Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.1
CVE-2026-32064
OpenClaw versions prior to 2026.2.21 sandbox browser entrypoint launches x11vnc without authentication for noVNC observer sessions, allowing unauthen…
Openclaw
2026.2.21+
HIGH 7.1
CVE-2026-32057
OpenClaw versions prior to 2026.2.25 contain an authentication bypass vulnerability in the trusted-proxy Control UI pairing mechanism that accepts cl…
Openclaw
2026.2.25+
MEDIUM 6.5
CVE-2026-32058
OpenClaw versions prior to 2026.2.26 contain an approval context-binding weakness in system.run execution flows with host=node that allows reuse of p…
Openclaw
2026.2.26+
MEDIUM 6.5
CVE-2026-32065
OpenClaw versions prior to 2026.2.25 contain an approval-integrity bypass vulnerability in system.run where rendered command text is used as approval…
Openclaw
2026.2.25+
CRITICAL 9.8
CVE-2026-32052
OpenClaw versions prior to 2026.2.24 contain a command injection vulnerability in the system.run shell-wrapper that allows attackers to execute hidde…
Openclaw
2026.2.24+
HIGH 8.8
CVE-2026-32051
OpenClaw versions prior to 2026.3.1 contain an authorization mismatch vulnerability that allows authenticated callers with operator.write scope to in…
Openclaw
2026.3.1+
HIGH 8.2
CVE-2026-32055
OpenClaw versions prior to 2026.2.26 contain a path traversal vulnerability in workspace boundary validation that allows attackers to write files out…
Openclaw
2026.2.26+
HIGH 7.8
CVE-2026-32054
OpenClaw versions prior to 2026.2.25 contain a symlink traversal vulnerability in browser trace and download output path handling that allows local a…
Openclaw
2026.2.25+
MEDIUM 6.5
CVE-2026-32053
OpenClaw versions prior to 2026.2.23 contain a vulnerability in Twilio webhook event deduplication where normalized event IDs are randomized per pars…
Openclaw
2026.2.23+
CRITICAL 9.9
CVE-2026-32048
OpenClaw versions prior to 2026.3.1 fail to enforce sandbox inheritance during cross-agent sessions_spawn operations, allowing sandboxed sessions to …
Openclaw
2026.3.1+
CRITICAL 9.8
CVE-2026-32046
OpenClaw versions prior to 2026.2.21 contain an improper sandbox configuration vulnerability that allows attackers to execute arbitrary code by explo…
Openclaw
2026.2.21+
CRITICAL 9.1
CVE-2026-32045
OpenClaw versions prior to 2026.2.21 incorrectly apply tokenless Tailscale header authentication to HTTP gateway routes, allowing bypass of token and…
Openclaw
2026.2.21+
HIGH 7.5
CVE-2026-32049
OpenClaw versions prior to 2026.2.22 fail to consistently enforce configured inbound media byte limits before buffering remote media across multiple …
Openclaw
2026.2.22+
MEDIUM 5.3
CVE-2026-32050
OpenClaw versions prior to 2026.2.25 contain an access control vulnerability in signal reaction notification handling that allows unauthorized sender…
Openclaw
2026.2.25+
HIGH 8.8
CVE-2026-32042
OpenClaw versions 2026.2.22 prior to 2026.2.25 contain a privilege escalation vulnerability allowing unpaired device identities to bypass operator pa…
Openclaw
2026.2.25+
HIGH 7.0
CVE-2026-32043
OpenClaw versions prior to 2026.2.25 contain a time-of-check-time-of-use vulnerability in approval-bound system.run execution where the cwd parameter…
Openclaw
2026.2.25+
MEDIUM 5.5
CVE-2026-32044
OpenClaw versions prior to 2026.3.2 contain an archive extraction vulnerability in the tar.bz2 installer path that bypasses safety checks enforced on…
Openclaw
2026.3.2+
CRITICAL 9.9
CVE-2026-22172
OpenClaw versions prior to 2026.3.12 contain an authorization bypass vulnerability in the WebSocket connect path that allows shared-token or password…
Openclaw
2026.3.12+
HIGH 7.8
CVE-2026-32041
OpenClaw versions prior to 2026.3.1 fail to properly handle authentication bootstrap errors during startup, allowing browser-control routes to remain…
Openclaw
2026.3.1+
MEDIUM 6.5
CVE-2026-32039
OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in the toolsBySender group policy matching that allows attackers t…
Openclaw
2026.2.22+
MEDIUM 6.1
CVE-2026-32040
OpenClaw versions prior to 2026.2.23 contain an html injection vulnerability in the HTML session exporter that allows attackers to execute arbitrary …
Openclaw
2026.2.23+
CRITICAL 9.0
CVE-2026-32038
OpenClaw before 2026.2.24 contains a sandbox network isolation bypass vulnerability that allows trusted operators to join another container's network…
Openclaw
2026.2.24+
HIGH 8.2
CVE-2026-32036
OpenClaw gateway plugin versions prior to 2026.2.26 contain a path traversal vulnerability that allows remote attackers to bypass route authenticatio…
Openclaw
2026.2.6+
HIGH 8.1
CVE-2026-32034
OpenClaw versions prior to 2026.2.21 contain an authentication bypass vulnerability in the Control UI when allowInsecureAuth is explicitly enabled an…
Openclaw
2026.2.21+
HIGH 7.1
CVE-2026-32035
OpenClaw versions prior to 2026.3.2 fail to pass the senderIsOwner flag when processing Discord voice transcripts in agentCommand, causing the flag t…
Openclaw
2026.3.2+
MEDIUM 6.5
CVE-2026-32037
OpenClaw versions prior to 2026.2.22 fail to consistently validate redirect chains against configured mediaAllowHosts allowlists during MSTeams media…
Openclaw
2026.2.22+
HIGH 7.8
CVE-2026-32032
OpenClaw versions prior to 2026.2.22 contain an arbitrary shell execution vulnerability in shell environment fallback that trusts the unvalidated SHE…
Openclaw
2026.2.22+
HIGH 7.5
CVE-2026-32030
OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the stageSandboxMedia function that accepts arbitrary absolute paths w…
Openclaw
2026.2.19+
MEDIUM 6.5
CVE-2026-32031
OpenClaw versions prior to 2026.2.26 server-http contains an authentication bypass vulnerability in gateway authentication for plugin channel endpoin…
Openclaw
2026.2.26+
MEDIUM 6.5
CVE-2026-32033
OpenClaw versions prior to 2026.2.24 contain a path traversal vulnerability where @-prefixed absolute paths bypass workspace-only file-system boundar…
Openclaw
2026.2.24+