4.9

CVSS3.1

CVE-2026-34267 - mysql: Optimizer unspecified vulnerability (CPU Apr 2026)

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attac…

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 23, 2026, 3:06 p.m.

4.9

CVSS3.1

CVE-2026-22002 - mysql: Optimizer unspecified vulnerability (CPU Apr 2026)

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise M…

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 23, 2026, 3:04 p.m.

8.4

CVSS3.1

CVE-2026-35570 - OpenClaude has Sandbox Bypass via Early-Exit Logic Flaw that Allows Path Traversal

OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Versions prior to 0.5.1 have a logic flaw in `bashToolHasPermission()` inside `src/tools/BashTool/bashPermissions.ts`. When the sandbox auto-allow feature is active and no explicit deny rule is con…

πŸ“… Published: April 20, 2026, 11:24 p.m. πŸ”„ Last Modified: April 23, 2026, 6:37 p.m.

6.3

CVSS3.1

CVE-2026-35588 - Glances has CQL Injection in its Cassandra Export Module via Unsanitized Config Values

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Cassandra export module (`glances/exports/glances_cassandra/__init__.py`) interpolates `keyspace`, `table`, and `replication_factor` configuration values directly into CQL statements without validation. A u…

πŸ“… Published: April 20, 2026, 11:20 p.m. πŸ”„ Last Modified: April 22, 2026, 6:40 p.m.

7.3

CVSS4.0

CVE-2026-35587 - Glances IP Plugin has SSRF via public_api that leads to credential leakage

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, a Server-Side Request Forgery (SSRF) vulnerability exists in the Glances IP plugin due to improper validation of the public_api configuration parameter. The value of public_api is used directly in outbound HTTP…

πŸ“… Published: April 20, 2026, 11:19 p.m. πŸ”„ Last Modified: April 23, 2026, 6:42 p.m.

7.7

CVSS4.0

CVE-2026-34839 - Glances Vulnerable to Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due…

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Glances web server exposes a REST API (`/api/4/*`) that is accessible without authentication and allows cross-origin requests from any origin due to a permissive CORS policy (`Access-Control-Allow-Origin: *…

πŸ“… Published: April 20, 2026, 11:09 p.m. πŸ”„ Last Modified: April 24, 2026, 7:09 p.m.

6.9

CVSS4.0

CVE-2026-41331 - OpenClaw < 2026.3.31 - Resource Consumption via Unauthorized Telegram Audio Preflight Transcription

OpenClaw before 2026.3.31 contains a resource consumption vulnerability in Telegram audio preflight transcription that allows unauthorized group senders to trigger transcription processing. Attackers can exploit insufficient allowlist enforcement to cause resource or billing consumption by initiati…

πŸ“… Published: April 20, 2026, 11:08 p.m. πŸ”„ Last Modified: April 21, 2026, 8:27 p.m.

2

CVSS4.0

CVE-2026-41330 - OpenClaw < 2026.3.31 - Environment Variable Override via Host Exec Policy

OpenClaw before 2026.3.31 contains an environment variable override vulnerability in host exec policy that fails to properly enforce proxy, TLS, Docker, and Git TLS controls. Attackers can bypass security controls by overriding environment variables to circumvent proxy settings, TLS verification, D…

πŸ“… Published: April 20, 2026, 11:08 p.m. πŸ”„ Last Modified: April 21, 2026, 4:20 p.m.

9

CVSS4.0

CVE-2026-41329 - OpenClaw < 2026.3.31 - Sandbox Bypass via Heartbeat Context Inheritance and senderIsOwner Escalation

OpenClaw before 2026.3.31 contains a sandbox bypass vulnerability allowing attackers to escalate privileges via heartbeat context inheritance and senderIsOwner parameter manipulation. Attackers can exploit improper context validation to bypass sandbox restrictions and achieve unauthorized privilege…

πŸ“… Published: April 20, 2026, 11:08 p.m. πŸ”„ Last Modified: April 22, 2026, 6 a.m.

8.7

CVSS4.0

CVE-2026-41303 - OpenClaw < 2026.3.28 - Authorization Bypass in Discord Text Approval Commands

OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in Discord text approval commands that allows non-approvers to resolve pending exec approvals. Attackers can send Discord text commands to bypass the channels.discord.execApprovals.approvers allowlist and approve pending host …

πŸ“… Published: April 20, 2026, 11:08 p.m. πŸ”„ Last Modified: April 21, 2026, 4:20 p.m.
Total resulsts: 346618
Page 125 of 34,662
Β« previous page Β» next page
Filters