VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,787 CVE recordsPage 662 of 1320 · EPSS data 2026.08.13
ReviewHigh
CVE-2026-53833

OpenClaw OpenClaw, openclaw

OpenClaw before 2026.4.29 contains an authorization bypass vulnerability in the QQBot streaming command that allows authenticated senders to mutate configuration without explicit allowFrom restrictions. Attackers can modify QQBot streaming configuration outside intended admin policy by reaching the affected command without non-wildcard allowlist entry requirements.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-53832

OpenClaw OpenClaw, openclaw

OpenClaw before 2026.5.18 contains an identity header validation vulnerability allowing local same-host callers to forge trusted-proxy identity headers. Attackers with access to the proxy-facing Gateway port can supply forged identity headers to assume operator identity and potentially escalate privileges.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-53831

OpenClaw OpenClaw, openclaw

OpenClaw before 2026.5.18 contains a policy enforcement vulnerability in system.run safe-bin allowlist validation that allows shell expansion to modify command interpretation on POSIX nodes. Authenticated operators can exploit shell metacharacters in approved commands to read unintended node-local files and expose sensitive configuration data.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-53829

OpenClaw OpenClaw, openclaw

OpenClaw before 2026.5.18 contains an approval display truncation vulnerability allowing authenticated users to hide command suffixes from approvers. Attackers can submit oversized exec commands with benign prefixes and malicious suffixes to execute unauthorized operations after approval.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-53828

OpenClaw OpenClaw, openclaw

OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in native command handling that allows authenticated senders to execute owner-only commands without proper policy enforcement. Attackers can trigger native command handling to bypass the configured owner-command access control, potentially executing privileged commands from unauthorized users.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-53825

OpenClaw OpenClaw, openclaw

OpenClaw before 2026.4.7 contains an arbitrary file read vulnerability in the memory-wiki ingest feature that allows authenticated Gateway operators with operator.write scope to read local files outside intended ingest sources. Attackers with operator.write access can specify arbitrary local file paths to import file content into wiki memory, bypassing access restrictions.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-53823

OpenClaw OpenClaw, openclaw

OpenClaw before 2026.5.3 contains a privilege escalation vulnerability in the allowFrom feature that binds to mutable Slack display names. Attackers with Slack account access can change display name metadata to match policy entries, potentially gaining unauthorized agent access intended for other identities.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-53822

OpenClaw OpenClaw, openclaw

OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between approval and execution. Attackers can rebuild command arguments after allowlist approval to execute unapproved command shapes, potentially bypassing security controls.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-53821

OpenClaw OpenClaw, openclaw

OpenClaw before 2026.5.18 accepts WebSocket client-declared operator scopes before binding to server-approved pairing or trusted-proxy authorization baseline. Unpaired or restricted trusted-proxy Control UI clients can obtain cached operator.admin authority on live WebSocket connections to execute admin-gated Gateway RPCs.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-44990

apostrophecms sanitize-html, multicluster engine for Kubernetes 2.1, multicluster engine for Kubernetes 2.6

ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. Under the default configuration, versions of `sanitize-html` prior to 2.17.4 can turn attacker-controlled content inside a disallowed `xmp` element into live HTML or JavaScript. This is a sanitizer bypass in the default `disallowedTagsMode: 'discard'` path and can lead to stored XSS in applications that render sanitized output back to users. Version 2.17.4 patches the issue.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-53407

Zoom Communications Zoom Workplace, workplace

Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-12143

form-data form-data, Cryostat 4 on RHEL 9, Red Hat Data Grid 8.6.2

form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header without escaping carriage return (CR), line feed (LF), or double-quote (") characters. An application that passes attacker-controlled data as a field name or filename (for example, an API gateway that turns JSON object keys into multipart field names) allows the attacker to terminate the header line and inject additional headers, or to smuggle entire additional...

The CVSS severity warrants an early asset and exposure review.
CISA KEVCritical
CVE-2026-48558

SimpleHelp SimpleHelp, simplehelp

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication. No user interaction is required.

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.
ReviewHigh
CVE-2026-48165

MariaDB server, Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux 7

MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, a high-privileged MariaDB user could've used wsrep_sst_receive_address or wsrep_sst_donor global system variables to execute shell commands as the uid of the mariadbd process on the galera joiner node. This issue has been patched in versions 10.6.27, 10.11.18, 11.4.12, 11.8.8, and 12.3.2.

The CVSS severity warrants an early asset and exposure review.