CVE Vulnerability Database
Search and browse 398,143 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44115 | HIGH | 8.8 | 0.4% | May 6, 2026 | OpenClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted ... |
| CVE-2026-44114 | HIGH | 8.5 | 0.1% | May 6, 2026 | OpenClaw before 2026.4.20 fails to properly reserve the OPENCLAW_ runtime-control environment namespace in workspace dot... |
| CVE-2026-44113 | HIGH | 8.3 | 0.2% | May 6, 2026 | OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in the OpenShell filesystem bridge that al... |
| CVE-2026-44112 | CRITICAL | 9.6 | 2.4% | May 6, 2026 | OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in OpenShell sandbox filesystem writes tha... |
| CVE-2026-44111 | MEDIUM | 4.3 | 0.2% | May 6, 2026 | OpenClaw before 2026.4.15 contains an arbitrary file read vulnerability in the QMD backend memory_get function that allo... |
| CVE-2026-44110 | HIGH | 8.8 | 0.3% | May 6, 2026 | OpenClaw before 2026.4.15 contains an authorization bypass vulnerability in Matrix room control-command authorization th... |
| CVE-2026-44109 | CRITICAL | 9.8 | 0.7% | May 6, 2026 | OpenClaw before 2026.4.15 contains an authentication bypass vulnerability in Feishu webhook and card-action validation t... |
| CVE-2026-43585 | CRITICAL | 9.8 | 0.5% | May 6, 2026 | OpenClaw before 2026.4.15 captures resolved bearer-auth configuration at startup, allowing revoked tokens to remain vali... |
| CVE-2026-43584 | HIGH | 8.8 | 0.4% | May 6, 2026 | OpenClaw before 2026.4.10 contains an insufficient environment variable denylist vulnerability in its exec environment p... |
| CVE-2026-43583 | MEDIUM | 6.5 | 0.2% | May 6, 2026 | OpenClaw versions 2026.4.10 before 2026.4.14 fail to persist session context during delivery queue recovery for media re... |
| CVE-2026-43582 | MEDIUM | 6.3 | 0.2% | May 6, 2026 | OpenClaw before 2026.4.10 contains a server-side request forgery vulnerability in browser navigation policy that allows ... |
| CVE-2026-43581 | CRITICAL | 9.6 | 0.2% | May 6, 2026 | OpenClaw before 2026.4.10 contains an improper network binding vulnerability in the sandbox browser CDP relay that expos... |
| CVE-2026-43580 | HIGH | 7.7 | 0.3% | May 6, 2026 | OpenClaw before 2026.4.10 contains an incomplete navigation guard vulnerability that allows attackers to trigger navigat... |
| CVE-2026-43579 | MEDIUM | 6.5 | 0.2% | May 6, 2026 | OpenClaw before 2026.4.10 contains an insufficient access control vulnerability in Nostr plugin HTTP profile routes that... |
| CVE-2026-43578 | CRITICAL | 9.1 | 0.3% | May 6, 2026 | OpenClaw versions 2026.3.31 before 2026.4.10 contain a privilege escalation vulnerability where heartbeat owner downgrad... |
| CVE-2026-43577 | HIGH | 7.1 | 0.3% | May 6, 2026 | OpenClaw before 2026.4.9 contains a file read vulnerability allowing attackers to bypass navigation guards through brows... |
| CVE-2026-43576 | HIGH | 7.7 | 0.3% | May 6, 2026 | OpenClaw before 2026.4.5 contains a server-side request forgery vulnerability in the CDP /json/version WebSocket endpoin... |
| CVE-2026-43575 | CRITICAL | 9.8 | 0.4% | May 6, 2026 | OpenClaw versions 2026.2.21 before 2026.4.10 contain an authentication bypass vulnerability in the sandbox noVNC helper ... |
| CVE-2026-40326 | HIGH | 7.1 | 0.2% | May 6, 2026 | Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the createBundle method in ... |
| CVE-2026-40325 | HIGH | 8.7 | 0.2% | May 6, 2026 | Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the `cTrash.restore` functi... |
| CVE-2026-40309 | HIGH | 7.2 | 0.2% | May 6, 2026 | Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the cTrash.empty function d... |
| CVE-2026-40174 | HIGH | 7.1 | 0.2% | May 6, 2026 | Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the cUsers.updateAddress fu... |
| CVE-2026-40171 | HIGH | 8.4 | 0.5% | May 6, 2026 | In Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions 4.5.6 and earlier, and the corresponding @jupyter-... |
| CVE-2026-40076 | HIGH | 8.8 | 0.9% | May 6, 2026 | OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8... |
| CVE-2026-33441 | — | — | — | May 6, 2026 | Rejected reason: This CVE is a duplicate of another CVE: CVE-2026-33079. |
