U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.


The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.

For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2026-35149 - HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by intercepting and altering the server's authentication responses, allowing... read CVE-2026-35149
    Published: July 16, 2026; 8:17:35 AM -0400

  • CVE-2026-35148 - HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another browser. This allows any network user to invoke these APIs and inter... read CVE-2026-35148
    Published: July 16, 2026; 8:17:35 AM -0400

  • CVE-2026-35147 - HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific API endpoints, allowing an unauthenticated attacker to interact with... read CVE-2026-35147
    Published: July 16, 2026; 8:17:35 AM -0400

  • CVE-2026-54126 - Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
    Published: July 14, 2026; 2:18:08 PM -0400

  • CVE-2026-54128 - Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally.
    Published: July 14, 2026; 2:18:08 PM -0400

  • CVE-2026-56159 - Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
    Published: July 14, 2026; 2:18:22 PM -0400

  • CVE-2026-56168 - Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.
    Published: July 14, 2026; 2:18:23 PM -0400

  • CVE-2026-56173 - Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.
    Published: July 14, 2026; 2:18:23 PM -0400

  • CVE-2026-35146 - HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish connections over unencrypted channels via the HTTP protocol, which could allow a remote attacker to intercept network traffic and e... read CVE-2026-35146
    Published: July 16, 2026; 8:17:35 AM -0400

  • CVE-2026-62220 - OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass non-browser rate limits on WebSocket authentication attempts. When the affected feature is enabled and reachable by lower-trust input, this can consu... read CVE-2026-62220
    Published: July 16, 2026; 10:18:08 PM -0400

  • CVE-2026-62216 - OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media upload feature. A lower-trust caller or configured input path could cause the media upload to reach network destinations that should have been blocked by OpenClaw polic... read CVE-2026-62216
    Published: July 16, 2026; 10:18:08 PM -0400

    V3.1: 5.0 MEDIUM

  • CVE-2026-62205 - OpenClaw versions 2026.4.12-beta.1 before 2026.6.6 contain a missing-authorization vulnerability in the MS Teams message actions feature. When the affected feature is enabled and reachable, a lower-trust caller or a configured input path can perfo... read CVE-2026-62205
    Published: July 16, 2026; 10:18:06 PM -0400

  • CVE-2026-62221 - OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature. When the affected feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist ac... read CVE-2026-62221
    Published: July 16, 2026; 10:18:09 PM -0400

  • CVE-2026-62227 - OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulnerability in browser snapshot routes that fail to validate post-navigation destinations. Attackers with lower-trust access can bypass OpenClaw policy checks to reach net... read CVE-2026-62227
    Published: July 16, 2026; 10:18:10 PM -0400

  • CVE-2026-62202 - OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that allows lower-trust callers to regain denied execution tools. Attackers can execute or persist actions beyond their intended authoriz... read CVE-2026-62202
    Published: July 16, 2026; 10:18:06 PM -0400

  • CVE-2026-62209 - OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mode dispatch feature, which could ignore the toolsAllow policy check. When the affected feature is enabled and reachable, a lower-trust cal... read CVE-2026-62209
    Published: July 16, 2026; 10:18:07 PM -0400

  • CVE-2026-62217 - OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. When the feature is enabled and reachable, a lower-trust caller or configured input path could execute or persist actions beyond the call... read CVE-2026-62217
    Published: July 16, 2026; 10:18:08 PM -0400

  • CVE-2026-62218 - OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature that allows lower-trust callers to bypass role-management checks. Attackers can perform actions requiring stronger authorization b... read CVE-2026-62218
    Published: July 16, 2026; 10:18:08 PM -0400

  • CVE-2026-62228 - OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust callers to execute actions beyond their intended authorization by using different gateway and node environments. Attackers can ex... read CVE-2026-62228
    Published: July 16, 2026; 10:18:10 PM -0400

  • CVE-2026-62219 - OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds validation. A lower-trust caller or configured input path can bypass agent ID restrictions by submitting blank agent IDs, allowing actio... read CVE-2026-62219
    Published: July 16, 2026; 10:18:08 PM -0400

Created September 20, 2022 , Updated August 27, 2024