|
991
|
9.4 |
CRITICAL
Network
|
apache
|
camel
|
The Camel-Mail component is vulnerable to Camel message header injection. The custom header filter strategy used by the component (MailHeaderFilterStrategy) only filters the 'out' direction via setOu…
Update
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-33454
|
2026-04-29 04:42 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
992
|
8.2 |
HIGH
Network
|
apache
|
camel
|
When authentication is enabled on the Apache Camel embedded HTTP server or embedded management server (camel-platform-http-main) and a non-root context path such as /api or /admin is configured via c…
Update
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-40022
|
2026-04-29 04:41 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
993
|
8.8 |
HIGH
Network
|
apache
|
camel
|
The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.ObjectInputStream without applying any ObjectInput…
Update
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-40858
|
2026-04-29 04:41 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
994
|
6.5 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.4.20 contains a scope enforcement bypass vulnerability in the assistant-media route that allows trusted-proxy callers without operator.read scope to access protected assistant-me…
Update
|
CWE-863
Incorrect Authorization
|
CVE-2026-41908
|
2026-04-29 04:41 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
995
|
5.4 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.4.20 contains an improper authorization vulnerability in paired-device pairing management that allows limited-scope sessions to enumerate and act on pairing requests. Attackers w…
Update
|
CWE-863
Incorrect Authorization
|
CVE-2026-41909
|
2026-04-29 04:40 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
996
|
10.0 |
CRITICAL
Network
|
apache
|
camel
|
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component.
Apache Camel's camel-coap component is vulnerable to Camel message …
Update
|
CWE-915
Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2026-33453
|
2026-04-29 04:39 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
997
|
7.5 |
HIGH
Network
|
marked_project
|
marked
|
Marked is a markdown parser and compiler. From 18.0.0 to 18.0.1, a critical Denial of Service (DoS) vulnerability exists in marked. By providing a specific 3-byte input sequence a tab, a vertical tab…
Update
|
CWE-400 CWE-674 CWE-835
Uncontrolled Resource Consumption Uncontrolled Recursion Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-41680
|
2026-04-29 04:37 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
998
|
4.3 |
MEDIUM
Network
|
rocket.chat
|
rocket.chat
|
In versions <8.4.0, <8.3.2, <8.2.2, <8.1.3, <8.0.4, <7.13.6, <7.12.7, <7.11.7, and <7.10.10, the endpoints /api/apps/logs and /api/apps/:id/logs have a typo in the required permission check, allowing…
Update
|
CWE-284
Improper Access Control
|
CVE-2026-29197
|
2026-04-29 04:34 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
999
|
5.3 |
MEDIUM
Network
|
opentelemetry
|
opentelemetry opentelemetry.api opentelemetry.extensions.propagators
|
OpenTelemetry dotnet is a dotnet telemetry framework. In OpenTelemetry.Api 0.5.0-beta.2 to 1.15.2 and OpenTelemetry.Extensions.Propagators 1.3.1 to 1.15.2, The implementation details of the baggage, …
Update
|
CWE-789
Memory Allocation with Excessive Size Value
|
CVE-2026-40894
|
2026-04-29 04:34 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1000
|
7.5 |
HIGH
Network
|
senselive
|
x3500_firmware
|
A vulnerability in SenseLive X3050’s management ecosystem allows unauthenticated discovery of deployed units through the vendor’s management protocol, enabling identification of device presence, iden…
Update
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-35064
|
2026-04-29 04:33 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|