|
1251
|
7.3 |
HIGH
Network
|
-
|
-
|
dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-co…
New
|
-
|
CVE-2026-2291
|
2026-05-13 23:17 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1252
|
7.3 |
HIGH
Network
|
-
|
-
|
Alien::FreeImage versions through 1.001 for Perl contains several vulnerable libraries.
Alien::FreeImage contains version 3.17.0 of the FreeImage library from 2017, which has known vulnerabilities s…
New
|
-
|
CVE-2022-4988
|
2026-05-13 23:16 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1253
|
8.8 |
HIGH
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.4.23 contains an improper access control vulnerability in the gateway tool's config.apply and config.patch operations that allows compromised models to write unsafe configuration…
New
|
CWE-184
Incomplete Blacklist
|
CVE-2026-45006
|
2026-05-13 23:14 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1254
|
6.0 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.4.23 caches resolved webhook route secrets backed by SecretRef values, allowing stale secrets to remain valid after rotation and reload. Attackers with previously valid webhook r…
New
|
CWE-672
Operation on a Resource after Expiration or Release
|
CVE-2026-45005
|
2026-05-13 23:14 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1255
|
7.8 |
HIGH
Local
|
openclaw
|
openclaw
|
OpenClaw before 2026.4.23 contains an arbitrary code execution vulnerability in the bundled plugin setup resolver that loads setup-api.js from process.cwd() during provider setup metadata resolution.…
New
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2026-45004
|
2026-05-13 23:13 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1256
|
5.0 |
MEDIUM
Local
|
openclaw
|
openclaw
|
OpenClaw before 2026.4.22 allows workspace dotenv files to override connector endpoint hosts for Matrix, Mattermost, IRC, and Synology connectors. Attackers with workspace access can redirect runtime…
New
|
CWE-441
Confused Deputy
|
CVE-2026-45003
|
2026-05-13 23:13 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1257
|
5.3 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.4.20 contains a hook session-key bypass vulnerability that allows attackers to circumvent the hooks.allowRequestSessionKey opt-in restriction. Attackers can render externally inf…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-45002
|
2026-05-13 23:13 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1258
|
7.1 |
HIGH
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.4.20 contains a guard bypass vulnerability in the agent-facing gateway config.patch and config.apply endpoints that fails to protect operator-trusted settings including sandbox p…
New
|
CWE-862
Missing Authorization
|
CVE-2026-45001
|
2026-05-13 23:13 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1259
|
5.0 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skips strict-mode SSRF policy checks. Attackers can create stored profiles pointing…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-45000
|
2026-05-13 23:12 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1260
|
5.3 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.4.20 fails to properly preserve untrusted labels for isolated cron awareness events, allowing webhook-triggered cron agent output to be recorded as trusted system events. Attacke…
New
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2026-44999
|
2026-05-13 23:12 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|