6.5

CVSS3.1

CVE-2026-34276 - mysql: Group Replication Plugin unspecified vulnerability (CPU Apr 2026)

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols t…

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 23, 2026, 3:05 p.m.

9.8

CVSS3.1

CVE-2026-38835 - Command Injection Vulnerability in Tenda W30E via formSetUSBPartitionUmount

Tenda W30E V2.0 V16.01.0.21 was found to contain a command injection vulnerability in the formSetUSBPartitionUmount function via the usbPartitionName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 22, 2026, 9:24 p.m.

8.4

CVSS3.1

CVE-2026-40706 - NTFS-3G SUID-root Heap Buffer Overflow Enables Privilege Escalation

In NTFS-3G 2022.10.3 before 2026.2.25, a heap buffer overflow exists in ntfs_build_permissions_posix() in acls.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow is triggered on the READ path (stat, readdir, open) when p…

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 22, 2026, 9:23 p.m.

8.8

CVSS3.1

CVE-2025-70420 - SQL Injection in Genesys Latitude Enabling Arbitrary Database Access

A SQL injection vulnerability exists in Genesys Latitude v25.1.0.420 that allows an authenticated attacker to execute arbitrary SQL queries against the backend database. The vulnerability is caused by unsanitized user-supplied input being concatenated directly into SQL statements.

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 22, 2026, 9:24 p.m.

4.9

CVSS3.1

CVE-2026-35234 - mysql: Partition unspecified vulnerability (CPU Apr 2026)

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Partition). Supported versions that are affected are 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attack…

πŸ“… Published: April 21, 2026, midnight πŸ”„ Last Modified: April 23, 2026, 3:10 p.m.

8.4

CVSS3.1

CVE-2026-35570 - OpenClaude has Sandbox Bypass via Early-Exit Logic Flaw that Allows Path Traversal

OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Versions prior to 0.5.1 have a logic flaw in `bashToolHasPermission()` inside `src/tools/BashTool/bashPermissions.ts`. When the sandbox auto-allow feature is active and no explicit deny rule is con…

πŸ“… Published: April 20, 2026, 11:24 p.m. πŸ”„ Last Modified: April 23, 2026, 6:37 p.m.

6.3

CVSS3.1

CVE-2026-35588 - Glances has CQL Injection in its Cassandra Export Module via Unsanitized Config Values

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Cassandra export module (`glances/exports/glances_cassandra/__init__.py`) interpolates `keyspace`, `table`, and `replication_factor` configuration values directly into CQL statements without validation. A u…

πŸ“… Published: April 20, 2026, 11:20 p.m. πŸ”„ Last Modified: April 22, 2026, 6:40 p.m.

7.3

CVSS4.0

CVE-2026-35587 - Glances IP Plugin has SSRF via public_api that leads to credential leakage

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, a Server-Side Request Forgery (SSRF) vulnerability exists in the Glances IP plugin due to improper validation of the public_api configuration parameter. The value of public_api is used directly in outbound HTTP…

πŸ“… Published: April 20, 2026, 11:19 p.m. πŸ”„ Last Modified: April 23, 2026, 6:42 p.m.

7.7

CVSS4.0

CVE-2026-34839 - Glances Vulnerable to Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due…

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Glances web server exposes a REST API (`/api/4/*`) that is accessible without authentication and allows cross-origin requests from any origin due to a permissive CORS policy (`Access-Control-Allow-Origin: *…

πŸ“… Published: April 20, 2026, 11:09 p.m. πŸ”„ Last Modified: April 24, 2026, 7:09 p.m.

6.9

CVSS4.0

CVE-2026-41331 - OpenClaw < 2026.3.31 - Resource Consumption via Unauthorized Telegram Audio Preflight Transcription

OpenClaw before 2026.3.31 contains a resource consumption vulnerability in Telegram audio preflight transcription that allows unauthorized group senders to trigger transcription processing. Attackers can exploit insufficient allowlist enforcement to cause resource or billing consumption by initiati…

πŸ“… Published: April 20, 2026, 11:08 p.m. πŸ”„ Last Modified: April 21, 2026, 8:27 p.m.
Total resulsts: 346802
Page 143 of 34,681
Β« previous page Β» next page
Filters