Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

Vulnerability List - Page 3

Found 480 results
CVE IDTitleVendorProductSeverityCVSS ScorePublished AtAI Analysis
CVE-2026-43583 OpenClaw 2026.4.10 < 2026.4.14 - Loss of Group Tool-Policy Context in Delivery Queue Recovery OpenClawOpenClaw Medium 5.3 2026-05-06 19:49:25 Deep Dive
CVE-2026-43582 OpenClaw < 2026.4.10 - DNS Rebinding SSRF via Hostname Validation Bypass OpenClawOpenClaw Medium 6.3 2026-05-06 19:49:25 Deep Dive
CVE-2026-43581 OpenClaw < 2026.4.10 - Chrome DevTools Protocol Exposure via Overly Broad CDP Relay Binding OpenClawOpenClaw Critical 9.6 2026-05-06 19:49:24 Deep Dive
CVE-2026-43580 OpenClaw < 2026.4.10 - Incomplete Navigation Guard Coverage in Browser Interactions OpenClawOpenClaw High 7.7 2026-05-06 19:49:23 Deep Dive
CVE-2026-43579 OpenClaw < 2026.4.10 - Insufficient Access Control in Nostr Profile Mutation Routes OpenClawOpenClaw Medium 6.5 2026-05-06 19:49:23 Deep Dive
CVE-2026-43578 OpenClaw 2026.3.31 < 2026.4.10 - Privilege Escalation via Missed Async Exec Completion Events in Heartbeat Owner Downgrade OpenClawOpenClaw Critical 9.1 2026-05-06 19:49:22 Deep Dive
CVE-2026-43577 OpenClaw < 2026.4.9 - Arbitrary File Read via Browser Interaction Routes OpenClawOpenClaw Medium 6.5 2026-05-06 19:49:21 Deep Dive
CVE-2026-43576 OpenClaw < 2026.4.5 - Second-hop SSRF via CDP /json/version WebSocket URL OpenClawOpenClaw High 7.7 2026-05-06 19:49:20 Deep Dive
CVE-2026-43575 OpenClaw 2026.2.21 < 2026.4.10 - Authentication Bypass in Sandbox noVNC Helper Route OpenClawOpenClaw Critical 9.8 2026-05-06 19:49:20 Deep Dive
CVE-2026-43574 OpenClaw < 2026.4.12 - Improper Authorization via Empty Approver Lists OpenClawOpenClaw Medium 6.5 2026-05-05 11:25:14 Deep Dive
CVE-2026-43573 OpenClaw < 2026.4.10 - SSRF Policy Bypass in Existing-Session Browser Interaction Routes OpenClawOpenClaw High 7.7 2026-05-05 11:25:13 Deep Dive
CVE-2026-43571 OpenClaw < 2026.4.10 - Untrusted Workspace Plugin Shadow Resolution in Channel Setup OpenClawOpenClaw High 8.8 2026-05-05 11:25:12 Deep Dive
CVE-2026-43572 OpenClaw 2026.4.10 < 2026.4.14 - Missing Sender Authorization in Microsoft Teams SSO Invoke Handler OpenClawOpenClaw Medium 5.3 2026-05-05 11:25:12 Deep Dive
CVE-2026-43570 OpenClaw 2026.3.22 < 2026.4.5 - Symlink Traversal in Remote Marketplace Repository Path Handling OpenClawOpenClaw Medium 6.5 2026-05-05 11:25:11 Deep Dive
CVE-2026-43569 OpenClaw < 2026.4.9 - Untrusted Provider Plugin Auto-enablement via Workspace Provider Auth OpenClawOpenClaw High 8.8 2026-05-05 11:25:10 Deep Dive
CVE-2026-43568 OpenClaw 2026.4.5 through 2026.4.9 - Privilege Escalation via Memory Dreaming Configuration in /dreaming Endpoint OpenClawOpenClaw Medium 6.5 2026-05-05 11:25:10 Deep Dive
CVE-2026-43567 OpenClaw < 2026.4.10 - Path Traversal in screen_record outPath Parameter OpenClawOpenClaw Medium 6.5 2026-05-05 11:25:09 Deep Dive
CVE-2026-43566 OpenClaw 2026.4.7 < 2026.4.14 - Privilege Escalation via Untrusted Webhook Wake Events OpenClawOpenClaw Critical 9.1 2026-05-05 11:25:08 Deep Dive
CVE-2026-43534 OpenClaw < 2026.4.10 - Unsanitized External Input in Agent Hook Events OpenClawOpenClaw Critical 9.1 2026-05-05 11:25:07 Deep Dive
CVE-2026-43535 OpenClaw < 2026.4.14 - Authorization Context Reuse in Collect-Mode Queue Batches OpenClawOpenClaw Medium 6.8 2026-05-05 11:25:07 Deep Dive