Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.1
CVE-2026-41364
OpenClaw before 2026.3.31 contains a symlink following vulnerability in SSH sandbox tar upload that allows remote attackers to write arbitrary files.…
Openclaw
2026.3.31+
MEDIUM 6.5
CVE-2026-41363
OpenClaw versions 2026.2.6 through 2026.3.24 contain a path traversal vulnerability in the Feishu extension resolveUploadInput function that bypasses…
Openclaw
2026.3.28+
MEDIUM 5.5
CVE-2026-41366
OpenClaw before 2026.3.31 contains a local roots self-whitelisting vulnerability in appendLocalMediaParentRoots that allows model-initiated arbitrary…
Openclaw
2026.3.31+
MEDIUM 5.4
CVE-2026-41365
OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability in MS Teams thread history fetched via Graph API. Attackers can retrieve t…
Openclaw
2026.3.31+
MEDIUM 5.0
CVE-2026-41367
OpenClaw versions 2026.2.14 through 2026.3.24 fail to consistently apply guild and channel policy gates to Discord button and component interactions.…
Openclaw
2026.3.28+
HIGH 8.8
CVE-2026-41359
OpenClaw before 2026.3.28 contains a privilege escalation vulnerability allowing authenticated operators with write permissions to access admin-class…
Openclaw
2026.3.28+
HIGH 7.1
CVE-2026-41361
OpenClaw before 2026.3.28 contains an SSRF guard bypass vulnerability that fails to block four IPv6 special-use ranges. Attackers can exploit this by…
Openclaw
2026.3.28+
MEDIUM 6.7
CVE-2026-41360
OpenClaw before 2026.4.2 contains an approval integrity vulnerability in pnpm dlx that fails to bind local script operands consistently with pnpm exe…
Openclaw
2026.4.2+
MEDIUM 5.4
CVE-2026-41356
OpenClaw before 2026.3.31 fails to terminate active WebSocket sessions when rotating device tokens. Attackers with previously compromised credentials…
Openclaw
2026.3.31+
MEDIUM 5.4
CVE-2026-41358
OpenClaw before 2026.4.2 fails to filter Slack thread context by sender allowlist, allowing non-allowlisted messages to enter agent context. Attacker…
Openclaw
2026.4.2+
HIGH 8.8
CVE-2026-41352
OpenClaw before 2026.3.31 contains a remote code execution vulnerability where a device-paired node can bypass the node scope gate authentication mec…
Openclaw
2026.3.31+
HIGH 8.1
CVE-2026-41353
OpenClaw before 2026.3.22 contains an access control bypass vulnerability in the allowProfiles feature that allows attackers to circumvent profile re…
Openclaw
2026.3.22+
HIGH 7.3
CVE-2026-41355
OpenClaw before 2026.3.28 contains an arbitrary code execution vulnerability in mirror mode that converts untrusted sandbox files into workspace hook…
Openclaw
2026.3.28+
MEDIUM 5.3
CVE-2026-41351
OpenClaw before 2026.3.31 contains a replay detection bypass vulnerability in webhook signature handling that treats Base64 and Base64URL encoded sig…
Openclaw
2026.3.31+
MEDIUM 5.3
CVE-2026-41354
OpenClaw before 2026.4.2 contains an insufficient scope vulnerability in Zalo webhook replay dedupe keys that allows legitimate events from different…
Openclaw
2026.4.2+
HIGH 8.8
CVE-2026-41349
OpenClaw before 2026.3.28 contains an agentic consent bypass vulnerability allowing LLM agents to silently disable execution approval via config.patc…
Openclaw
2026.3.28+
HIGH 7.5
CVE-2026-41346
OpenClaw 2026.2.26 before 2026.3.31 enforces pending pairing-request caps per channel file instead of per account, allowing attackers to exhaust the …
Openclaw
2026.3.31+
HIGH 7.1
CVE-2026-41347
OpenClaw before 2026.3.31 lacks browser-origin validation in HTTP operator endpoints when operating in trusted-proxy mode, allowing cross-site reques…
Openclaw
2026.3.31+
MEDIUM 5.4
CVE-2026-41348
OpenClaw before 2026.3.31 contains an authorization bypass vulnerability in Discord slash command and autocomplete paths that fail to enforce group D…
Openclaw
2026.3.31+
MEDIUM 5.3
CVE-2026-41345
OpenClaw before 2026.3.31 contains a credential exposure vulnerability in media download functionality that forwards Authorization headers across cro…
Openclaw
2026.3.31+
HIGH 8.8
CVE-2026-41344
OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in the chat.send endpoint that allows write-scoped gateway callers to persist…
Openclaw
2026.3.28+
HIGH 8.1
CVE-2026-41342
OpenClaw before 2026.3.28 contains an authentication bypass vulnerability in the remote onboarding component that persists unauthenticated discovery …
Openclaw
2026.3.28+
MEDIUM 6.5
CVE-2026-41340
OpenClaw before 2026.3.31 contains an authentication boundary vulnerability where Telegram legacy allowFrom migration incorrectly fans default-accoun…
Openclaw
2026.3.31+
MEDIUM 5.4
CVE-2026-41341
OpenClaw before 2026.3.31 contains a logic error in Discord component interaction routing that misclassifies group direct messages as direct messages…
Openclaw
2026.3.31+
MEDIUM 5.3
CVE-2026-41343
OpenClaw before 2026.3.31 lacks a shared pre-auth concurrency budget on the public LINE webhook path, allowing attackers to cause transient availabil…
Openclaw
2026.3.31+
HIGH 7.8
CVE-2026-41336
OpenClaw before 2026.3.31 allows workspace .env files to override the OPENCLAW_BUNDLED_HOOKS_DIR environment variable, enabling loading of attacker-c…
Openclaw
2026.3.31+
MEDIUM 6.5
CVE-2026-41334
OpenClaw before 2026.3.31 contains a decompression bomb vulnerability in image processing that fails to properly enforce pixel-limit guards on sips. …
Openclaw
2026.3.31+
MEDIUM 5.3
CVE-2026-41335
OpenClaw before 2026.3.31 contains an information disclosure vulnerability in the Control Interface bootstrap JSON that exposes version and assistant…
Openclaw
2026.3.31+
MEDIUM 5.3
CVE-2026-41337
OpenClaw before 2026.3.31 contains a callback origin mutation vulnerability in Plivo voice-call replay that allows attackers to mutate in-process cal…
Openclaw
2026.3.31+
MEDIUM 5.0
CVE-2026-41338
OpenClaw before 2026.3.31 contains a time-of-check-time-of-use vulnerability in sandbox file operations that allows attackers to bypass fd-based defe…
Openclaw
2026.3.31+