|
1341
|
6.5 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.3.31 contains a path traversal vulnerability in ACP dispatch that allows attackers to read arbitrary files by manipulating inbound channel attachment paths. Remote attackers can …
|
CWE-22
Path Traversal
|
CVE-2026-41370
|
2026-04-29 03:41 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1342
|
7.5 |
HIGH
Network
|
apache
|
thrift
|
Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, w…
|
CWE-762
Mismatched Memory Management Routines
|
CVE-2025-48431
|
2026-04-29 03:40 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1343
|
7.5 |
HIGH
Network
|
apache
|
thrift
|
Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to versio…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-41602
|
2026-04-29 03:40 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1344
|
8.2 |
HIGH
Network
|
apache
|
thrift
|
Out-of-bounds Read vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
|
CWE-125
Out-of-bounds Read
|
CVE-2026-41604
|
2026-04-29 03:40 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1345
|
7.3 |
HIGH
Network
|
apache
|
thrift
|
Integer Overflow or Wraparound vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-41605
|
2026-04-29 03:39 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1346
|
5.3 |
MEDIUM
Network
|
apache
|
thrift
|
Uncontrolled Recursion vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
|
CWE-674
Uncontrolled Recursion
|
CVE-2026-41606
|
2026-04-29 03:39 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1347
|
6.5 |
MEDIUM
Network
|
apache
|
thrift
|
Out-of-bounds Read vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
|
CWE-125
Out-of-bounds Read
|
CVE-2026-41607
|
2026-04-29 03:39 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1348
|
7.5 |
HIGH
Network
|
apache
|
thrift
|
Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
|
CWE-674
Uncontrolled Recursion
|
CVE-2026-41636
|
2026-04-29 03:38 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1349
|
7.5 |
HIGH
Network
|
nds-association
|
zserio
|
Zserio is a framework for serializing structured data with a compact and efficient way with low overhead. Prior to 2.18.1, a crafted payload as small as 4-5 bytes can force memory allocations of up t…
|
CWE-789
Memory Allocation with Excessive Size Value
|
CVE-2026-33524
|
2026-04-29 03:33 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1350
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
firmware: arm_scmi: Fix NULL dereference on notify error path
Since commit b5daf93b809d1 ("firmware: arm_scmi: Avoid notifier
reg…
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-31544
|
2026-04-29 03:32 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|