Skip to main content

CWE archive

CWE-372 CVEs

Programmatic archive

9 CVEs tagged with CWE-3722 Critical, 2 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2026-41388

Published Apr 28, 2026

OpenClaw before 2026.3.31 contains a configuration management vulnerability where startup migration treats empty-array settings as missing values. Attackers can restart the applic…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-41340

Published Apr 23, 2026

OpenClaw before 2026.3.31 contains an authentication boundary vulnerability where Telegram legacy allowFrom migration incorrectly fans default-account trust into all named account…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-41300

Published Apr 21, 2026

OpenClaw before 2026.3.31 contains a trust-decline vulnerability that preserves attacker-discovered endpoints in remote onboarding flows. Attackers can route gateway credentials t…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2024-22590

Published May 28, 2024

The TLS engine in Kwik commit 745fd4e2 does not track the current state of the connection. This vulnerability can allow Client Hello messages to be overwritten at any time, includ…

CVSS 9.1 · Critical

CVE-2023-4012

Published Aug 7, 2023

ntpd will crash if the server is not NTS-enabled (no certificate) and it receives an NTS-enabled client request (mode 3).

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-31127

Published May 8, 2023

libspdm is a sample implementation that follows the DMTF SPDM specifications. A vulnerability has been identified in SPDM session establishment in libspdm prior to version 2.3.1.…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-25735

Published Sep 6, 2021

A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-27222

Published Feb 3, 2021

In Eclipse Californium version 2.3.0 to 2.6.0, the certificate based (x509 and RPK) DTLS handshakes accidentally fails, because the DTLS server side sticks to a wrong internal sta…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1