6

CVSS4.0

CVE-2026-41366 - OpenClaw < 2026.3.31 - Arbitrary Host File Read via appendLocalMediaParentRoots Self-Whitelisting

OpenClaw before 2026.3.31 contains a local roots self-whitelisting vulnerability in appendLocalMediaParentRoots that allows model-initiated arbitrary host file read. Attackers can exploit improper media parent directory validation to exfiltrate credentials and access sensitive files.

πŸ“… Published: April 27, 2026, 11:24 p.m. πŸ”„ Last Modified: April 28, 2026, 2:45 p.m.

5.3

CVSS4.0

CVE-2026-41365 - OpenClaw < 2026.3.31 - Sender Allowlist Bypass via Graph API Thread History

OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability in MS Teams thread history fetched via Graph API. Attackers can retrieve thread messages that should be filtered by sender allowlists, bypassing message filtering restrictions.

πŸ“… Published: April 27, 2026, 11:24 p.m. πŸ”„ Last Modified: April 28, 2026, 1:55 p.m.

7.2

CVSS4.0

CVE-2026-41364 - OpenClaw < 2026.3.31 - Arbitrary File Write via Symlink Following in SSH Sandbox Tar Upload

OpenClaw before 2026.3.31 contains a symlink following vulnerability in SSH sandbox tar upload that allows remote attackers to write arbitrary files. Attackers can exploit this by uploading tar archives containing symlinks to escape the sandbox and overwrite files on the remote host.

πŸ“… Published: April 27, 2026, 11:24 p.m. πŸ”„ Last Modified: April 29, 2026, 2:05 p.m.

6

CVSS4.0

CVE-2026-41363 - OpenClaw 2026.2.6 < 2026.3.28 - Arbitrary File Read via Feishu upload_image Parameter

OpenClaw versions 2026.2.6 through 2026.3.24 contain a path traversal vulnerability in the Feishu extension resolveUploadInput function that bypasses file-system sandbox restrictions. Attackers can exploit improper path resolution during upload_image operations to read arbitrary files outside confi…

πŸ“… Published: April 27, 2026, 11:24 p.m. πŸ”„ Last Modified: April 28, 2026, 3:01 p.m.

2.3

CVSS4.0

CVE-2026-41362 - OpenClaw 2026.2.19 < 2026.3.31 - Webhook Replay Dedupe Cache Event Suppression via Shared Authentic…

OpenClaw versions 2026.2.19 before 2026.3.31 contain an improper cache isolation vulnerability in the Zalo webhook replay-dedupe mechanism that is shared across authenticated webhook targets. Attackers controlling one authenticated Zalo webhook path in multi-account deployments can suppress legitim…

πŸ“… Published: April 27, 2026, 11:24 p.m. πŸ”„ Last Modified: April 28, 2026, 1 p.m.

7.5

CVSS3.1

CVE-2026-40972 - Timing Attack on Spring Boot Remote Secret Comparison Enables Remote Code Execution

An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme circumstances this could result in the attacker determining the secret and uploading changed classes, thereby achieving remote code execution …

πŸ“… Published: April 27, 2026, 11:15 p.m. πŸ”„ Last Modified: April 30, 2026, 2:26 p.m.

6.9

CVSS4.0

CVE-2026-7199 - SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection

A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=delete_product. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attac…

πŸ“… Published: April 27, 2026, 11:15 p.m. πŸ”„ Last Modified: April 28, 2026, 2:48 p.m.

5.3

CVSS4.0

CVE-2026-7196 - CodeAstro Online Classroom guestdetails sql injection

A security vulnerability has been detected in CodeAstro Online Classroom 1.0. Affected is an unknown function of the file /guestdetails. Such manipulation of the argument deleteid leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be use…

πŸ“… Published: April 27, 2026, 11 p.m. πŸ”„ Last Modified: April 28, 2026, 2:35 p.m.

5

CVSS3.1

CVE-2026-40971 - Hostname Verification Bypass in Spring Boot RabbitMQ SSL Connections

When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitMQ broker. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14) per vendor advisory.

πŸ“… Published: April 27, 2026, 10:45 p.m. πŸ”„ Last Modified: April 28, 2026, 1 p.m.

6.9

CVSS4.0

CVE-2026-7194 - SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection

A weakness has been identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts an unknown function of the file /ajax.php?action=save_product. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been ma…

πŸ“… Published: April 27, 2026, 10:45 p.m. πŸ”„ Last Modified: April 28, 2026, 1 p.m.
Total resulsts: 347810
Page 99 of 34,781
Β« previous page Β» next page
Filters