|
701
|
7.8 |
HIGH
Local
|
deepcool
|
deepcreative
|
Insecure Permissions vulnerability in DeepCool DeepCreative v.1.2.12 and before allows a local attacker to execute arbitrary code via a crafted file
Update
|
CWE-277
Insecure Inherited Permissions
|
CVE-2026-30266
|
2026-04-28 01:42 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
702
|
6.3 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.3.31 contains a server-side request forgery vulnerability in the marketplace plugin download functionality that allows remote attackers to make arbitrary network requests. Attack…
Update
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-41302
|
2026-04-28 00:26 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
703
|
9.9 |
CRITICAL
Network
|
doorman
|
doorman
|
Improper access control in Doorman v0.1.0 and v1.0.2 allows any authenticated user to update their own account role to a non-admin privileged role via /platform/user/{username}. The `role` field is a…
Update
|
CWE-269
Improper Privilege Management
|
CVE-2026-30269
|
2026-04-28 00:24 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
704
|
8.2 |
HIGH
Network
|
ultradag
|
ultradag
|
UltraDAG is a minimal DAG-BFT blockchain in Rust. In version 0.1, a non-council attacker can submit a signed SmartOp::Vote transaction that passes signature, nonce, and balance prechecks, but fails a…
Update
|
CWE-460 CWE-696
Improper Cleanup on Thrown Exception Incorrect Behavior Order
|
CVE-2026-40583
|
2026-04-28 00:23 |
2026-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
705
|
8.8 |
HIGH
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in Discord text approval commands that allows non-approvers to resolve pending exec approvals. Attackers can send Discord text…
Update
|
CWE-863
Incorrect Authorization
|
CVE-2026-41303
|
2026-04-28 00:20 |
2026-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
706
|
- |
|
-
|
-
|
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accid…
New
|
-
|
CVE-2026-6337
|
2026-04-28 00:16 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
707
|
9.8 |
CRITICAL
Network
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
mptcp: fix slab-use-after-free in __inet_lookup_established
The ehash table lookups are lockless and rely on
SLAB_TYPESAFE_BY_RCU…
Update
|
-
|
CVE-2026-31669
|
2026-04-28 00:16 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
708
|
9.8 |
CRITICAL
Network
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
seg6: separate dst_cache for input and output paths in seg6 lwtunnel
The seg6 lwtunnel uses a single dst_cache per encap route, s…
Update
|
-
|
CVE-2026-31668
|
2026-04-28 00:16 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
709
|
7.8 |
HIGH
Local
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
Input: uinput - fix circular locking dependency with ff-core
A lockdep circular locking dependency warning can be triggered
repro…
Update
|
-
|
CVE-2026-31667
|
2026-04-28 00:16 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
710
|
7.8 |
HIGH
Local
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref()
After commit 1618aa3c2e01 ("btrfs: simplify ret…
Update
|
-
|
CVE-2026-31666
|
2026-04-28 00:16 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|