Total
9920 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-0071 | 1 Google | 1 Android | 2026-06-18 | N/A | 7.8 HIGH |
| In SettingsLib, there is a possible missing permission check due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
| CVE-2025-48640 | 1 Google | 1 Android | 2026-06-18 | N/A | 8.0 HIGH |
| In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
| CVE-2025-48617 | 1 Google | 1 Android | 2026-06-18 | N/A | 7.8 HIGH |
| In overrideConfig of CarrierConfigLoader.java, there is a possible way to bypass UID check due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
| CVE-2026-53850 | 1 Openclaw | 1 Openclaw | 2026-06-17 | N/A | 5.5 MEDIUM |
| OpenClaw before 2026.4.25 contains a control scope enforcement bypass vulnerability in the focus command that allows authenticated callers to execute the command without proper authorization checks. Attackers can trigger the focus command to change focus state outside intended caller authority, potentially enabling unauthorized operations depending on gateway configuration and input trust levels. | |||||
| CVE-2026-53851 | 1 Openclaw | 1 Openclaw | 2026-06-17 | N/A | 5.3 MEDIUM |
| OpenClaw before 2026.5.12 contains a notification bypass vulnerability allowing Slack reaction events to enter the agent pipeline despite disabled reaction notifications. Attackers can trigger unintended agent processing by sending reaction events when the feature is enabled, potentially leading to unauthorized processing of lower-trust input. | |||||
| CVE-2026-53844 | 1 Openclaw | 1 Openclaw | 2026-06-17 | N/A | 6.5 MEDIUM |
| OpenClaw before 2026.4.29 contains a session visibility check bypass vulnerability in shared memory search that allows authenticated callers to access memory entries without proper authorization. Attackers can skip session visibility guards on the search path to retrieve memory entries that should not be visible to their session. | |||||
| CVE-2026-45085 | 1 Discourse | 1 Discourse | 2026-06-17 | N/A | 5.3 MEDIUM |
| Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to before 2026.3.1, and 2026.4.0-latest to before 2026.4.1, four authorization/disclosure issues in the chat plugin (one also involving discourse-calendar): read-only category users could create chat threads, self-deleted chat messages could be restored by their author after channel access was revoked, moderators reviewing a flagged chat message were shown the channel's current last_message (often unrelated DM content), and calendar event payloads exposed the attached chat channel and its last message to viewers without chat access (including anonymous users). This affects sites with the chat plugin enabled; the calendar issue additionally requires discourse-calendar. This issue has been patched in versions 2026.1.4, 2026.3.1, 2026.4.1, and 2026.5.0-latest.1. | |||||
| CVE-2026-54810 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Missing Authorization vulnerability in Nexi Payments Nexi XPay allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Nexi XPay: from n/a through 8.3.1. | |||||
| CVE-2026-49072 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Broken Access Control in WooCommerce Anti-Fraud <= 7.2.6 versions. | |||||
| CVE-2026-45436 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Subscriber Broken Access Control in WPBakery Page Builder <= 8.7.2 versions. | |||||
| CVE-2026-40723 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| Subscriber Broken Access Control in Bricks Builder <= 2.1.4 versions. | |||||
| CVE-2026-39595 | 2026-06-17 | N/A | 4.7 MEDIUM | ||
| Author Broken Access Control in W3 Total Cache <= 2.9.1 versions. | |||||
| CVE-2026-24611 | 2026-06-17 | N/A | 9.1 CRITICAL | ||
| Unauthenticated Broken Access Control in MetForm Pro <= 3.9.1 versions. | |||||
| CVE-2026-24610 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| Subscriber Broken Access Control in MetForm Pro <= 3.9.1 versions. | |||||
| CVE-2025-69189 | 2026-06-17 | N/A | 7.3 HIGH | ||
| Missing Authorization vulnerability in EMV JobBank allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JobBank: from n/a through 1.2.3. | |||||
| CVE-2024-37210 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Missing Authorization vulnerability in ali2woo AliNext allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects AliNext: from n/a through 3.3.5. | |||||
| CVE-2024-24709 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| Missing Authorization vulnerability in Shareaholic allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Shareaholic: from n/a through 9.7.11. | |||||
| CVE-2026-0057 | 1 Google | 1 Android | 2026-06-17 | N/A | 3.3 LOW |
| In Contacts Provider, there is a possible way to access an incoming call's phone number and associated metadata due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
| CVE-2026-28587 | 1 Google | 1 Android | 2026-06-17 | N/A | 5.5 MEDIUM |
| In MmsSmsProvider of MmsSmsProvider.java, there is a possible way to retrieve sensitive information due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
| CVE-2026-0133 | 1 Google | 1 Android | 2026-06-17 | N/A | 7.8 HIGH |
| In smmu_attach_dev of arm-smmu-v3.c, there is a possible way to sign malicious Android Runtime bootclass artifacts due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | |||||
