All CVEs — page 54 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw allows unauthenticated attackers to perform administrator-only actions by tricking a logged-in administrator into visiting a crafted page, due to improper verification of the WordPress REST API nonce.
The flaw allows unauthenticated attackers to upload executable files, such as PHP files, to a web-accessible temporary directory, leading to Remote Code Execution (RCE).
The flaw allows an attacker to execute arbitrary processes on a paired node by bypassing the normal approval flow for Google Meet node commands, posing a significant risk to the security and integrity of the system.
OpenClaw versions before 2026.7.1 allow non-owner users to execute arbitrary stdio MCP commands with process privileges, leading to potential host compromise.