Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

1,211 CVEs · High severity

CVEs (1,211, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 1,211 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-34150 HIGH Patched 7.5 2026-07-17 Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 1.0.0 and above, prior to 4.14.5, a heap buffer overflow in wazuh-…
CVE-2026-39359 HIGH Patched 7.5 2026-07-17 Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.0.0 through 4.10.3 and 4.11.0 through 4.14.4, a logic flaw affec…
CVE-2026-54340 HIGH 7.5 2026-07-17 h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 9265bdd, there is an HTTP/2 state amplification issue that combines HPACK decompression …
CVE-2026-62201 HIGH Patched 7.7 2026-07-17 OpenClaw versions before 2026.6.6 contain a network policy bypass vulnerability in the sandbox exec-server that allows lower-trust callers to reach internal network destina…
CVE-2026-62202 HIGH Patched 8.8 2026-07-17 OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that allows lower-trust callers to regain denied execution too…
CVE-2026-62203 HIGH Patched 8.8 2026-07-17 OpenClaw versions before 2026.6.6 contain an environment variable filtering vulnerability in host exec that fails to properly sanitize rustup startup variables. Attackers w…
CVE-2026-62205 HIGH Patched 7.1 2026-07-17 OpenClaw versions 2026.4.12-beta.1 before 2026.6.6 contain a missing-authorization vulnerability in the MS Teams message actions feature. When the affected feature is enabl…
CVE-2026-62206 HIGH Patched 7.1 2026-07-17 OpenClaw versions before 2026.6.9 contain a missing authorization vulnerability in Discord moderation actions. In affected versions, a lower-trust caller or configured inpu…
CVE-2026-62207 HIGH Patched 8.8 2026-07-17 OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability that allows lower-trust callers to reach admin-scoped tools. Attackers can perform actions …
CVE-2026-62209 HIGH Patched 8.1 2026-07-17 OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mode dispatch feature, which could ignore the toolsAllow policy c…
CVE-2026-62212 HIGH Patched 7.1 2026-07-17 OpenClaw before 2026.5.28 contains a race condition in the MS Teams safeFetch DNS rebinding check. When the affected feature is enabled and reachable, a lower-trust caller …
CVE-2026-62215 HIGH Patched 8.0 2026-07-17 OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability in HTTP Canvas responses that allows lower-trust callers to forge trusted A2UI actions. Att…
CVE-2026-62217 HIGH Patched 8.8 2026-07-17 OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. When the feature is enabled and reachable, a lower-trust calle…
CVE-2026-62218 HIGH Patched 8.8 2026-07-17 OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature that allows lower-trust callers to bypass role-manageme…
CVE-2026-62219 HIGH Patched 7.1 2026-07-17 OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds validation. A lower-trust caller or configured input path can…
CVE-2026-62222 HIGH Patched 7.8 2026-07-17 OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of untrusted workspace plugins. Attackers with lower-trust caller access or co…
CVE-2026-62223 HIGH Patched 8.8 2026-07-17 OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in the device-pair approval feature that allows lower-trust callers to execute actions beyond their …
CVE-2026-62226 HIGH Patched 8.5 2026-07-17 OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fails to properly validate current-tab URL checks. Attackers…
CVE-2026-62227 HIGH Patched 7.7 2026-07-17 OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulnerability in browser snapshot routes that fail to validate post-navigation destinations. Attac…
CVE-2026-62228 HIGH Patched 8.8 2026-07-17 OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust callers to execute actions beyond their intended autho…
CVE-2026-62229 HIGH Patched 8.8 2026-07-17 OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in exec allowlist glob matching that allows lower-trust callers to execute actions beyond intended a…
CVE-2026-62230 HIGH Patched 7.5 2026-07-17 Grav before 2.0.4 ships a default .htaccess (and reference webserver-configs/htaccess.txt) whose rules blocking access to sensitive file types (.yaml, .php, .json, etc.) la…
CVE-2026-62231 HIGH Patched 8.1 2026-07-17 The Grav API plugin (getgrav/grav-plugin-api) before 1.0.6 contains an authorization bypass: API keys can be created with a restricted scopes array, but the ApiKeyAuthentic…
CVE-2026-62232 HIGH Patched 7.4 2026-07-17 Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the regenerate2FASecret task checks only user existence, not authoriza…
CVE-2026-62233 HIGH Patched 8.8 2026-07-17 grav-plugin-api before 1.0.6 fails to validate super-admin status in createApiKey, generate2fa, and disable2fa endpoints, allowing non-super api.users.write managers to esc…