Vulnerability index

Browse CVEs

530 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-62228 OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust callers to execute actions beyo… Openclaw 2026.6.5+ Fix from $1,9502026-07-17 HIGH 8.8 CVE-2026-62229 OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in exec allowlist glob matching that allows lower-trust callers to execute ac… Openclaw 2026.5.18+ Fix from $1,9502026-07-17 HIGH 7.7 CVE-2026-62227 OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulnerability in browser snapshot routes that fail to validate post-navigat… Openclaw 2026.5.26+ Fix from $1,9502026-07-17 HIGH 8.8 CVE-2026-62223 OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in the device-pair approval feature that allows lower-trust callers to execut… Openclaw 2026.5.18+ Fix from $1,9502026-07-17 HIGH 8.5 CVE-2026-62226 OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fails to properly validate current-ta… Openclaw 2026.5.19+ Fix from $1,9502026-07-17 HIGH 7.8 CVE-2026-62222 OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of untrusted workspace plugins. Attackers with lower-tr… Openclaw 2026.5.22+ Fix from $1,9502026-07-17 MEDIUM 5.4 CVE-2026-62221 OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature. When the affected feature i… Openclaw 2026.5.26+ Fix from $1,6002026-07-17 MEDIUM 5.4 CVE-2026-62225 OpenClaw versions before 2026.5.18 contain an authorization bypass vulnerability in skill command dispatch that allows lower-trust callers to execute… Openclaw 2026.5.18+ Fix from $1,6002026-07-17 HIGH 8.8 CVE-2026-62217 OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. When the feature is enabled and reachab… Openclaw 2026.5.27+ Fix from $1,9502026-07-17 HIGH 8.8 CVE-2026-62218 OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature that allows lower-trust callers … Openclaw 2026.5.27+ Fix from $1,9502026-07-17 HIGH 8.0 CVE-2026-62215 OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability in HTTP Canvas responses that allows lower-trust callers to forge tr… Openclaw 2026.6.5+ Fix from $1,9502026-07-17 HIGH 7.1 CVE-2026-62219 OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds validation. A lower-trust caller or co… Openclaw 2026.5.26+ Fix from $1,9502026-07-17 MEDIUM 6.5 CVE-2026-62214 OpenClaw versions before 2026.5.28 Bot Framework contains an improper input validation vulnerability that allows lower-trust callers to expose bot to… Openclaw 2026.5.28+ Fix from $1,6002026-07-17 MEDIUM 5.3 CVE-2026-62220 OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass non-browser rate limits on WebSocket authentication… Openclaw 2026.5.26+ Fix from $1,6002026-07-17 MEDIUM 5.0 CVE-2026-62216 OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media upload feature. A lower-trust caller or configured input path could ca… Openclaw 2026.5.28+ Fix from $1,6002026-07-17 HIGH 8.8 CVE-2026-62207 OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability that allows lower-trust callers to reach admin-scoped tools. Attacke… Openclaw 2026.6.5+ Fix from $1,9502026-07-17 HIGH 8.1 CVE-2026-62209 OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mode dispatch feature, which could ignore … Openclaw 2026.6.5+ Fix from $1,9502026-07-17 HIGH 7.1 CVE-2026-62212 OpenClaw before 2026.5.28 contains a race condition in the MS Teams safeFetch DNS rebinding check. When the affected feature is enabled and reachable… Openclaw 2026.5.28+ Fix from $1,9502026-07-17 MEDIUM 6.5 CVE-2026-62208 OpenClaw before 2026.6.5 could forward Authorization headers during MCP SSE redirects. When the affected feature is enabled and reachable, a lower-tr… Openclaw 2026.6.5+ Fix from $1,6002026-07-17 MEDIUM 6.5 CVE-2026-62210 OpenClaw versions before 2026.6.1 contain a denial of service vulnerability where remote media URLs can trigger slow-read attacks that exhaust gatewa… Openclaw 2026.6.1+ Fix from $1,6002026-07-17 MEDIUM 6.5 CVE-2026-62213 OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower-trust callers to expose Bot … Openclaw 2026.5.27+ Fix from $1,6002026-07-17 MEDIUM 5.0 CVE-2026-62211 OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature that allows lower-trust caller… Openclaw 2026.6.1+ Fix from $1,6002026-07-17 HIGH 8.8 CVE-2026-62202 OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that allows lower-trust callers to rega… Openclaw 2026.6.9+ Fix from $1,9502026-07-17 HIGH 8.8 CVE-2026-62203 OpenClaw versions before 2026.6.6 contain an environment variable filtering vulnerability in host exec that fails to properly sanitize rustup startup… Openclaw 2026.6.6+ Fix from $1,9502026-07-17 HIGH 7.7 CVE-2026-62201 OpenClaw versions before 2026.6.6 contain a network policy bypass vulnerability in the sandbox exec-server that allows lower-trust callers to reach i… Openclaw 2026.6.6+ Fix from $1,9502026-07-17 HIGH 7.1 CVE-2026-62205 OpenClaw versions 2026.4.12-beta.1 before 2026.6.6 contain a missing-authorization vulnerability in the MS Teams message actions feature. When the af… Openclaw 2026.6.6+ Fix from $1,9502026-07-17 HIGH 7.1 CVE-2026-62206 OpenClaw versions before 2026.6.9 contain a missing authorization vulnerability in Discord moderation actions. In affected versions, a lower-trust ca… Openclaw 2026.6.9+ Fix from $1,9502026-07-17 HIGH 8.8 CVE-2026-62199 OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that can miss interpreter startup variables. When the affected fe… Openclaw 2026.6.6+ Fix from $1,9502026-07-13 HIGH 8.8 CVE-2026-62200 OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that could allow Git ext transport to be abused. When the affecte… Openclaw 2026.6.6+ Fix from $1,9502026-07-13 HIGH 8.5 CVE-2026-62197 OpenClaw before 2026.6.6 contains a policy bypass vulnerability in browser CDP discovery that accepts blocked WebSocket URLs. Attackers with lower-tr… Openclaw 2026.6.6+ Fix from $1,9502026-07-13