Vulnerability index

Browse CVEs

530 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-32064 OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches x11vnc without authentication for noVNC observer sessions, allowing unauthen… Openclaw 2026.2.21+ Fix from $2,3002026-03-21 HIGH 7.1 CVE-2026-32057 OpenClaw versions prior to 2026.2.25 contain an authentication bypass vulnerability in the trusted-proxy Control UI pairing mechanism that accepts cl… Openclaw 2026.2.25+ Fix from $1,9502026-03-21 MEDIUM 6.5 CVE-2026-32058 OpenClaw versions prior to 2026.2.26 contain an approval context-binding weakness in system.run execution flows with host=node that allows reuse of p… Openclaw 2026.2.26+ Fix from $1,6002026-03-21 MEDIUM 6.5 CVE-2026-32065 OpenClaw versions prior to 2026.2.25 contain an approval-integrity bypass vulnerability in system.run where rendered command text is used as approval… Openclaw 2026.2.25+ Fix from $1,6002026-03-21 CRITICAL 9.8 CVE-2026-32052 OpenClaw versions prior to 2026.2.24 contain a command injection vulnerability in the system.run shell-wrapper that allows attackers to execute hidde… Openclaw 2026.2.24+ Fix from $2,3002026-03-21 HIGH 8.8 CVE-2026-32051 OpenClaw versions prior to 2026.3.1 contain an authorization mismatch vulnerability that allows authenticated callers with operator.write scope to in… Openclaw 2026.3.1+ Fix from $1,9502026-03-21 HIGH 8.2 CVE-2026-32055 OpenClaw versions prior to 2026.2.26 contain a path traversal vulnerability in workspace boundary validation that allows attackers to write files out… Openclaw 2026.2.26+ Fix from $1,9502026-03-21 HIGH 7.8 CVE-2026-32054 OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in browser trace and download output path handling that allows local a… Openclaw 2026.2.25+ Fix from $1,9502026-03-21 MEDIUM 6.5 CVE-2026-32053 OpenClaw versions prior to 2026.2.23 contain a vulnerability in Twilio webhook event deduplication where normalized event IDs are randomized per pars… Openclaw 2026.2.23+ Fix from $1,6002026-03-21 CRITICAL 9.9 CVE-2026-32048 OpenClaw versions prior to 2026.3.1 fail to enforce sandbox inheritance during cross-agent sessions_spawn operations, allowing sandboxed sessions to … Openclaw 2026.3.1+ Fix from $2,3002026-03-21 CRITICAL 9.8 CVE-2026-32046 OpenClaw versions prior to 2026.2.21 contain an improper sandbox configuration vulnerability that allows attackers to execute arbitrary code by explo… Openclaw 2026.2.21+ Fix from $2,3002026-03-21 CRITICAL 9.1 CVE-2026-32045 OpenClaw versions prior to 2026.2.21 incorrectly apply tokenless Tailscale header authentication to HTTP gateway routes, allowing bypass of token and… Openclaw 2026.2.21+ Fix from $2,3002026-03-21 HIGH 7.5 CVE-2026-32049 OpenClaw versions prior to 2026.2.22 fail to consistently enforce configured inbound media byte limits before buffering remote media across multiple … Openclaw 2026.2.22+ Fix from $1,9502026-03-21 MEDIUM 5.3 CVE-2026-32050 OpenClaw versions prior to 2026.2.25 contain an access control vulnerability in signal reaction notification handling that allows unauthorized sender… Openclaw 2026.2.25+ Fix from $1,6002026-03-21 HIGH 8.8 CVE-2026-32042 OpenClaw versions 2026.2.22 prior to 2026.2.25 contain a privilege escalation vulnerability allowing unpaired device identities to bypass operator pa… Openclaw 2026.2.25+ Fix from $1,9502026-03-21 HIGH 7.0 CVE-2026-32043 OpenClaw versions prior to 2026.2.25 contain a time-of-check-time-of-use vulnerability in approval-bound system.run execution where the cwd parameter… Openclaw 2026.2.25+ Fix from $1,9502026-03-21 MEDIUM 5.5 CVE-2026-32044 OpenClaw versions prior to 2026.3.2 contain an archive extraction vulnerability in the tar.bz2 installer path that bypasses safety checks enforced on… Openclaw 2026.3.2+ Fix from $1,6002026-03-21 CRITICAL 9.9 CVE-2026-22172 OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token or password… Openclaw 2026.3.12+ Fix from $2,3002026-03-20 HIGH 7.8 CVE-2026-32041 OpenClaw versions prior to 2026.3.1 fail to properly handle authentication bootstrap errors during startup, allowing browser-control routes to remain… Openclaw 2026.3.1+ Fix from $1,9502026-03-19 MEDIUM 6.5 CVE-2026-32039 OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the toolsBySender group policy matching that allows attackers t… Openclaw 2026.2.22+ Fix from $1,6002026-03-19 MEDIUM 6.1 CVE-2026-32040 OpenClaw versions prior to 2026.2.23 contain an html injection vulnerability in the HTML session exporter that allows attackers to execute arbitrary … Openclaw 2026.2.23+ Fix from $1,6002026-03-19 CRITICAL 9.0 CVE-2026-32038 OpenClaw before 2026.2.24 contains a sandbox network isolation bypass vulnerability that allows trusted operators to join another container's network… Openclaw 2026.2.24+ Fix from $2,3002026-03-19 HIGH 8.2 CVE-2026-32036 OpenClaw gateway plugin versions prior to 2026.2.26 contain a path traversal vulnerability that allows remote attackers to bypass route authenticatio… Openclaw 2026.2.6+ Fix from $1,9502026-03-19 HIGH 8.1 CVE-2026-32034 OpenClaw versions prior to 2026.2.21 contain an authentication bypass vulnerability in the Control UI when allowInsecureAuth is explicitly enabled an… Openclaw 2026.2.21+ Fix from $1,9502026-03-19 HIGH 7.1 CVE-2026-32035 OpenClaw versions prior to 2026.3.2 fail to pass the senderIsOwner flag when processing Discord voice transcripts in agentCommand, causing the flag t… Openclaw 2026.3.2+ Fix from $1,9502026-03-19 MEDIUM 6.5 CVE-2026-32037 OpenClaw versions prior to 2026.2.22 fail to consistently validate redirect chains against configured mediaAllowHosts allowlists during MSTeams media… Openclaw 2026.2.22+ Fix from $1,6002026-03-19 HIGH 7.8 CVE-2026-32032 OpenClaw versions prior to 2026.2.22 contain an arbitrary shell execution vulnerability in shell environment fallback that trusts the unvalidated SHE… Openclaw 2026.2.22+ Fix from $1,9502026-03-19 HIGH 7.5 CVE-2026-32030 OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the stageSandboxMedia function that accepts arbitrary absolute paths w… Openclaw 2026.2.19+ Fix from $1,9502026-03-19 MEDIUM 6.5 CVE-2026-32031 OpenClaw versions prior to 2026.2.26 server-http contains an authentication bypass vulnerability in gateway authentication for plugin channel endpoin… Openclaw 2026.2.26+ Fix from $1,6002026-03-19 MEDIUM 6.5 CVE-2026-32033 OpenClaw versions prior to 2026.2.24 contain a path traversal vulnerability where @-prefixed absolute paths bypass workspace-only file-system boundar… Openclaw 2026.2.24+ Fix from $1,6002026-03-19