CVE Vulnerability Database

Search and browse 398,143 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-44115HIGH8.8OpenClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted ...
CVE-2026-44114HIGH8.5OpenClaw before 2026.4.20 fails to properly reserve the OPENCLAW_ runtime-control environment namespace in workspace dot...
CVE-2026-44113HIGH8.3OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in the OpenShell filesystem bridge that al...
CVE-2026-44112CRITICAL9.6OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in OpenShell sandbox filesystem writes tha...
CVE-2026-44111MEDIUM4.3OpenClaw before 2026.4.15 contains an arbitrary file read vulnerability in the QMD backend memory_get function that allo...
CVE-2026-44110HIGH8.8OpenClaw before 2026.4.15 contains an authorization bypass vulnerability in Matrix room control-command authorization th...
CVE-2026-44109CRITICAL9.8OpenClaw before 2026.4.15 contains an authentication bypass vulnerability in Feishu webhook and card-action validation t...
CVE-2026-43585CRITICAL9.8OpenClaw before 2026.4.15 captures resolved bearer-auth configuration at startup, allowing revoked tokens to remain vali...
CVE-2026-43584HIGH8.8OpenClaw before 2026.4.10 contains an insufficient environment variable denylist vulnerability in its exec environment p...
CVE-2026-43583MEDIUM6.5OpenClaw versions 2026.4.10 before 2026.4.14 fail to persist session context during delivery queue recovery for media re...
CVE-2026-43582MEDIUM6.3OpenClaw before 2026.4.10 contains a server-side request forgery vulnerability in browser navigation policy that allows ...
CVE-2026-43581CRITICAL9.6OpenClaw before 2026.4.10 contains an improper network binding vulnerability in the sandbox browser CDP relay that expos...
CVE-2026-43580HIGH7.7OpenClaw before 2026.4.10 contains an incomplete navigation guard vulnerability that allows attackers to trigger navigat...
CVE-2026-43579MEDIUM6.5OpenClaw before 2026.4.10 contains an insufficient access control vulnerability in Nostr plugin HTTP profile routes that...
CVE-2026-43578CRITICAL9.1OpenClaw versions 2026.3.31 before 2026.4.10 contain a privilege escalation vulnerability where heartbeat owner downgrad...
CVE-2026-43577HIGH7.1OpenClaw before 2026.4.9 contains a file read vulnerability allowing attackers to bypass navigation guards through brows...
CVE-2026-43576HIGH7.7OpenClaw before 2026.4.5 contains a server-side request forgery vulnerability in the CDP /json/version WebSocket endpoin...
CVE-2026-43575CRITICAL9.8OpenClaw versions 2026.2.21 before 2026.4.10 contain an authentication bypass vulnerability in the sandbox noVNC helper ...
CVE-2026-40326HIGH7.1Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the createBundle method in ...
CVE-2026-40325HIGH8.7Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the `cTrash.restore` functi...
CVE-2026-40309HIGH7.2Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the cTrash.empty function d...
CVE-2026-40174HIGH7.1Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the cUsers.updateAddress fu...
CVE-2026-40171HIGH8.4In Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions 4.5.6 and earlier, and the corresponding @jupyter-...
CVE-2026-40076HIGH8.8OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8...
CVE-2026-33441——Rejected reason: This CVE is a duplicate of another CVE: CVE-2026-33079.