Vulnerability index

Browse CVEs

530 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.3 CVE-2026-35659 OpenClaw before 2026.3.22 contains a service discovery vulnerability where TXT metadata from Bonjour and DNS-SD could influence CLI routing even when… Openclaw 2026.3.22+ Fix from $1,6002026-04-10 MEDIUM 5.3 CVE-2026-35661 OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Telegram callback query handling that allows attackers to mutate session … Openclaw 2026.3.25+ Fix from $1,6002026-04-10 HIGH 8.1 CVE-2026-35653 OpenClaw before 2026.3.24 contains an incorrect authorization vulnerability in the POST /reset-profile endpoint that allows authenticated callers wit… Openclaw 2026.3.24+ Fix from $1,9502026-04-10 MEDIUM 6.5 CVE-2026-35656 OpenClaw before 2026.3.22 contains an authentication bypass vulnerability in the X-Forwarded-For header processing when trustedProxies is configured,… Openclaw 2026.3.22+ Fix from $1,6002026-04-10 MEDIUM 6.5 CVE-2026-35657 OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in the HTTP /sessions/:sessionKey/history route that skips operator.read sco… Openclaw 2026.3.25+ Fix from $1,6002026-04-10 MEDIUM 5.7 CVE-2026-35655 OpenClaw before 2026.3.22 contains an identity spoofing vulnerability in ACP permission resolution that trusts conflicting tool identity hints from r… Openclaw 2026.3.22+ Fix from $1,6002026-04-10 MEDIUM 5.3 CVE-2026-35654 OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Microsoft Teams feedback invokes that allows unauthorized senders to reco… Openclaw 2026.3.25+ Fix from $1,6002026-04-10 CRITICAL 9.1 CVE-2026-35652 OpenClaw before 2026.3.22 contains an authorization bypass vulnerability in interactive callback dispatch that allows non-allowlisted senders to exec… Openclaw 2026.3.22+ Fix from $2,3002026-04-10 HIGH 8.8 CVE-2026-35650 OpenClaw before 2026.3.22 contains an environment variable override handling vulnerability that allows attackers to bypass the shared host environmen… Openclaw 2026.3.22+ Fix from $1,9502026-04-10 MEDIUM 6.5 CVE-2026-35649 OpenClaw before 2026.3.22 contains a settings reconciliation vulnerability that allows attackers to bypass intended deny-all revocations by exploitin… Openclaw 2026.3.22+ Fix from $1,6002026-04-10 MEDIUM 5.9 CVE-2026-35648 OpenClaw before 2026.3.22 contains a policy bypass vulnerability where queued node actions are not revalidated against current command policy when de… Openclaw 2026.3.22+ Fix from $1,6002026-04-10 MEDIUM 5.3 CVE-2026-35647 OpenClaw before 2026.3.25 contains an access control vulnerability where verification notices bypass DM policy checks and reply to unpaired peers. At… Openclaw 2026.3.25+ Fix from $1,6002026-04-10 HIGH 8.8 CVE-2026-35643 OpenClaw before 2026.3.22 contains an unvalidated WebView JavascriptInterface vulnerability allowing attackers to inject arbitrary instructions. Untr… Openclaw 2026.3.22+ Fix from $1,9502026-04-10 HIGH 7.8 CVE-2026-35641 OpenClaw before 2026.3.24 contains an arbitrary code execution vulnerability in local plugin and hook installation that allows attackers to execute m… Openclaw 2026.3.24+ Fix from $1,9502026-04-10 MEDIUM 6.5 CVE-2026-35621 OpenClaw before 2026.3.24 contains a privilege escalation vulnerability where the /allowlist command fails to re-validate gateway client scopes for i… Openclaw 2026.3.24+ Fix from $1,6002026-04-10 MEDIUM 5.4 CVE-2026-35620 OpenClaw before 2026.3.24 contains missing authorization vulnerabilities in the /send and /allowlist chat command handlers. The /send command allows … Openclaw 2026.3.24+ Fix from $1,6002026-04-10 HIGH 8.1 CVE-2026-6011 A weakness has been identified in OpenClaw up to 2026.1.26. Affected by this issue is some unknown functionality of the file src/agents/tools/web-fet… Openclaw 2026.1.29+ Fix from $1,9502026-04-10 HIGH 8.8 CVE-2026-35645 OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in the gateway plugin subagent fallback deleteSession function that uses a sy… Openclaw 2026.3.25+ Fix from $1,9502026-04-09 MEDIUM 6.5 CVE-2026-35646 OpenClaw before 2026.3.25 contains a pre-authentication rate-limit bypass vulnerability in webhook token validation that allows attackers to brute-fo… Openclaw 2026.3.25+ Fix from $1,6002026-04-09 HIGH 8.8 CVE-2026-35638 OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the Control UI that allows unauthenticated sessions to retain self-declare… Openclaw 2026.3.22+ Fix from $1,9502026-04-09 HIGH 8.8 CVE-2026-35639 OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the device.pair.approve method that allows an operator.pairing approver to… Openclaw 2026.3.22+ Fix from $1,9502026-04-09 HIGH 7.5 CVE-2026-35640 OpenClaw before 2026.3.25 parses JSON request bodies before validating webhook signatures, allowing unauthenticated attackers to force resource-inten… Openclaw 2026.3.25+ Fix from $1,9502026-04-09 MEDIUM 6.5 CVE-2026-35644 OpenClaw before 2026.3.22 contains an information disclosure vulnerability that allows attackers with operator.read scope to expose credentials embed… Openclaw 2026.3.22+ Fix from $1,6002026-04-09 HIGH 7.8 CVE-2026-35632 OpenClaw through 2026.2.22 contains a symlink traversal vulnerability in agents.create and agents.update handlers that use fs.appendFile on IDENTITY.… Openclaw after 2026.2.22 Fix from $1,9502026-04-09 HIGH 7.3 CVE-2026-35637 OpenClaw before 2026.3.22 performs cite expansion before completing channel and DM authorization checks, allowing cite work and content handling prio… Openclaw 2026.3.22+ Fix from $1,9502026-04-09 MEDIUM 6.5 CVE-2026-35635 OpenClaw before 2026.3.22 contains a webhook path route replacement vulnerability in the Synology Chat extension that allows attackers to collapse mu… Openclaw 2026.3.22+ Fix from $1,6002026-04-09 MEDIUM 6.5 CVE-2026-35636 OpenClaw versions 2026.3.11 through 2026.3.24 contain a session isolation bypass vulnerability where session_status resolves sessionId to canonical s… Openclaw 2026.3.25+ Fix from $1,6002026-04-09 MEDIUM 5.3 CVE-2026-35633 OpenClaw before 2026.3.22 contains an unbounded memory allocation vulnerability in remote media HTTP error handling that allows attackers to trigger … Openclaw 2026.3.22+ Fix from $1,6002026-04-09 MEDIUM 5.1 CVE-2026-35634 OpenClaw before 2026.3.23 contains an authentication bypass vulnerability in the Canvas gateway where authorizeCanvasRequest() unconditionally allows… Openclaw 2026.3.23+ Fix from $1,6002026-04-09 HIGH 8.2 CVE-2026-35627 OpenClaw before 2026.3.22 performs cryptographic and dispatch operations on inbound Nostr direct messages before enforcing sender and pairing policy … Openclaw 2026.3.22+ Fix from $1,9502026-04-09