|
501
|
6.5 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.3.28 contains an environment variable disclosure vulnerability in the jq safe-bin policy that fails to block the $ENV filter. Attackers can bypass safe-bin restrictions by using …
New
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2026-41368
|
2026-04-29 03:44 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
502
|
6.5 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.3.31 contains insufficient environment variable sanitization in host exec operations, failing to filter package, registry, Docker, compiler, and TLS override variables. Attackers…
New
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2026-41369
|
2026-04-29 03:44 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
503
|
8.5 |
HIGH
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.3.28 contains a privilege escalation vulnerability in chat.send that allows write-scoped gateway callers to trigger admin-only session reset operations. Attackers can rotate targ…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-41371
|
2026-04-29 03:44 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
504
|
5.8 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.4.2 fails to normalize trailing-dot localhost hosts in remote CDP discovery responses, allowing bypass of loopback protections. Attackers can craft hostile discovery responses re…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-41372
|
2026-04-29 03:43 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
505
|
8.8 |
HIGH
Network
|
jpcert
|
logontracer
|
An OS command Injection issue exists in LogonTracer prior to v2.0.0. An arbitrary OS command may be executed by a logged-in user.
Update
|
CWE-78
OS Command
|
CVE-2026-33277
|
2026-04-29 03:43 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
506
|
7.4 |
HIGH
Network
|
apache
|
thrift
|
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixe…
New
|
CWE-297 CWE-306
Improper Validation of Certificate with Host Mismatch Missing Authentication for Critical Function
|
CVE-2026-41603
|
2026-04-29 03:42 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
507
|
5.4 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability in MS Teams thread history fetched via Graph API. Attackers can retrieve thread messages that should be filtered by sender a…
New
|
CWE-441
Confused Deputy
|
CVE-2026-41365
|
2026-04-29 03:41 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
508
|
6.5 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.3.31 contains a path traversal vulnerability in ACP dispatch that allows attackers to read arbitrary files by manipulating inbound channel attachment paths. Remote attackers can …
New
|
CWE-22
Path Traversal
|
CVE-2026-41370
|
2026-04-29 03:41 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
509
|
7.5 |
HIGH
Network
|
apache
|
thrift
|
Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, w…
New
|
CWE-762
Mismatched Memory Management Routines
|
CVE-2025-48431
|
2026-04-29 03:40 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
510
|
7.5 |
HIGH
Network
|
apache
|
thrift
|
Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to versio…
New
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-41602
|
2026-04-29 03:40 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|