolution. Attackers … |
| CVE-2026-53814 | HIGH | Patched | 8.3 | 2026-06-11 | OpenClaw before 2026.5.20 contains a privilege escalation vulnerability where hook-triggered agent runs incorrectly receive owner-scoped MCP loopback authority instead of h… |
| CVE-2026-53815 | MEDIUM | Patched | 6.5 | 2026-06-11 | OpenClaw before 2026.5.19 contains an authorization bypass vulnerability in message read actions that skips channel allowlist checks. Lower-trust callers can request messag… |
| CVE-2026-53816 | HIGH | Patched | 7.2 | 2026-06-11 | OpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event handling that allows paired nodes to forge exec lifecycle events withou… |
| CVE-2026-53817 | HIGH | Patched | 8.8 | 2026-06-11 | OpenClaw before 2026.5.22 contains a locality validation vulnerability in Control UI pairing that allows attackers with network access to spoof locality information and obt… |
| CVE-2026-53818 | MEDIUM | Patched | 6.6 | 2026-06-11 | OpenClaw before 2026.4.24 contains an authorization bypass vulnerability in the MCP loopback feature that allows non-owner callers to skip owner-only tool policies and befo… |
| CVE-2026-53819 | HIGH | Patched | 8.8 | 2026-06-11 | OpenClaw before 2026.5.27 contains an arbitrary code execution vulnerability in skill install flows where workspace .env files can override the Homebrew executable selectio… |
| CVE-2026-12007 | HIGH | Patched | 8.8 | 2026-06-11 | Use after free in Core in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security s… |