CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-62209
8.1 HIGH

OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mode dispatch feature, which could ignore the toolsAllow policy check. When the affected …

Jul 17, 2026
CVE-2026-62208
6.5 MEDIUM

OpenClaw before 2026.6.5 could forward Authorization headers during MCP SSE redirects. When the affected feature is enabled and reachable, a lower-trust caller or configured input …

Jul 17, 2026
CVE-2026-62207
8.8 HIGH

OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability that allows lower-trust callers to reach admin-scoped tools. Attackers can perform actions requiring stronger authorization by …

Jul 17, 2026
CVE-2026-62206
7.1 HIGH

OpenClaw versions before 2026.6.9 contain a missing authorization vulnerability in Discord moderation actions. In affected versions, a lower-trust caller or configured input path could perform …

Jul 17, 2026
CVE-2026-62205
7.1 HIGH

OpenClaw versions 2026.4.12-beta.1 before 2026.6.6 contain a missing-authorization vulnerability in the MS Teams message actions feature. When the affected feature is enabled and reachable, a …

Jul 17, 2026
CVE-2026-62203
8.8 HIGH

OpenClaw versions before 2026.6.6 contain an environment variable filtering vulnerability in host exec that fails to properly sanitize rustup startup variables. Attackers with lower-trust caller …

Jul 17, 2026
CVE-2026-62202
8.8 HIGH

OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that allows lower-trust callers to regain denied execution tools. Attackers can …

Jul 17, 2026
CVE-2026-62201
7.7 HIGH

OpenClaw versions before 2026.6.6 contain a network policy bypass vulnerability in the sandbox exec-server that allows lower-trust callers to reach internal network destinations blocked by …

Jul 17, 2026
CVE-2026-44251
6.5 MEDIUM

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.0.0 and above, prior to 4.14.5, a size_t …

Jul 17, 2026
CVE-2026-40106
4.7 MEDIUM

Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.6.0 and above prior to 4.14.5 contain a heap-based …

Jul 17, 2026
CVE-2026-2594
6.4 MEDIUM

The Smart Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.7. This is due to insufficient …

Jul 17, 2026
CVE-2026-14956
9.8 CRITICAL

The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper validation of …

Jul 17, 2026
CVE-2026-54340
7.5 HIGH

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 9265bdd, there is an HTTP/2 state amplification issue that combines …

Jul 17, 2026
CVE-2026-39359
7.5 HIGH

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.0.0 through 4.10.3 and 4.11.0 through 4.14.4, a …

Jul 17, 2026
CVE-2026-34150
7.5 HIGH

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 1.0.0 and above, prior to 4.14.5, a heap …

Jul 17, 2026
CVE-2026-33754
6.5 MEDIUM

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.9.0 and above, prior to 4.14.5, a remote …

Jul 17, 2026
CVE-2026-33434
4.3 MEDIUM

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.6.0 and above, prior to 4.14.5, a logic …

Jul 17, 2026
CVE-2026-44453
7.5 HIGH

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 6b5370d, h2o is vulnerable to a Denial of Service attack …

Jul 16, 2026
CVE-2026-44452
5.9 MEDIUM

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 8dc37cb, when h2o receives a ClientHello message over TLS or …

Jul 16, 2026
CVE-2026-44436
7.5 HIGH

Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b178e6, Quicly is vulnerable to a …

Jul 16, 2026
CVE-2026-44435
7.5 HIGH

Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 937d0e9, an assertion failure is raised …

Jul 16, 2026
CVE-2026-44434
5.3 MEDIUM

Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit dccf5d4, Quicly was vulnerable to stateless …

Jul 16, 2026
CVE-2026-44433
5.3 MEDIUM

Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b178e6, an adversarial peer could send …

Jul 16, 2026
CVE-2026-44182

Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In versions prior to 3.3.0, the server …

Jul 16, 2026
CVE-2026-44181

Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In versions 2.0.0rc2 and above, prior to …

Jul 16, 2026
CVE-2026-43978
8.1 HIGH

wger is a free, open-source workout and fitness manager. In versions prior to 2.6, a gym trainer can escalate their session to any higher-privileged account …

Jul 16, 2026
CVE-2026-43977
7.5 HIGH

wger is a free, open-source workout and fitness manager. In versions prior to 2.6, any authenticated user can read another user's private workout session notes, …

Jul 16, 2026
CVE-2026-15997

Out-of-bounds write vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on ARM allows Overflow Buffers. This vulnerability is associated with program files https://github.Com/bcgit/bc-lts-java/blob/main/native_c/arm/sha/shake.C, …

Jul 16, 2026
CVE-2026-14253

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 16, 2026
CVE-2026-11740

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 16, 2026
CVE-2026-62826
4.6 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Jul 16, 2026
CVE-2026-59117
7.5 HIGH

Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network.

Jul 16, 2026
CVE-2026-58643
6.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.

Jul 16, 2026
CVE-2026-58598
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.

Jul 16, 2026
CVE-2026-57077
7.7 HIGH

YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len. In the bundled libsyck newline_len and is_newline dereference …

Jul 16, 2026
CVE-2026-57076
7.8 HIGH

YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key in syck_hdlr_add_anchor. In the bundled libsyck …

Jul 16, 2026
CVE-2026-57075
9.1 CRITICAL

YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec. The base64 decoder in the bundled libsyck indexes …

Jul 16, 2026
CVE-2026-53412
9.8 CRITICAL

Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user …

Jul 16, 2026
CVE-2026-53411
7.8 HIGH

A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user …

Jul 16, 2026
CVE-2026-45368

Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the underlying URL methods for the KirbyTags and image blocks components …

Jul 16, 2026
CVE-2026-45334

Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the content-locking feature returned lock information without checking the requesting user's …

Jul 16, 2026
CVE-2026-44180
9.8 CRITICAL

Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. Versions 2.0.0rc1 and above prior to 3.3.0 …

Jul 16, 2026
CVE-2026-44177

Kirby is an open-source content management system. In versions 5.3.0 and above but prior to 5.4.1, Kirby did not correctly validate the provided user ID, …

Jul 16, 2026
CVE-2026-44176

Kirby is an open-source content management system. Versions prior to 4.9.1 and 5.4.1 do not check the `pages.access` permission during page draft rendering. Permissions are …

Jul 16, 2026
CVE-2026-44175

Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, Kirby did not securely sanitize the contents of the list field …

Jul 16, 2026
CVE-2026-44174

Kirby is an open-source content management system. Prior to 4.9.1 and 5.4.1, Kirby did not validate the model attributes that were used in its collection …

Jul 16, 2026
CVE-2026-14782
4.9 MEDIUM

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the Customer Import in all versions up …

Jul 16, 2026
CVE-2026-13713
6.2 MEDIUM

YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stack. In the …

Jul 16, 2026
CVE-2026-61378
5.5 MEDIUM

A divide-by-zero vulnerability in the Productivity Suite allows a local attacker to cause a division by zero leading to a system crash.

Jul 16, 2026
CVE-2026-60073
5.9 MEDIUM

An out-of-bounds read in the Productivity Suite allows a physical attacker to control the length of data sent to a USB device. This can lead …

Jul 16, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.