Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

Vulnerability List - Page 6

Found 480 results
CVE IDTitleVendorProductSeverityCVSS ScorePublished AtAI Analysis
CVE-2026-41402 OpenClaw < 2026.3.31 - Webhook Replay Cache Cross-Target messageId Scope Bypass OpenClawOpenClaw Medium 4.2 2026-04-28 18:09:59 Deep Dive
CVE-2026-41400 OpenClaw < 2026.3.31 - Resource Consumption via Oversized WebSocket Frames in voice-call OpenClawOpenClaw Medium 5.3 2026-04-28 18:09:59 Deep Dive
CVE-2026-41399 OpenClaw < 2026.3.28 - Denial of Service via Unbounded Pre-auth WebSocket Upgrades OpenClawOpenClaw High 7.5 2026-04-28 18:09:58 Deep Dive
CVE-2026-41398 OpenClaw - Unauthorized Agent Request Dispatch via Untrusted Local-Network Pages in iOS A2UI Bridge OpenClawOpenClaw Medium 4.6 2026-04-28 18:09:57 Deep Dive
CVE-2026-41397 OpenClaw < 2026.3.31 - Sandbox Escape via Unrestricted File Sync and Symlink Traversal OpenClawOpenClaw Medium 6.8 2026-04-28 18:09:56 Deep Dive
CVE-2026-41396 OpenClaw < 2026.3.31 - Environment Variable Override of Plugin Trust Root OpenClawOpenClaw High 7.8 2026-04-28 18:09:56 Deep Dive
CVE-2026-41395 OpenClaw < 2026.3.28 - Webhook Replay via Query Parameter Reordering in Plivo V3 OpenClawOpenClaw High 7.5 2026-04-28 18:09:55 Deep Dive
CVE-2026-41394 OpenClaw < 2026.3.31 - Unauthorized Operator Scope Access in Unauthenticated Plugin-Auth Routes OpenClawOpenClaw High 8.2 2026-04-28 18:09:54 Deep Dive
CVE-2026-41393 OpenClaw < 2026.3.31 - Arbitrary DNS Authority Acceptance and Credential Exfiltration via Wide-Area Discovery OpenClawOpenClaw Medium 4.8 2026-04-28 18:09:53 Deep Dive
CVE-2026-41392 OpenClaw < 2026.3.31 - Exec Allowlist Bypass via Shell Init-File Options OpenClawOpenClaw Medium 6.7 2026-04-28 18:09:53 Deep Dive
CVE-2026-41391 OpenClaw < 2026.3.31 - Environment Variable Bypass in Package Index URL Handling OpenClawOpenClaw Medium 5.3 2026-04-28 18:09:52 Deep Dive
CVE-2026-41390 OpenClaw < 2026.3.28 - Exec Allowlist Bypass via Unregistered /usr/bin/script Wrapper OpenClawOpenClaw High 7.3 2026-04-28 18:09:51 Deep Dive
CVE-2026-41388 OpenClaw < 2026.3.31 - Configuration Rehydration via Empty-Array Revocation Handling OpenClawOpenClaw Medium 6.5 2026-04-28 18:09:50 Deep Dive
CVE-2026-41387 OpenClaw < 2026.3.22 - Supply Chain Redirection via Incomplete Host Environment Sanitization OpenClawOpenClaw High 7.8 2026-04-28 18:09:50 Deep Dive
CVE-2026-41386 OpenClaw < 2026.3.22 - Privilege Escalation via Unbound Bootstrap Setup Codes OpenClawOpenClaw Critical 9.1 2026-04-28 18:09:49 Deep Dive
CVE-2026-41385 OpenClaw < 2026.3.31 - Nostr Private Key Exposure via config.get Redaction Bypass OpenClawOpenClaw Medium 6.5 2026-04-28 18:09:48 Deep Dive
CVE-2026-41384 OpenClaw < 2026.3.24 - Environment Variable Injection via Workspace Config in CLI Backend OpenClawOpenClaw High 7.8 2026-04-28 18:09:47 Deep Dive
CVE-2026-41383 OpenClaw < 2026.4.2 - Arbitrary Remote Directory Deletion via Mis-scoped Mirror Mode Paths OpenClawOpenClaw High 8.1 2026-04-28 18:09:46 Deep Dive
CVE-2026-41382 OpenClaw < 2026.3.31 - Discord Voice Ingress Authorization Bypass via Channel and Role Validation Gaps OpenClawOpenClaw Medium 5.4 2026-04-28 18:09:45 Deep Dive
CVE-2026-41381 OpenClaw < 2026.3.31 - Access Control Bypass in Discord Voice Manager via Channel Allowlist OpenClawOpenClaw Medium 5.4 2026-04-28 18:09:44 Deep Dive