6.9

CVSS4.0

CVE-2026-41335 - OpenClaw < 2026.3.31 - Information Disclosure via Control UI Bootstrap JSON

OpenClaw before 2026.3.31 contains an information disclosure vulnerability in the Control Interface bootstrap JSON that exposes version and assistant agent identifiers. Attackers can extract sensitive fingerprinting information from the Control UI bootstrap payload to identify system versions and a…

πŸ“… Published: April 23, 2026, 9:57 p.m. πŸ”„ Last Modified: April 25, 2026, 1:33 a.m.

7.1

CVSS4.0

CVE-2026-41334 - OpenClaw < 2026.3.31 - Decompression Bomb Denial of Service via Image Pixel-Limit Guard Bypass

OpenClaw before 2026.3.31 contains a decompression bomb vulnerability in image processing that fails to properly enforce pixel-limit guards on sips. Attackers can exploit this by uploading oversized images to cause denial of service through excessive memory consumption.

πŸ“… Published: April 23, 2026, 9:57 p.m. πŸ”„ Last Modified: April 24, 2026, 4:41 p.m.

6.3

CVSS4.0

CVE-2026-41333 - OpenClaw < 2026.3.31 - Authentication Rate Limiting Bypass via Fake DeviceToken

OpenClaw before 2026.3.31 contains an authentication rate limiting bypass vulnerability that allows attackers to circumvent shared authentication protections using fake device tokens. Attackers can exploit the mixed WebSocket authentication flow to bypass rate limiting controls and conduct brute fo…

πŸ“… Published: April 23, 2026, 9:57 p.m. πŸ”„ Last Modified: April 23, 2026, 9:57 p.m.

5.8

CVSS4.0

CVE-2026-41332 - OpenClaw < 2026.3.28 - Code Execution via Missing Environment Variable Blocklist

OpenClaw before 2026.3.28 contains an environment variable sanitization vulnerability where GIT_TEMPLATE_DIR and AWS_CONFIG_FILE are not blocked in the host-env blocklist. Attackers can exploit approved exec requests to redirect git or AWS CLI behavior through attacker-controlled configuration file…

πŸ“… Published: April 23, 2026, 9:57 p.m. πŸ”„ Last Modified: April 24, 2026, 6:19 p.m.

8

CVSS3.1

CVE-2026-32172 - Microsoft Power Apps Remote Code Execution Vulnerability

Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network.

πŸ“… Published: April 23, 2026, 9:37 p.m. πŸ”„ Last Modified: April 24, 2026, 2:55 p.m.

10

CVSS3.1

CVE-2026-35431 - Microsoft Entra ID Entitlement Management Spoofing Vulnerability

Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network.

πŸ“… Published: April 23, 2026, 9:37 p.m. πŸ”„ Last Modified: April 24, 2026, 2:55 p.m.

9.6

CVSS3.1

CVE-2026-24303 - Microsoft Partner Center Elevation of Privilege Vulnerability

Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.

πŸ“… Published: April 23, 2026, 9:37 p.m. πŸ”„ Last Modified: April 24, 2026, 6:19 p.m.

8.6

CVSS3.1

CVE-2026-26150 - Microsoft Purview eDiscovery Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

πŸ“… Published: April 23, 2026, 9:37 p.m. πŸ”„ Last Modified: April 24, 2026, 2:55 p.m.

10

CVSS3.1

CVE-2026-33819 - Microsoft Bing Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.

πŸ“… Published: April 23, 2026, 9:35 p.m. πŸ”„ Last Modified: April 24, 2026, 3:05 p.m.

9.3

CVSS3.1

CVE-2026-33102 - Microsoft 365 Copilot Elevation of Privilege Vulnerability

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

πŸ“… Published: April 23, 2026, 9:35 p.m. πŸ”„ Last Modified: April 24, 2026, 6:19 p.m.
Total resulsts: 346554
Page 36 of 34,656
Β« previous page Β» next page
Filters