Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.6
CVE-2026-44116
OpenClaw before 2026.4.22 contains a server-side request forgery vulnerability in the Zalo plugin's sendPhoto function that fails to validate outboun…
Openclaw
2026.4.22+
HIGH 7.8
CVE-2026-44114
OpenClaw before 2026.4.20 fails to properly reserve the OPENCLAW_ runtime-control environment namespace in workspace dotenv files, allowing attackers…
Openclaw
2026.4.20+
HIGH 7.8
CVE-2026-44118
OpenClaw before 2026.4.22 derives loopback MCP owner context from spoofable server-issued bearer tokens in request headers. Non-owner loopback client…
Openclaw
2026.4.22+
HIGH 7.7
CVE-2026-44113
OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in the OpenShell filesystem bridge that allows attackers to read files …
Openclaw
2026.4.22+
MEDIUM 5.8
CVE-2026-44117
OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in QQBot direct media upload that skips URL validation. Attackers can …
Openclaw
2026.4.20+
CRITICAL 9.8
CVE-2026-43585
OpenClaw before 2026.4.15 captures resolved bearer-auth configuration at startup, allowing revoked tokens to remain valid after SecretRef rotation. G…
Openclaw
2026.4.15+
CRITICAL 9.8
CVE-2026-44109
OpenClaw before 2026.4.15 contains an authentication bypass vulnerability in Feishu webhook and card-action validation that allows unauthenticated re…
Openclaw
2026.4.15+
HIGH 8.8
CVE-2026-43584
OpenClaw before 2026.4.10 contains an insufficient environment variable denylist vulnerability in its exec environment policy that allows operator-su…
Openclaw
2026.4.10+
HIGH 8.8
CVE-2026-44110
OpenClaw before 2026.4.15 contains an authorization bypass vulnerability in Matrix room control-command authorization that trusts DM pairing-store en…
Openclaw
2026.4.15+
MEDIUM 6.5
CVE-2026-43583
OpenClaw versions 2026.4.10 before 2026.4.14 fail to persist session context during delivery queue recovery for media replay. Attackers can exploit r…
Openclaw
2026.4.14+
MEDIUM 6.3
CVE-2026-43582
OpenClaw before 2026.4.10 contains a server-side request forgery vulnerability in browser navigation policy that allows attackers to bypass hostname …
Openclaw
2026.4.10+
CRITICAL 9.8
CVE-2026-43575
OpenClaw versions 2026.2.21 before 2026.4.10 contain an authentication bypass vulnerability in the sandbox noVNC helper route that exposes interactiv…
Openclaw
2026.4.10+
CRITICAL 9.6
CVE-2026-43581
OpenClaw before 2026.4.10 contains an improper network binding vulnerability in the sandbox browser CDP relay that exposes Chrome DevTools Protocol o…
Openclaw
2026.4.10+
CRITICAL 9.1
CVE-2026-43578
OpenClaw versions 2026.3.31 before 2026.4.10 contain a privilege escalation vulnerability where heartbeat owner downgrade detection misses local back…
Openclaw
2026.4.10+
HIGH 7.7
CVE-2026-43576
OpenClaw before 2026.4.5 contains a server-side request forgery vulnerability in the CDP /json/version WebSocket endpoint that allows attackers to pi…
Openclaw
2026.4.5+
HIGH 7.7
CVE-2026-43580
OpenClaw before 2026.4.10 contains an incomplete navigation guard vulnerability that allows attackers to trigger navigation without complete SSRF pol…
Openclaw
2026.4.10+
MEDIUM 6.5
CVE-2026-43577
OpenClaw before 2026.4.9 contains a file read vulnerability allowing attackers to bypass navigation guards through browser act/evaluate interactions.…
Openclaw
2026.4.9+
MEDIUM 6.5
CVE-2026-43579
OpenClaw before 2026.4.10 contains an insufficient access control vulnerability in Nostr plugin HTTP profile routes that allows operators with write …
Openclaw
2026.4.10+
HIGH 7.7
CVE-2026-43573
OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in existing-session browser interaction routes. Attacker…
Openclaw
2026.4.10+
MEDIUM 6.5
CVE-2026-43574
OpenClaw before 2026.4.12 contains an improper authorization vulnerability in helper-backed channels where empty resolved approver lists are interpre…
Openclaw
2026.4.12+
MEDIUM 5.3
CVE-2026-43572
OpenClaw versions 2026.4.10 before 2026.4.14 contain a missing authorization vulnerability in the Microsoft Teams SSO invoke handler that fails to ap…
Openclaw
2026.4.14+
CRITICAL 9.8
CVE-2026-43566
OpenClaw versions 2026.4.7 before 2026.4.14 contain a privilege escalation vulnerability where heartbeat owner downgrade logic skips webhook wake eve…
Openclaw
2026.4.14+
HIGH 8.8
CVE-2026-43569
OpenClaw before 2026.4.9 contains an authentication bypass vulnerability allowing untrusted workspace plugins to be auto-enabled during non-interacti…
Openclaw
2026.4.9+
HIGH 8.8
CVE-2026-43571
OpenClaw before 2026.4.10 contains a plugin trust bypass vulnerability that allows channel setup catalog lookups to resolve workspace plugin shadows …
Openclaw
2026.4.10+
MEDIUM 6.5
CVE-2026-43567
OpenClaw before 2026.4.10 contains a path traversal vulnerability in the screen_record tool's outPath parameter that bypasses workspace-only filesyst…
Openclaw
2026.4.10+
MEDIUM 6.5
CVE-2026-43568
OpenClaw versions 2026.4.5 before 2026.4.10 contain a privilege escalation vulnerability allowing write-scoped operators to modify persistent memory …
Openclaw
2026.4.10+
MEDIUM 6.5
CVE-2026-43570
OpenClaw versions 2026.3.22 before 2026.4.5 contain a symlink traversal vulnerability in remote marketplace repository path handling that allows atta…
Openclaw
2026.4.5+
CRITICAL 9.8
CVE-2026-43534
OpenClaw before 2026.4.10 contains an input validation vulnerability that allows external hook metadata to be enqueued as trusted system events. Atta…
Openclaw
2026.4.10+
HIGH 8.8
CVE-2026-43530
OpenClaw versions 2026.2.23 before 2026.4.12 contain a weakened exec approval binding vulnerability in busybox and toybox applet execution that allow…
Openclaw
2026.4.12+
HIGH 8.8
CVE-2026-43531
OpenClaw before 2026.4.9 contains an environment variable injection vulnerability allowing malicious workspace .env files to set runtime-control vari…
Openclaw
2026.4.9+