6.3

CVSS4.0

CVE-2026-41333 - OpenClaw < 2026.3.31 - Authentication Rate Limiting Bypass via Fake DeviceToken

OpenClaw before 2026.3.31 contains an authentication rate limiting bypass vulnerability that allows attackers to circumvent shared authentication protections using fake device tokens. Attackers can exploit the mixed WebSocket authentication flow to bypass rate limiting controls and conduct brute fo…

πŸ“… Published: April 23, 2026, 9:57 p.m. πŸ”„ Last Modified: April 24, 2026, 2:40 p.m.

5.8

CVSS4.0

CVE-2026-41332 - OpenClaw < 2026.3.28 - Code Execution via Missing Environment Variable Blocklist

OpenClaw before 2026.3.28 contains an environment variable sanitization vulnerability where GIT_TEMPLATE_DIR and AWS_CONFIG_FILE are not blocked in the host-env blocklist. Attackers can exploit approved exec requests to redirect git or AWS CLI behavior through attacker-controlled configuration file…

πŸ“… Published: April 23, 2026, 9:57 p.m. πŸ”„ Last Modified: April 24, 2026, 6:19 p.m.

8

CVSS3.1

CVE-2026-32172 - Microsoft Power Apps Remote Code Execution Vulnerability

Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network.

πŸ“… Published: April 23, 2026, 9:37 p.m. πŸ”„ Last Modified: April 24, 2026, 2:55 p.m.

10

CVSS3.1

CVE-2026-35431 - Microsoft Entra ID Entitlement Management Spoofing Vulnerability

Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network.

πŸ“… Published: April 23, 2026, 9:37 p.m. πŸ”„ Last Modified: April 24, 2026, 2:55 p.m.

9.6

CVSS3.1

CVE-2026-24303 - Microsoft Partner Center Elevation of Privilege Vulnerability

Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.

πŸ“… Published: April 23, 2026, 9:37 p.m. πŸ”„ Last Modified: April 24, 2026, 6:19 p.m.

8.6

CVSS3.1

CVE-2026-26150 - Microsoft Purview eDiscovery Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

πŸ“… Published: April 23, 2026, 9:37 p.m. πŸ”„ Last Modified: April 24, 2026, 2:55 p.m.

10

CVSS3.1

CVE-2026-33819 - Microsoft Bing Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.

πŸ“… Published: April 23, 2026, 9:35 p.m. πŸ”„ Last Modified: May 5, 2026, 2:15 p.m.

9.3

CVSS3.1

CVE-2026-33102 - Microsoft 365 Copilot Elevation of Privilege Vulnerability

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

πŸ“… Published: April 23, 2026, 9:35 p.m. πŸ”„ Last Modified: April 24, 2026, 6:19 p.m.

9.3

CVSS3.1

CVE-2026-32210 - Microsoft Dynamics 365 (online) Spoofing Vulnerability

Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network.

πŸ“… Published: April 23, 2026, 9:35 p.m. πŸ”„ Last Modified: May 5, 2026, 2:10 p.m.

9.3

CVSS4.0

CVE-2026-26210 - KTransformers Unsafe Deserialization RCE via balance_serve

KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where the scheduler RPC server binds a ZMQ ROUTER socket to all interfaces with no authentication and deserializes incoming messages using pickle.loads() without validation. Attackers can …

πŸ“… Published: April 23, 2026, 9:24 p.m. πŸ”„ Last Modified: May 5, 2026, 2:43 p.m.
Total resulsts: 349182
Page 297 of 34,919
Β« previous page Β» next page
Filters