5.8

CVSS4.0

CVE-2026-41332 - OpenClaw < 2026.3.28 - Code Execution via Missing Environment Variable Blocklist

OpenClaw before 2026.3.28 contains an environment variable sanitization vulnerability where GIT_TEMPLATE_DIR and AWS_CONFIG_FILE are not blocked in the host-env blocklist. Attackers can exploit approved exec requests to redirect git or AWS CLI behavior through attacker-controlled configuration file…

πŸ“… Published: April 23, 2026, 9:57 p.m. πŸ”„ Last Modified: April 24, 2026, 6:19 p.m.

8

CVSS3.1

CVE-2026-32172 - Microsoft Power Apps Remote Code Execution Vulnerability

Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network.

πŸ“… Published: April 23, 2026, 9:37 p.m. πŸ”„ Last Modified: April 24, 2026, 2:55 p.m.

10

CVSS3.1

CVE-2026-35431 - Microsoft Entra ID Entitlement Management Spoofing Vulnerability

Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network.

πŸ“… Published: April 23, 2026, 9:37 p.m. πŸ”„ Last Modified: April 24, 2026, 2:55 p.m.

9.6

CVSS3.1

CVE-2026-24303 - Microsoft Partner Center Elevation of Privilege Vulnerability

Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.

πŸ“… Published: April 23, 2026, 9:37 p.m. πŸ”„ Last Modified: April 25, 2026, 3:55 a.m.

8.6

CVSS3.1

CVE-2026-26150 - Microsoft Purview eDiscovery Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

πŸ“… Published: April 23, 2026, 9:37 p.m. πŸ”„ Last Modified: April 24, 2026, 2:55 p.m.

10

CVSS3.1

CVE-2026-33819 - Microsoft Bing Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.

πŸ“… Published: April 23, 2026, 9:35 p.m. πŸ”„ Last Modified: April 24, 2026, 3:05 p.m.

9.3

CVSS3.1

CVE-2026-33102 - Microsoft 365 Copilot Elevation of Privilege Vulnerability

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

πŸ“… Published: April 23, 2026, 9:35 p.m. πŸ”„ Last Modified: April 25, 2026, 3:55 a.m.

9.3

CVSS3.1

CVE-2026-32210 - Microsoft Dynamics 365 (online) Spoofing Vulnerability

Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network.

πŸ“… Published: April 23, 2026, 9:35 p.m. πŸ”„ Last Modified: April 25, 2026, 3:55 a.m.

9.3

CVSS4.0

CVE-2026-26210 - KTransformers Unsafe Deserialization RCE via balance_serve

KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where the scheduler RPC server binds a ZMQ ROUTER socket to all interfaces with no authentication and deserializes incoming messages using pickle.loads() without validation. Attackers can …

πŸ“… Published: April 23, 2026, 9:24 p.m. πŸ”„ Last Modified: April 23, 2026, 10:16 p.m.

9.3

CVSS4.0

CVE-2026-41274 - Flowise: Cypher Injection in GraphCypherQAChain

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GraphCypherQAChain node forwards user-provided input directly into the Cypher query execution pipeline without proper sanitization. An attacker can inject arbitrary Cypher commands that are …

πŸ“… Published: April 23, 2026, 9:12 p.m. πŸ”„ Last Modified: April 27, 2026, 9:30 p.m.
Total resulsts: 346810
Page 62 of 34,681
Β« previous page Β» next page
Filters