Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2026-53817
OpenClaw before 2026.5.22 contains a locality validation vulnerability in Control UI pairing that allows attackers with network access to spoof local…
Openclaw
2026.5.22+
HIGH 8.3
CVE-2026-53814
OpenClaw before 2026.5.20 contains a privilege escalation vulnerability where hook-triggered agent runs incorrectly receive owner-scoped MCP loopback…
Openclaw
2026.5.20+
HIGH 7.8
CVE-2026-53813
OpenClaw before 2026.4.25 contains a path traversal vulnerability in memory-core artifact loading where workspace state influences local package root…
Openclaw
2026.4.25+
HIGH 7.7
CVE-2026-53812
OpenClaw before 2026.5.18 contains a server-side request forgery vulnerability in browser control that allows authenticated users to bypass private-n…
Openclaw
2026.5.18+
HIGH 7.2
CVE-2026-53816
OpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event handling that allows paired nodes to forge exec …
Openclaw
2026.5.18+
MEDIUM 6.5
CVE-2026-53815
OpenClaw before 2026.5.19 contains an authorization bypass vulnerability in message read actions that skips channel allowlist checks. Lower-trust cal…
Openclaw
2026.5.19+
HIGH 8.8
CVE-2026-53806
OpenClaw before 2026.5.12 contains a shell option parsing vulnerability that allows combined POSIX shell flags to bypass exec revalidation checks. At…
Openclaw
2026.5.12+
HIGH 8.8
CVE-2026-53807
OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that allows authenticated users to skip com…
Openclaw
2026.5.6+
MEDIUM 6.5
CVE-2026-53808
OpenClaw before 2026.5.6 contains an approval policy bypass vulnerability in the Skill Workshop apply flow that allows agent tool calls to set apply:…
Openclaw
2026.5.6+
HIGH 8.8
CVE-2026-35674
OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped clients to execute privileged comma…
Openclaw
2026.5.18+
HIGH 8.0
CVE-2026-35630
OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to enforce configured approver i…
Openclaw
2026.5.18+
MEDIUM 6.5
CVE-2026-35673
OpenClaw before 2026.4.29 contains an SSRF policy bypass vulnerability in browser debug and export routes that allows reuse of already-open blocked t…
Openclaw
2026.4.29+
HIGH 8.3
CVE-2026-32905
OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows non-owner authorized chat sende…
Openclaw
2026.5.4+
MEDIUM 5.4
CVE-2026-34507
OpenClaw before 2026.4.29 contains a policy bypass vulnerability in QQBot admin commands that allows authenticated senders to skip DM-only and allowF…
Openclaw
2026.4.29+
CRITICAL 9.8
CVE-2026-8305
A vulnerability was detected in OpenClaw up to 2026.1.24. The impacted element is the function handleBlueBubblesWebhookRequest of the file extensions…
Openclaw
2026.2.12+
HIGH 8.8
CVE-2026-45006
OpenClaw before 2026.4.23 contains an improper access control vulnerability in the gateway tool's config.apply and config.patch operations that allow…
Openclaw
2026.4.23+
HIGH 7.8
CVE-2026-45004
OpenClaw before 2026.4.23 contains an arbitrary code execution vulnerability in the bundled plugin setup resolver that loads setup-api.js from proces…
Openclaw
2026.4.23+
HIGH 7.1
CVE-2026-45001
OpenClaw before 2026.4.20 contains a guard bypass vulnerability in the agent-facing gateway config.patch and config.apply endpoints that fails to pro…
Openclaw
2026.4.20+
MEDIUM 6.0
CVE-2026-45005
OpenClaw before 2026.4.23 caches resolved webhook route secrets backed by SecretRef values, allowing stale secrets to remain valid after rotation and…
Openclaw
2026.4.23+
MEDIUM 5.3
CVE-2026-45002
OpenClaw before 2026.4.20 contains a hook session-key bypass vulnerability that allows attackers to circumvent the hooks.allowRequestSessionKey opt-i…
Openclaw
2026.4.20+
MEDIUM 5.0
CVE-2026-45000
OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skips strict-mode SSRF policy che…
Openclaw
2026.4.20+
MEDIUM 5.0
CVE-2026-45003
OpenClaw before 2026.4.22 allows workspace dotenv files to override connector endpoint hosts for Matrix, Mattermost, IRC, and Synology connectors. At…
Openclaw
2026.4.22+
HIGH 7.3
CVE-2026-44995
OpenClaw before 2026.4.20 contains an improper environment variable validation vulnerability in MCP stdio server configuration that allows attackers …
Openclaw
2026.4.20+
MEDIUM 5.4
CVE-2026-44993
OpenClaw before 2026.4.20 contains a message classification vulnerability in Feishu card-action callbacks that misclassifies direct messages as group…
Openclaw
2026.4.20+
MEDIUM 5.4
CVE-2026-44998
OpenClaw before 2026.4.20 contains a tool policy bypass vulnerability allowing bundled MCP and LSP tools to circumvent configured tool restrictions. …
Openclaw
2026.4.20+
MEDIUM 5.3
CVE-2026-44994
OpenClaw before 2026.4.22 contains an authentication bypass vulnerability in the Control UI bootstrap config endpoint that allows unauthenticated att…
Openclaw
2026.4.22+
MEDIUM 5.3
CVE-2026-44999
OpenClaw before 2026.4.20 fails to properly preserve untrusted labels for isolated cron awareness events, allowing webhook-triggered cron agent outpu…
Openclaw
2026.4.20+
MEDIUM 5.0
CVE-2026-44992
OpenClaw versions 2026.4.5 before 2026.4.20 contain an environment variable injection vulnerability allowing workspace dotenv to override MINIMAX_API…
Openclaw
2026.4.20+
CRITICAL 9.6
CVE-2026-44112
OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in OpenShell sandbox filesystem writes that allows attackers to redirec…
Openclaw
2026.4.22+
HIGH 8.8
CVE-2026-44115
OpenClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted heredoc bodies. Attackers can…
Openclaw
2026.4.22+