CVE Feed

    Dashboard / CVE

    3.1
    Low

    CVE-2026-12032

    Last Modified: 22 Jun 2026

    Inappropriate implementation in Passwords in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

    Published: 11 Jun 2026
    8.3
    High

    CVE-2026-12031

    Last Modified: 22 Jun 2026

    Inappropriate implementation in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 11 Jun 2026
    8.3
    High

    CVE-2026-12030

    Last Modified: 12 Jun 2026

    Out of bounds write in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 11 Jun 2026
    8.3
    High

    CVE-2026-12029

    Last Modified: 12 Jun 2026

    Use after free in Video in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 11 Jun 2026
    8.3
    High

    CVE-2026-12028

    Last Modified: 12 Jun 2026

    Use after free in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 11 Jun 2026
    9.6
    Critical

    CVE-2026-12027

    Last Modified: 13 Jun 2026

    Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 11 Jun 2026
    5.3
    Medium

    CVE-2026-12025

    Last Modified: 12 Jun 2026

    Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

    Published: 11 Jun 2026
    6.5
    Medium

    CVE-2026-12026

    Last Modified: 1 Jul 2026

    Out of bounds read in Video in Google Chrome on ChromeOS prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

    Published: 11 Jun 2026
    6.5
    Medium

    CVE-2026-12024

    Last Modified: 13 Jun 2026

    Insufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7827.115 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

    Published: 11 Jun 2026
    8.3
    High

    CVE-2026-12023

    Last Modified: 12 Jun 2026

    Use after free in GPU in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 11 Jun 2026
    8.3
    High

    CVE-2026-12022

    Last Modified: 13 Jun 2026

    Race in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

    Published: 11 Jun 2026
    8.8
    High

    CVE-2026-12020

    Last Modified: 13 Jun 2026

    Use after free in Autofill in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 11 Jun 2026
    8.3
    High

    CVE-2026-12019

    Last Modified: 13 Jun 2026

    Heap buffer overflow in Codecs in Google Chrome on Linux and ChromeOS prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 11 Jun 2026
    8.8
    High

    CVE-2026-12018

    Last Modified: 12 Jun 2026

    Inappropriate implementation in Mojo in Google Chrome on Windows prior to 149.0.7827.115 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)

    Published: 11 Jun 2026
    3.1
    Low

    CVE-2026-12017

    Last Modified: 13 Jun 2026

    Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

    Published: 11 Jun 2026
    8.3
    High

    CVE-2026-12016

    Last Modified: 13 Jun 2026

    Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 11 Jun 2026
    5.3
    Medium

    CVE-2026-12015

    Last Modified: 13 Jun 2026

    Use after free in Autofill in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

    Published: 11 Jun 2026
    8.3
    High

    CVE-2026-12014

    Last Modified: 13 Jun 2026

    Use after free in Cast in Google Chrome prior to 149.0.7827.115 allowed an attacker on the local network segment to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)

    Published: 11 Jun 2026
    8.8
    High

    CVE-2026-12013

    Last Modified: 16 Jun 2026

    Determined not a vulnerability

    Published: 11 Jun 2026
    8.1
    High

    CVE-2026-12012

    Last Modified: 12 Jun 2026

    Use after free in Network in Google Chrome prior to 149.0.7827.115 allowed an attacker in a privileged network position to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High)

    Published: 11 Jun 2026
    8.3
    High

    CVE-2026-12011

    Last Modified: 12 Jun 2026

    Use after free in WebMIDI in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

    Published: 11 Jun 2026
    8.3
    High

    CVE-2026-12010

    Last Modified: 12 Jun 2026

    Heap buffer overflow in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

    Published: 11 Jun 2026
    8.3
    High

    CVE-2026-12009

    Last Modified: 12 Jun 2026

    Insufficient validation of untrusted input in Accessibility in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

    Published: 11 Jun 2026
    8.3
    High

    CVE-2026-12008

    Last Modified: 12 Jun 2026

    Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

    Published: 11 Jun 2026
    8.8
    High

    CVE-2026-12007

    Last Modified: 19 Jun 2026

    Use after free in Core in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

    Published: 11 Jun 2026
    8.1
    High

    CVE-2026-44249

    Last Modified: 11 Sept 2026

    Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. Versions 4.1.135.Final and 4.2.15.Final patch the issue.

    Published: 11 Jun 2026
    7
    High

    CVE-2026-6250

    Last Modified: 16 Jun 2026

    An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of user-controlled input.  Externally controlled data is interpreted as a format string, which can be used to manipulate stack memory, including control flow data such as return addresses. A remote authenticated attacker may redirect execution flow to existing internal functions, triggering an unauthorized factory reset, leading to loss of configuration, deletion of stored credentials and service disruption.

    Published: 11 Jun 2026
    8.7
    High

    CVE-2026-53819

    Last Modified: 12 Jun 2026

    OpenClaw before 2026.5.27 contains an arbitrary code execution vulnerability in skill install flows where workspace .env files can override the Homebrew executable selection. Attackers with access to trusted operator workspaces can execute unintended Homebrew-compatible executables during skill setup to compromise the system.

    Published: 11 Jun 2026
    6.9
    Medium

    CVE-2026-53818

    Last Modified: 12 Jun 2026

    OpenClaw before 2026.4.24 contains an authorization bypass vulnerability in the MCP loopback feature that allows non-owner callers to skip owner-only tool policies and before-tool-call hooks. Attackers can invoke owner-only behavior through the affected loopback path to execute restricted tools when the feature is enabled and reachable.

    Published: 11 Jun 2026
    8.7
    High

    CVE-2026-53817

    Last Modified: 12 Jun 2026

    OpenClaw before 2026.5.22 contains a locality validation vulnerability in Control UI pairing that allows attackers with network access to spoof locality information and obtain durable admin-capable device tokens. Attackers can exploit insufficient locality-derived trust validation to convert temporary shared access into persistent administrative credentials that survive token rotation.

    Published: 11 Jun 2026
    8.6
    High

    CVE-2026-53816

    Last Modified: 12 Jun 2026

    OpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event handling that allows paired nodes to forge exec lifecycle events without system.run authorization. A malicious or compromised paired node can send crafted node.event messages to the gateway, steering target sessions into exec-event paths that expose capabilities the reduced node surface should not provide.

    Published: 11 Jun 2026
    7.1
    High

    CVE-2026-53815

    Last Modified: 12 Jun 2026

    OpenClaw before 2026.5.19 contains an authorization bypass vulnerability in message read actions that skips channel allowlist checks. Lower-trust callers can request messages from channels not intended for them by exploiting insufficient validation in the affected feature, potentially exposing sensitive channel messages.

    Published: 11 Jun 2026
    8.7
    High

    CVE-2026-53814

    Last Modified: 13 Jun 2026

    OpenClaw before 2026.5.20 contains a privilege escalation vulnerability where hook-triggered agent runs incorrectly receive owner-scoped MCP loopback authority instead of hook-appropriate scope. Attackers with a valid hook token can exploit the /hooks/agent endpoint to cause spawned CLI runtimes to access or invoke owner-only MCP tools, potentially executing privileged actions like persistent cron state modifications.

    Published: 11 Jun 2026
    7.3
    High

    CVE-2026-53813

    Last Modified: 12 Jun 2026

    OpenClaw before 2026.4.25 contains a path traversal vulnerability in memory-core artifact loading where workspace state influences local package root resolution. Attackers with access to affected workspaces can load memory-core artifacts from unintended local locations, potentially executing malicious code or accessing sensitive data.

    Published: 11 Jun 2026
    4.9
    Medium

    CVE-2026-53812

    Last Modified: 12 Jun 2026

    OpenClaw before 2026.5.18 contains a server-side request forgery vulnerability in browser control that allows authenticated users to bypass private-network navigation checks through Playwright act interactions. Attackers can trigger navigation to private-network targets via action-triggered redirects and subsequently read restricted page content using browser evaluation capabilities.

    Published: 11 Jun 2026
    7.7
    High

    CVE-2026-53811

    Last Modified: 16 Jun 2026

    OpenClaw before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom feature that allows authenticated accounts to match policy entries through mutable display name metadata. Attackers with the ability to change display names can receive agent access intended for another Matrix identity, potentially gaining unauthorized permissions depending on operator configuration.

    Published: 11 Jun 2026
    7.7
    High

    CVE-2026-53810

    Last Modified: 12 Jun 2026

    OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata can redirect loading toward unscanned package payloads. Attackers with trusted operator access can manipulate extension metadata to load plugin code outside reviewed package entry points, bypassing security scanning.

    Published: 11 Jun 2026
    4.8
    Medium

    CVE-2026-53809

    Last Modified: 13 Jun 2026

    OpenClaw before 2026.4.25 contains a policy bypass vulnerability in embedded runner policy that allows requests using provider aliases to compare against aliases instead of canonical provider identities. Attackers can exploit this confusion to select bundled tool access outside intended provider policy restrictions when the affected feature is enabled.

    Published: 11 Jun 2026
    6
    Medium

    CVE-2026-53808

    Last Modified: 12 Jun 2026

    OpenClaw before 2026.5.6 contains an approval policy bypass vulnerability in the Skill Workshop apply flow that allows agent tool calls to set apply: true despite approvalPolicy: pending configuration. Attackers can exploit this by reaching the affected apply path to apply workshop changes before the expected approval step, potentially modifying configurations without proper authorization.

    Published: 11 Jun 2026
    7.7
    High

    CVE-2026-53807

    Last Modified: 12 Jun 2026

    OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that allows authenticated users to skip commands.allowFrom validation. Attackers can invoke affected callbacks to mark themselves as authorized senders before allowlist checks are applied, triggering command behavior outside configured Telegram sender restrictions.

    Published: 11 Jun 2026
    7.7
    High

    CVE-2026-53806

    Last Modified: 12 Jun 2026

    OpenClaw before 2026.5.12 contains a shell option parsing vulnerability that allows combined POSIX shell flags to bypass exec revalidation checks. Attackers can exploit this by using combined shell options to execute inline shell content without intended allowlist validation, potentially enabling unauthorized command execution when the affected feature is enabled.

    Published: 11 Jun 2026
    9
    Critical

    CVE-2026-41005

    Last Modified: 12 Jun 2026

    Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signatures from the Identity Provider (authenticity) in two SAML flows: the OAuth 2.0 SAML2 bearer grant (token endpoint) and browser SSO (ACS) when wantAssertionSigned is set to false. Assertions or responses that were unsigned but contained encrypted content could still be accepted. Encryption uses the SP's public key from published metadata, therefore, any party, not only a trusted IdP, can produce ciphertext UAA can decrypt; successful decryption therefore does not prove the IdP issued the message. Affected versions: Cloud Foundry UAA (uaa_release) 2.0.0 through 78.13.0. Cloud Foundry CF Deployment all versions through 56.1.0.

    Published: 11 Jun 2026
    8.3
    High

    CVE-2026-50005

    Last Modified: 12 Jun 2026

    Brickcom cameras ship with default credentials that allows any unauthenticated remote attacker to silently access camera feeds.

    Published: 11 Jun 2026
    8.3
    High

    CVE-2026-50245

    Last Modified: 12 Jun 2026

    Brickcom cameras allow unauthenticated access to live snapshot images via the /ONVIF endpoint and no authentication is required to retrieve still images from the camera feed.

    Published: 11 Jun 2026
    6.3
    Medium

    CVE-2026-53782

    Last Modified: 12 Jun 2026

    Summarize before 0.17.0 contains a server-side request forgery vulnerability that allows attackers who control a podcast RSS feed to direct the host to fetch transcript content from loopback addresses, link-local addresses, RFC 1918 private ranges, or other reserved destinations by supplying malicious podcast:transcript URL values. Attackers can bypass protections through DNS rebinding and redirect-based techniques, as redirect targets are not revalidated and hostnames are not resolved before request dispatch, exposing internal service responses through the summarization flow.

    Published: 11 Jun 2026
    Unknown

    CVE-2026-12038

    Last Modified: 11 Jun 2026

    ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 11 Jun 2026
    5.3
    Medium

    CVE-2026-53781

    Last Modified: 12 Jun 2026

    Summarize before 0.17.0 contains a resource exhaustion vulnerability that allows remote attackers to cause disk exhaustion by serving media responses that bypass the enforced size limit through missing or misreported Content-Length headers, chunked transfer encoding, or failed HEAD requests. Attackers who control a podcast feed or media URL can stream an unbounded response to local storage via the temp-file download path, exhausting disk or system resources on the host running the CLI.

    Published: 11 Jun 2026
    Unknown

    CVE-2026-54101

    Last Modified: 12 Jun 2026

    Reserved but no longer needed.

    Published: 11 Jun 2026
    Unknown

    CVE-2026-54102

    Last Modified: 12 Jun 2026

    Reserved but no longer needed.

    Published: 11 Jun 2026
    9.2
    Critical

    CVE-2026-49973

    Last Modified: 14 Jul 2026

    Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remote attackers to hijack initial setup by submitting the _set_password parameter to the settings API endpoint without any network origin restriction. Attackers on any reachable network can send a POST request to the settings endpoint during the first-run setup window to persist an arbitrary password hash, obtain a valid session cookie, and lock out the legitimate operator from their own instance.

    Published: 11 Jun 2026