|
411
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A Server-Side Request Forgery (SSRF) in the /plugins/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-36757
|
2026-05-1 03:16 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
412
|
5.4 |
MEDIUM
Network
|
-
|
-
|
A Server-Side Request Forgery (SSRF) in the /plugins/-/install-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-36756
|
2026-05-1 03:16 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
413
|
8.1 |
HIGH
Network
|
-
|
-
|
An issue in Krayin CRM v.2.1.5 and fixed in v.2.1.6 allows a remote attacker to execute arbitrary code via the compose email function
New
|
CWE-94
Code Injection
|
CVE-2026-36340
|
2026-05-1 03:16 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
414
|
7.5 |
HIGH
Network
|
-
|
-
|
A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This…
New
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2026-33845
|
2026-05-1 03:16 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
415
|
8.8 |
HIGH
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.3.31 contains an incomplete scope-clearing vulnerability in trusted-proxy authentication mode that allows operator.admin privilege escalation. Attackers can exploit this by decla…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-41404
|
2026-05-1 02:41 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
416
|
4.0 |
MEDIUM
Local
|
openclaw
|
openclaw
|
OpenClaw before 2026.3.31 misclassifies proxied remote requests as loopback connections in the diffs viewer when allowRemoteViewer is disabled, allowing unauthorized access. Attackers can bypass acce…
New
|
CWE-807
Reliance on Untrusted Inputs in a Security Decision
|
CVE-2026-41403
|
2026-05-1 02:40 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
417
|
5.4 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.3.31 contains a scope bypass vulnerability in webhook replay cache deduplication that allows authenticated attackers to replay messages across sibling targets using the same mess…
New
|
CWE-706
Use of Incorrectly-Resolved Name or Reference
|
CVE-2026-41402
|
2026-05-1 02:27 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
418
|
7.5 |
HIGH
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.3.31 contains an incomplete fix for CVE-2026-32062 where the voice-call component parses large WebSocket frames before start validation. Remote attackers can send oversized pre-s…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-41400
|
2026-05-1 02:27 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
419
|
- |
|
-
|
-
|
Improper Restriction of XML External Entity Reference vulnerability in Connext Professional (Core Libraries) allows Serialized Data External Linking.This issue affects Connext Professional: from 7.4.…
New
|
CWE-611
XXE
|
CVE-2025-14543
|
2026-05-1 02:20 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
420
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Bypass.
This issue affects MOVEit Automation: from 2025.0.0 before 2025.0.9, from…
New
|
CWE-305
Authentication Bypass by Primary Weakness
|
CVE-2026-4670
|
2026-05-1 02:20 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|