CVE Vulnerability Database
Search and browse 398,382 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-43569 | HIGH | 8.8 | 0.4% | May 5, 2026 | OpenClaw before 2026.4.9 contains an authentication bypass vulnerability allowing untrusted workspace plugins to be auto... |
| CVE-2026-43568 | HIGH | 7.1 | 0.2% | May 5, 2026 | OpenClaw versions 2026.4.5 before 2026.4.10 contain a privilege escalation vulnerability allowing write-scoped operators... |
| CVE-2026-43567 | HIGH | 7.1 | 0.2% | May 5, 2026 | OpenClaw before 2026.4.10 contains a path traversal vulnerability in the screen_record tool's outPath parameter that byp... |
| CVE-2026-43566 | CRITICAL | 9.8 | 0.4% | May 5, 2026 | OpenClaw versions 2026.4.7 before 2026.4.14 contain a privilege escalation vulnerability where heartbeat owner downgrade... |
| CVE-2026-43535 | HIGH | 8.1 | 0.2% | May 5, 2026 | OpenClaw before 2026.4.14 contains an authorization context reuse vulnerability in collect-mode queue batches that allow... |
| CVE-2026-43534 | CRITICAL | 9.8 | 0.2% | May 5, 2026 | OpenClaw before 2026.4.10 contains an input validation vulnerability that allows external hook metadata to be enqueued a... |
| CVE-2026-43533 | HIGH | 8.9 | 0.4% | May 5, 2026 | OpenClaw before 2026.4.10 contains an arbitrary file read vulnerability in QQBot media tags that allows attackers to ref... |
| CVE-2026-43532 | HIGH | 7.7 | 0.3% | May 5, 2026 | OpenClaw versions 2026.4.7 before 2026.4.10 fail to normalize Discord event cover image parameters in sandbox media proc... |
| CVE-2026-43531 | HIGH | 8.8 | 0.2% | May 5, 2026 | OpenClaw before 2026.4.9 contains an environment variable injection vulnerability allowing malicious workspace .env file... |
| CVE-2026-43530 | HIGH | 8.8 | 0.4% | May 5, 2026 | OpenClaw versions 2026.2.23 before 2026.4.12 contain a weakened exec approval binding vulnerability in busybox and toybo... |
| CVE-2026-43529 | LOW | 2.5 | 0.1% | May 5, 2026 | OpenClaw before 2026.4.10 contains a time-of-check-time-of-use vulnerability in the validateScriptFileForShellBleed func... |
| CVE-2026-43528 | HIGH | 7.1 | 0.3% | May 5, 2026 | OpenClaw before 2026.4.14 contains a redaction bypass vulnerability that allows authenticated gateway clients to receive... |
| CVE-2026-43527 | HIGH | 7.7 | 0.3% | May 5, 2026 | OpenClaw before 2026.4.14 contains a server-side request forgery vulnerability in browser SSRF policy that allows privat... |
| CVE-2026-43526 | CRITICAL | 9.3 | 0.3% | May 5, 2026 | OpenClaw before 2026.4.12 contains a server-side request forgery vulnerability in QQBot reply media URL handling that al... |
| CVE-2026-42439 | HIGH | 8.5 | 0.2% | May 5, 2026 | OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in the browser tabs action ... |
| CVE-2026-42438 | HIGH | 7.7 | 0.2% | May 5, 2026 | OpenClaw versions 2026.4.9 before 2026.4.10 contain a sender policy bypass vulnerability in the outbound host-media atta... |
| CVE-2026-42437 | HIGH | 8.2 | 0.4% | May 5, 2026 | OpenClaw versions 2026.4.9 before 2026.4.10 contain a denial of service vulnerability in the voice-call realtime WebSock... |
| CVE-2026-42436 | HIGH | 7.7 | 0.3% | May 5, 2026 | OpenClaw before 2026.4.14 contains an improper access control vulnerability in browser snapshot, screenshot, and tab rou... |
| CVE-2026-42435 | HIGH | 8.8 | 0.4% | May 5, 2026 | OpenClaw versions from 2026.2.22 before 2026.4.12 contain an insufficient shell-wrapper detection vulnerability allowing... |
| CVE-2026-42434 | HIGH | 8.8 | 0.3% | May 5, 2026 | OpenClaw versions 2026.4.5 before 2026.4.10 contain a sandbox escape vulnerability allowing sandboxed agents to override... |
| CVE-2026-42433 | HIGH | 7.1 | 0.3% | May 5, 2026 | OpenClaw before 2026.4.10 contains an authorization bypass vulnerability allowing operator.write message-tool paths to a... |
| CVE-2023-54349 | MEDIUM | 6.1 | 0.3% | May 5, 2026 | AmazCart CMS 3.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject... |
| CVE-2023-54348 | HIGH | 8.8 | 0.4% | May 5, 2026 | ERPGo SaaS 3.9 contains a CSV injection vulnerability that allows authenticated attackers to inject spreadsheet formulas... |
| CVE-2023-54347 | HIGH | 8.7 | 0.5% | May 5, 2026 | OpenEMR 7.0.1 contains an authentication brute force vulnerability that allows attackers to bypass rate limiting protect... |
| CVE-2023-54346 | HIGH | 8.7 | 0.3% | May 5, 2026 | WordPress Plugin Backup Migration 1.2.8 contains an information disclosure vulnerability that allows unauthenticated att... |
