Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.3
CVE-2026-62195
OpenClaw versions 2026.5.20 before 2026.6.6 contain an authorization bypass vulnerability in the MCP loopback feature that allows lower-trust callers…
Openclaw
2026.6.6+
HIGH 8.3
CVE-2026-62196
OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowl…
Openclaw
2026.6.6+
MEDIUM 5.4
CVE-2026-62198
OpenClaw versions 2026.5.28 before 2026.6.6 contain an authorization bypass vulnerability in native web search that allows lower-trust callers to per…
Openclaw
2026.6.6+
HIGH 8.8
CVE-2026-62190
OpenClaw versions before 2026.6.9 contain an authorization bypass vulnerability in the flock wrapper that allows lower-trust callers to execute or pe…
Openclaw
2026.6.9+
HIGH 8.8
CVE-2026-62194
OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install commands that allows lower-trust callers t…
Openclaw
2026.6.9+
HIGH 8.1
CVE-2026-62192
OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in Discord guild actions that allows lower-trust callers to …
Openclaw
2026.6.9+
HIGH 7.1
CVE-2026-62189
OpenClaw versions before 2026.6.9 contain a symlink following vulnerability in the mirror sync feature that allows lower-trust callers to perform act…
Openclaw
2026.6.9+
HIGH 7.1
CVE-2026-62191
OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message mutation handling that allows lower-trust callers…
Openclaw
2026.6.9+
MEDIUM 6.5
CVE-2026-62193
OpenClaw versions 2026.6.5 before 2026.6.9 contain a vulnerability in the plugin install wrappers that could skip the install policy (authorization) …
Openclaw
2026.6.9+
HIGH 8.1
CVE-2026-62187
OpenClaw Feishu tools (npm package @openclaw/feishu) in versions <= 2026.6.6 could ignore per-account disablement. A lower-trust caller or a configur…
Openclaw\/feishu
2026.6.9+
HIGH 8.1
CVE-2026-62188
OpenClaw @openclaw/feishu versions 2026.6.6 and earlier contain an incorrect authorization vulnerability in which the Feishu permission tools could i…
Openclaw\/feishu
2026.6.9+
HIGH 7.6
CVE-2026-62186
OpenClaw versions before 2026.6.8 contain an authorization bypass vulnerability in OpenAI-compatible HTTP model overrides that allows lower-trust cal…
Openclaw
2026.6.8+
MEDIUM 6.5
CVE-2026-59261
OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provider credentials. Attackers with…
Openclaw
2026.5.28+
HIGH 8.1
CVE-2026-53866
OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing that allows authenticated operators to execute u…
Openclaw
2026.5.12+
CRITICAL 9.8
CVE-2026-53861
OpenClaw before 2026.5.6 contains an allowlist bypass vulnerability in the macOS Swift exec feature that misses combined POSIX inline-command flags. …
Openclaw
2026.5.6+
HIGH 8.1
CVE-2026-53864
OpenClaw before 2026.5.26 contains an insufficient sanitization vulnerability in the host environment sanitizer that allows Node.js control variables…
Openclaw
2026.5.26+
HIGH 7.1
CVE-2026-53865
OpenClaw before 2026.5.2 contains a path traversal vulnerability in maintenance task execution that allows workspace-derived service paths to influen…
Openclaw
2026.5.26+
MEDIUM 6.5
CVE-2026-53863
OpenClaw before 2026.4.25 contains an input validation vulnerability in tool group policy callers that accept unvalidated group IDs. Attackers who ca…
Openclaw
2026.4.25+
MEDIUM 5.4
CVE-2026-53862
OpenClaw before 2026.5.12 contains a bootstrap token replay vulnerability allowing callers with pending token access to reuse tokens with broader req…
Openclaw
2026.5.12+
HIGH 8.1
CVE-2026-53857
OpenClaw before 2026.5.3 contains a policy enforcement vulnerability where Zalo contacts with mutable display metadata could match allowFrom policy e…
Openclaw
2026.5.3+
HIGH 7.1
CVE-2026-53858
OpenClaw before 2026.5.2 contains an environment variable injection vulnerability where workspace .env STATE_DIRECTORY could influence bundled runtim…
Openclaw
2026.5.2+
MEDIUM 6.5
CVE-2026-53859
OpenClaw before 2026.5.26 contains a hostname validation vulnerability allowing attackers to bypass blocklist comparisons using trailing-dot notation…
Openclaw
2026.5.26+
MEDIUM 5.5
CVE-2026-53856
OpenClaw 2026.4.23 before 2026.4.24 contains an insecure file permissions vulnerability in config recovery that restores OpenClaw.json with overly br…
Openclaw
Mitigation only
MEDIUM 5.4
CVE-2026-53860
OpenClaw before 2026.5.7 contains a sender policy bypass vulnerability in BlueBubbles that allows participants to match allowlist entries through con…
Openclaw
2026.5.7+
HIGH 8.3
CVE-2026-53853
OpenClaw before 2026.5.12 contains an argument pattern validation bypass in the exec allowlist that allows attackers to execute disallowed arguments …
Openclaw
2026.5.12+
HIGH 8.1
CVE-2026-53849
OpenClaw before 2026.5.7 contains a privilege escalation vulnerability where the allowFrom feature improperly validates Discord account identity usin…
Openclaw
2026.5.7+
HIGH 8.1
CVE-2026-53855
OpenClaw before 2026.4.2 contains an inline-eval bypass vulnerability allowing authenticated operators to weaken strict allowlist checks via shell po…
Openclaw
2026.4.2+
MEDIUM 6.5
CVE-2026-53854
OpenClaw before 2026.4.25 contains a privilege escalation vulnerability in internal and webchat command authentication that allows senders to inherit…
Openclaw
2026.4.25+
MEDIUM 5.5
CVE-2026-53850
OpenClaw before 2026.4.25 contains a control scope enforcement bypass vulnerability in the focus command that allows authenticated callers to execute…
Openclaw
2026.4.25+
MEDIUM 5.4
CVE-2026-53852
OpenClaw before 2026.4.25 contains a scope containment bypass vulnerability in device re-pairing that allows authenticated operators to restore broad…
Openclaw
2026.4.25+