|
471
|
8.1 |
HIGH
Network
|
senselive
|
x3500_firmware
|
A vulnerability in SenseLive X3050's web management interface allows critical system and network configuration parameters to be modified without sufficient validation and safety controls. Due to inad…
Update
|
CWE-862
Missing Authorization
|
CVE-2026-40623
|
2026-04-29 04:02 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
472
|
9.8 |
CRITICAL
Network
|
senselive
|
x3500_firmware
|
A vulnerability in
SenseLive
X3050’s web management interface allows unauthorized access to certain configuration endpoints due to improper access control enforcement. An attacker with network acc…
Update
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-40630
|
2026-04-29 04:01 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
473
|
9.8 |
CRITICAL
Network
|
huggingface
|
lerobot
|
LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.loads() is used to deserialize data received over unauthenticated gRPC channels wit…
Update
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-25874
|
2026-04-29 04:01 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
474
|
7.5 |
HIGH
Network
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
smb: server: make use of smbdirect_socket.recv_io.credits.available
The logic off managing recv credits by counting posted recv_i…
Update
|
NVD-CWE-Other
|
CVE-2026-31538
|
2026-04-29 03:59 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
475
|
9.8 |
CRITICAL
Network
|
std42
|
elfinder
|
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.67, elFinder contains a command injection vulnerability in the resize command. The bg (background …
Update
|
CWE-78
OS Command
|
CVE-2026-41247
|
2026-04-29 03:57 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
476
|
5.3 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.3.31 contains a replay detection bypass vulnerability in webhook signature handling that treats Base64 and Base64URL encoded signatures as distinct requests. Attackers can re-enc…
Update
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2026-41351
|
2026-04-29 03:56 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
477
|
4.3 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.3.31 contains a session visibility bypass vulnerability where the session_status function fails to enforce configured tools.sessions.visibility restrictions for unsandboxed invoc…
Update
|
CWE-863
Incorrect Authorization
|
CVE-2026-41350
|
2026-04-29 03:56 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
478
|
7.1 |
HIGH
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.3.31 lacks browser-origin validation in HTTP operator endpoints when operating in trusted-proxy mode, allowing cross-site request forgery attacks. Attackers can exploit this by s…
Update
|
CWE-352
Origin Validation Error
|
CVE-2026-41347
|
2026-04-29 03:56 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
479
|
5.3 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.3.31 contains a credential exposure vulnerability in media download functionality that forwards Authorization headers across cross-origin redirects. Attackers can exploit this by…
Update
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2026-41345
|
2026-04-29 03:56 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
480
|
5.3 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.3.31 lacks a shared pre-auth concurrency budget on the public LINE webhook path, allowing attackers to cause transient availability loss. Remote attackers can flood the webhook e…
Update
|
CWE-799
Improper Control of Interaction Frequency
|
CVE-2026-41343
|
2026-04-29 03:56 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|