Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

3,163 CVEs

CVEs (3,163, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 26–50 of 3,163 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-62218 HIGH Patched 8.8 2026-07-17 OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature that allows lower-trust callers to bypass role-manageme…
CVE-2026-62219 HIGH Patched 7.1 2026-07-17 OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds validation. A lower-trust caller or configured input path can…
CVE-2026-62220 MEDIUM Patched 5.3 2026-07-17 OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass non-browser rate limits on WebSocket authentication attempts. When the aff…
CVE-2026-62221 MEDIUM Patched 5.4 2026-07-17 OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature. When the affected feature is enabled and reachable…
CVE-2026-62222 HIGH Patched 7.8 2026-07-17 OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of untrusted workspace plugins. Attackers with lower-trust caller access or co…
CVE-2026-62223 HIGH Patched 8.8 2026-07-17 OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in the device-pair approval feature that allows lower-trust callers to execute actions beyond their …
CVE-2026-62224 MEDIUM Patched 5.4 2026-07-17 OpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the allowFrom feature binds to mutable display names. Attackers with lower-trust acce…
CVE-2026-62225 MEDIUM Patched 5.4 2026-07-17 OpenClaw versions before 2026.5.18 contain an authorization bypass vulnerability in skill command dispatch that allows lower-trust callers to execute or persist actions bey…
CVE-2026-62226 HIGH Patched 8.5 2026-07-17 OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fails to properly validate current-tab URL checks. Attackers…
CVE-2026-62227 HIGH Patched 7.7 2026-07-17 OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulnerability in browser snapshot routes that fail to validate post-navigation destinations. Attac…
CVE-2026-62228 HIGH Patched 8.8 2026-07-17 OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust callers to execute actions beyond their intended autho…
CVE-2026-62229 HIGH Patched 8.8 2026-07-17 OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in exec allowlist glob matching that allows lower-trust callers to execute actions beyond intended a…
CVE-2026-62230 HIGH Patched 7.5 2026-07-17 Grav before 2.0.4 ships a default .htaccess (and reference webserver-configs/htaccess.txt) whose rules blocking access to sensitive file types (.yaml, .php, .json, etc.) la…
CVE-2026-62231 HIGH Patched 8.1 2026-07-17 The Grav API plugin (getgrav/grav-plugin-api) before 1.0.6 contains an authorization bypass: API keys can be created with a restricted scopes array, but the ApiKeyAuthentic…
CVE-2026-62232 HIGH Patched 7.4 2026-07-17 Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the regenerate2FASecret task checks only user existence, not authoriza…
CVE-2026-62233 HIGH Patched 8.8 2026-07-17 grav-plugin-api before 1.0.6 fails to validate super-admin status in createApiKey, generate2fa, and disable2fa endpoints, allowing non-super api.users.write managers to esc…
CVE-2026-62234 HIGH Patched 8.1 2026-07-17 Grav before 2.0.4 fails to restrict cURL protocols in webhook dispatch, allowing authenticated users with api.webhooks.write permission to create webhooks with file://, dic…
CVE-2026-62235 MEDIUM 6.3 2026-07-17 Grav Flex-Objects before version 1.4.3 contains a broken access control vulnerability in the admin-next REST API that allows authenticated users with only api.access permis…
CVE-2026-62236 MEDIUM Patched 5.4 2026-07-17 grav-plugin-login before 3.8.11 contains a cross-site request forgery (CSRF) vulnerability in the login.regenerate2FASecret frontend task, which regenerates and persists a …
CVE-2026-62237 MEDIUM Patched 6.5 2026-07-17 Grav before 2.0.4 contains a regular expression denial of service (ReDoS) vulnerability in the regex_replace filter and function, which are allowlisted in the Twig content …
CVE-2026-62238 NONE Patched — 2026-07-17 OpenRemote before 1.26.0 contain an authenticated SQL injection vulnerability in the datapoint crosstab export endpoint that constructs PostgreSQL queries by concatenating …
CVE-2026-62241 CRITICAL Patched 9.1 2026-07-17 clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as the default in .env.exam…
CVE-2026-62386 HIGH Patched 7.5 2026-07-17 The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens through the ?token= URL query parameter on every API route (JwtAuthenticator::ext…
CVE-2026-62387 HIGH Patched 7.1 2026-07-17 The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 shipped Access-Control-Allow-Origin: * as its default CORS configuration on all responses, including authen…
CVE-2026-11324 MEDIUM 6.1 2026-07-17 The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'redirect-url' parameter in…