Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

23,162 CVEs

CVEs (23,162, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 451–475 of 23,162 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-41390 HIGH Patched 7.3 2026-04-28 OpenClaw before 2026.3.28 contains an exec allowlist bypass vulnerability where allow-always persistence fails to unwrap /usr/bin/script and similar wrappers before storing…
CVE-2026-41391 MEDIUM Patched 5.3 2026-04-28 OpenClaw before 2026.3.31 fails to properly sanitize PIP_INDEX_URL and UV_INDEX_URL environment variables in host execution contexts, allowing attackers to redirect Python …
CVE-2026-41392 MEDIUM Patched 6.7 2026-04-28 OpenClaw before 2026.3.31 contains an exec allowlist bypass vulnerability allowing attackers to inherit allowlist trust via shell init-file wrapper invocations. Attackers c…
CVE-2026-41393 MEDIUM Patched 4.8 2026-04-28 OpenClaw before 2026.3.31 contains a wide-area discovery vulnerability allowing arbitrary tailnet peers to be accepted as DNS authorities. Attackers with same-tailnet posit…
CVE-2026-41394 HIGH Patched 8.2 2026-04-28 OpenClaw before 2026.3.31 contains an authentication bypass vulnerability where unauthenticated plugin-auth HTTP routes receive operator runtime write scopes. Attackers can…
CVE-2026-41395 HIGH Patched 7.5 2026-04-28 OpenClaw before 2026.3.28 contains a webhook replay vulnerability in Plivo V3 signature verification that canonicalizes query ordering for signatures but hashes raw URLs fo…
CVE-2026-41396 HIGH Patched 7.8 2026-04-28 OpenClaw before 2026.3.31 allows workspace .env files to override the OPENCLAW_BUNDLED_PLUGINS_DIR environment variable, compromising plugin trust verification. Attackers w…
CVE-2026-41397 MEDIUM Patched 6.8 2026-04-28 OpenClaw before 2026.3.31 contains a sandbox escape vulnerability allowing attackers to traverse directory boundaries through symlink exploitation during file synchronizati…
CVE-2026-41398 MEDIUM Patched 4.6 2026-04-28 OpenClaw before 2026.4.2 contains an improper access control vulnerability in the iOS A2UI bridge that treats generic local-network pages as trusted origins. Attackers can …
CVE-2026-41399 HIGH Patched 7.5 2026-04-28 OpenClaw before 2026.3.28 accepts unbounded concurrent unauthenticated WebSocket upgrades without pre-authentication budget allocation. Unauthenticated network attackers ca…
CVE-2026-41400 MEDIUM Patched 5.3 2026-04-28 OpenClaw before 2026.3.31 contains an incomplete fix for CVE-2026-32062 where the voice-call component parses large WebSocket frames before start validation. Remote attacke…
CVE-2026-41402 MEDIUM Patched 4.2 2026-04-28 OpenClaw before 2026.3.31 contains a scope bypass vulnerability in webhook replay cache deduplication that allows authenticated attackers to replay messages across sibling …
CVE-2026-41403 LOW Patched 2.9 2026-04-28 OpenClaw before 2026.3.31 misclassifies proxied remote requests as loopback connections in the diffs viewer when allowRemoteViewer is disabled, allowing unauthorized access…
CVE-2026-41404 HIGH Patched 8.8 2026-04-28 OpenClaw before 2026.3.31 contains an incomplete scope-clearing vulnerability in trusted-proxy authentication mode that allows operator.admin privilege escalation. Attacker…
CVE-2026-41405 HIGH Patched 7.5 2026-04-28 OpenClaw before 2026.3.31 parses MS Teams webhook request bodies before performing JWT validation, allowing unauthenticated attackers to trigger resource exhaustion. Remote…
CVE-2026-41406 MEDIUM Patched 5.4 2026-04-28 OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability that allows remote attackers to access restricted messages. Attackers can exploit fetched quoted,…
CVE-2026-41407 LOW Patched 3.7 2026-04-28 OpenClaw before 2026.4.2 contains a timing side channel vulnerability in shared-secret comparison call sites that use early length-mismatch checks instead of fixed-length c…
CVE-2026-41408 MEDIUM Patched 4.3 2026-04-28 OpenClaw before 2026.3.31 contains a resource exhaustion vulnerability in media downloads that bypasses core safety limits for file size, count, and cleanup operations. Att…
CVE-2026-41910 MEDIUM Patched 4.3 2026-04-28 OpenClaw before 2026.4.8 omits owner-only enforcement for cross-channel allowlist writes in the /allowlist endpoint. An authorized non-owner sender can bypass access contro…
CVE-2026-41911 MEDIUM Patched 6.5 2026-04-28 OpenClaw before 2026.4.8 contains a filesystem policy bypass vulnerability in docx upload processing that allows local file reads outside workspace boundaries. Attackers ca…
CVE-2026-41912 HIGH Patched 7.6 2026-04-28 OpenClaw before 2026.4.8 contains a server-side request forgery policy bypass vulnerability allowing attackers to trigger navigations bypassing normal SSRF checks. Attacker…
CVE-2026-41913 LOW Patched 3.7 2026-04-28 OpenClaw before 2026.4.4 contains a race condition vulnerability in shared-secret authentication that allows concurrent asynchronous requests to bypass the per-key rate-lim…
CVE-2026-41914 HIGH Patched 8.5 2026-04-28 OpenClaw before 2026.4.8 contains a server-side request forgery vulnerability in QQ Bot media download paths that bypass SSRF protection. Attackers can exploit unprotected …
CVE-2026-41915 MEDIUM Patched 5.3 2026-04-28 OpenClaw before 2026.4.8 fails to remove git plumbing environment variables from the execution environment before host exec operations. Attackers can exploit this by settin…
CVE-2026-41916 MEDIUM Patched 5.4 2026-04-28 OpenClaw before 2026.4.8 contains an authentication state management vulnerability where the resolvedAuth closure becomes stale after configuration reload. Newly accepted g…