2026-07-13
2026-07-13 22:16Z
HIGH

CVE-2026-62195 — OpenClaw: versions 2026.5.20 before 2026.6.6 contain an authorization bypass vulnerability in the MCP loopback

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62195

OpenClaw versions 2026.5.20 before 2026.6.6 contain an authorization bypass vulnerability in the MCP loopback feature that allows lower-trust callers to execute owner-only tools. Attackers can bypass authorization checks through configured input paths to execute or persist actions beyond their intended permissions. CVSSv3.1 8.3 (HIGH)

CWECWE 732VNDOpenclawTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-13
2026-07-13 22:16Z
HIGH

CVE-2026-62194 — OpenClaw: versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install commands

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62194

OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install commands that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can exploit misconfigured input paths or enabled features to escalate privileges and perform unauthorized actions when the feature is reachable. CVSSv3.1 8.8 (HIGH)

CWECWE 862CWECWE 732VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-13
2026-07-13 22:16Z
HIGH

CVE-2026-62192 — OpenClaw: versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in Discord guild actions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62192

OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in Discord guild actions that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input paths to skip cross-provider requester authorization and execute restricted operations. CVSSv3.1 8.1 (HIGH)

CWECWE 863VNDOpenclawTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-13
2026-07-13 22:16Z
HIGH

CVE-2026-62190 — OpenClaw: versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62190

OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can leverage configured input paths to bypass durable exec approval binding and perform unauthorized operations when the affected feature is enabled. CVSSv3.1 8.8 (HIGH)

CWECWE 863CWECWE 706VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-13
2026-07-13 22:16Z
HIGH

CVE-2026-62188 — OpenClaw: @openclaw/feishu versions 2026.6.6 and earlier contain an incorrect authorization vulnerability in which the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62188

OpenClaw @openclaw/feishu versions 2026.6.6 and earlier contain an incorrect authorization vulnerability in which the Feishu permission tools could ignore per-account disablement settings. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could perform actions that should have required a stronger authorization or policy check. The issue is fixed in version 2026.6.9. CVSSv3.1 8.1 (HIGH)

CWECWE 863VNDOpenclawTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-13
2026-07-13 22:16Z
HIGH

CVE-2026-62187 — OpenClaw: A lower-trust caller or a configured input path could perform actions that should have

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62187

OpenClaw Feishu tools (npm package @openclaw/feishu) in versions <= 2026.6.6 could ignore per-account disablement. A lower-trust caller or a configured input path could perform actions that should have required a stronger authorization or policy check, resulting in unauthorized operations. The issue is fixed in version 2026.6.9. Impact depends on the operator's configuration and whether lower-trust input can reach the affected feature. CVSSv3.1 8.1 (HIGH)

CWECWE 863VNDOpenclawTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-13
2026-07-13 22:16Z
CRIT

CVE-2026-59801 — 9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59801

9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API endpoints by sending requests without any credentials due to missing authentication middleware in the Next.js API routes under src/app/api/providers/*. Attackers can enumerate, create, modify, or delete provider connections to expose partial credentials, OAuth tokens, and API keys, redirect AI traffic to attacker-controlled serv CVSSv3.1 9.8 (CRITICAL)

CWECWE 306TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-13
2026-07-13 22:16Z
HIGH

CVE-2026-58500 — MCP: When a victim's MCP client renders this resource, the injected script executes and can

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58500

MCP Appium is an MCP server that provides AI assistants with tools to automate mobile app testing on Android and iOS. In versions prior to 1.85.10, the createLocatorGeneratorUI function interpolates attacker-controlled element attributes — text, content-desc, resource-id, and locator selector values — directly into an HTML template literal without any HTML or JavaScript context escaping. An attacker who controls the UI of the app under test can inject arbitrary HTML and JavaS CVSSv3.1 8.2 (HIGH)

CWECWE 79VNDMcpTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-13
2026-07-13 22:16Z
CRIT

CVE-2026-52533 — Link: An issue in D-Link DIR-1253 v.1.0.1.250923.142435 allows an attacker to escalate privileges via the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52533

An issue in D-Link DIR-1253 v.1.0.1.250923.142435 allows an attacker to escalate privileges via the etc/shadow component file CVSSv3.1 9.8 (CRITICAL)

CWECWE 269VNDLinkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-13
2026-07-13 22:16Z
CRIT

CVE-2026-51821 — SQL: Injection vulnerability in Shenzhou Shihan Video Conference System v.1.0 allows a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51821

SQL Injection vulnerability in Shenzhou Shihan Video Conference System v.1.0 allows a remote attacker to execute arbitrary code via the /user/getUserLogin endpoint CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-13
2026-07-13 22:16Z
CRIT

CVE-2026-51541 — OpENer: 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message parsing when

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51541

OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message parsing when handling malformed explicit requests with a forged EPath size. An attacker can send a valid ENIP SendRRData frame carrying a very short CIP payload whose path_size field claims that many more path words are present than are actually available. Because the parser trusts the attacker-controlled path_size and continues decoding path segments without a remaining-length boundary, it reads bey CVSSv3.1 9.1 (CRITICAL)

CWECWE 125VNDOpenerTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-13
2026-07-13 22:16Z
CRIT

CVE-2026-51540 — OpENer: 2.3.0 (master branch up to commit 76b95cf) is vulnerable to a severe memory

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51540

OpENer 2.3.0 (master branch up to commit 76b95cf) is vulnerable to a severe memory corruption issue caused by an integer underflow in the processing of connected explicit messages (SendUnitData). CVSSv3.1 9.8 (CRITICAL)

CWECWE 191VNDOpenerTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-13
2026-07-13 22:16Z
CRIT

CVE-2026-51538 — EIPStackGroup: OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability in its

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51538

EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability in its handling of encapsulation sessions. When the server processes critical encapsulation commands, it verifies whether the provided session_handle exists in the global session list, but it fails to verify whether that handle belongs to the specific TCP connection issuing the request. Because there is no strong binding between a session handle and its originating socket, any a CVSSv3.1 9.1 (CRITICAL)

CWECWE 284VNDEipstackgroupTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-13
2026-07-13 22:16Z
CRIT

CVE-2026-51537 — EIPStackGroup: OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in Connection Manager handling

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51537

EIPStackGroup OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in Connection Manager handling of ForwardOpen requests when processing short malformed packets. An attacker can send a valid ENIP outer frame carrying a malformed CIP ForwardOpen/LargeForwardOpen request, causing the parser to continue reading fields even when request data is insufficient. This issue is remotely triggerable via network traffic and does not require authentication. CVSSv3.1 9.1 (CRITICAL)

CWECWE 125VNDEipstackgroupTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-13
2026-07-13 22:16Z
CRIT

CVE-2026-51536 — OpENer: This negative length bypasses subsequent bounds checking (due to signed/unsigned comparison issues) and is

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51536

In OpENer 2.3.0 (commit 76b95cf) when parsing incoming CIP (Common Industrial Protocol) network packets, the length parameter is inconsistently typed across the call stack. Specifically, an upstream length calculated as an int is passed to a downstream function that expects an EipInt16 (a 16-bit signed integer). If a maliciously crafted packet with specific length fields is processed, the length parameter can overflow or be truncated into a negative value. This negative lengt CVSSv3.1 9.1 (CRITICAL)

CWECWE 190VNDOpenerTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-13
2026-07-13 21:16Z
CRIT

CVE-2026-58409 — ChurchCRM: Prior to version 7.4.0, an authenticated administrator can achieve Remote Code Execution (RCE) on

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58409

ChurchCRM is an open-source church management system. Prior to version 7.4.0, an authenticated administrator can achieve Remote Code Execution (RCE) on the server by installing a malicious plugin ZIP archive containing a PHP webshell. The application explicitly includes 'php' in its ALLOWED_EXTENSIONS list, while the dangerous extensions denylist (DENIED_EXTENSIONS) fails to block standard .php files. Because `php` is explicitly included in the allowed extension list for plug CVSSv3.1 9.1 (CRITICAL)

CWECWE 434VNDChurchcrmTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-13
2026-07-13 21:16Z
HIGH

CVE-2026-48364 — ColdFusion: versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48364

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. CVSSv3.1 8.2 (HIGH)

CWECWE 427VNDColdfusionTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-13
2026-07-13 21:16Z
HIGH

CVE-2026-48363 — ColdFusion: versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48363

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. CVSSv3.1 8.2 (HIGH)

CWECWE 427VNDColdfusionTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-13
2026-07-13 20:16Z
HIGH

CVE-2026-55773 — CedarJava: In versions prior to 2.3.6, 3.4.1 and 4.9.0, under certain circumstances, improper input handling

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55773

CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. In versions prior to 2.3.6, 3.4.1 and 4.9.0, under certain circumstances, improper input handling could allow Cedar-expression injection via unescaped toCedarExpr(). The toCedarExpr() method on Cedar Value types does not escape special characters (" or \) when converting values to Cedar source code. If an integrator uses toCedarExpr() to build policy te CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDCedarjavaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-13
2026-07-13 20:16Z
HIGH

CVE-2026-55771 — CedarJava: In versions prior to 4.9.0, the EntityIdentifier.equals() has inverted null/self branches which could lead

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55771

CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. In versions prior to 4.9.0, the EntityIdentifier.equals() has inverted null/self branches which could lead to incorrect equality comparisons. The EntityIdentifier.equals() method has inverted logic for null and self-reference checks, returning true for null comparisons and false for self-comparisons. This does not affect Cedar authorization decisions (c CVSSv3.1 8.8 (HIGH)

CWECWE 94CWECWE 843CWECWE 697VNDCedarjavaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-13
2026-07-13 19:17Z
HIGH

CVE-2026-55772 — CedarJava: In versions prior to 2.3.6, 3.4.1 and 4.9.0, under certain circumstances, improper input handling

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55772

CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. In versions prior to 2.3.6, 3.4.1 and 4.9.0, under certain circumstances, improper input handling could allow Record-to-Entity type confusion across the Java-Rust FFI boundary. CedarJava sends authorization requests to the Rust cedar-policy evaluator as JSON. The JSON protocol reserves magic single-key object shapes (__entity and __extn) for entity refe CVSSv3.1 8.8 (HIGH)

CWECWE 843VNDCedarjavaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-13
2026-07-13 19:17Z
HIGH

CVE-2026-49972 — Laravel: Laravel-Mediable before 7.0.0 contains a file upload vulnerability that allows unauthenticated attackers to achieve

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49972

Laravel-Mediable before 7.0.0 contains a file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading a file with an embedded PHP extension disguised within a double extension such as shell.php.jpg. The PATHINFO_FILENAME extraction preserves the inner .php extension in the base name, and on misconfigured Apache or nginx servers that execute any filename containing .php as PHP, the stored file is interpreted as executable code w CVSSv3.1 8.8 (HIGH)

CWECWE 434VNDLaravelTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-13
2026-07-13 19:17Z
HIGH

CVE-2026-49970 — Laravel: Laravel-Mediable before 7.0.0 contains a path traversal vulnerability in the File::sanitizePath() function that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49970

Laravel-Mediable before 7.0.0 contains a path traversal vulnerability in the File::sanitizePath() function that allows attackers to write uploaded files to arbitrary locations by controlling the directory argument passed to MediaUploader::toDestination(). Attackers can exploit the permissive character-class regex that allows both dot and slash characters combined with an ineffective trailing trim() call to bypass sanitization and upload files to sensitive locations such as th CVSSv3.1 8.8 (HIGH)

CWECWE 22VNDLaravelTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-13
2026-07-13 18:16Z
CRIT

CVE-2026-61500 — Rejetto: A remote attacker can collect a small number of login responses, reconstruct the generator's

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61500

Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login. A remote attacker can collect a small number of login responses, reconstruct the generator's state, recover the signing key, and forge a valid administrator session cookie, leading to full administrative access and remote code execution via the server_code configuration fe CVSSv3.1 9.8 (CRITICAL)

CWECWE 338VNDRejettoTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-13
2026-07-13 18:16Z
HIGH

CVE-2026-61463 — Shiori: contains a privilege escalation vulnerability in the account update endpoint that allows authenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61463

Shiori contains a privilege escalation vulnerability in the account update endpoint that allows authenticated users to modify the owner field without authorization checks. Attackers can escalate to administrator by submitting a crafted PATCH request with owner: true, then re-authenticate to obtain an admin JWT token granting full system access. CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDShioriTYPVulnerability
8.8
CVSS v3.1
94
Edit Score