|
231
|
4.6 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.3.31 contains a fail-open vulnerability in the plugin installation flow where security scan failures do not block installation. Attackers can exploit scan failures to install unt…
New
|
CWE-636
Not Failing Securely ('Failing Open')
|
CVE-2026-41377
|
2026-05-2 00:50 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
232
|
6.5 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.3.31 contains an allowlist bypass vulnerability in Matrix thread root and reply context handling that fails to properly validate message senders. Attackers can fetch thread-root …
New
|
CWE-346
Origin Validation Error
|
CVE-2026-41376
|
2026-05-2 00:50 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
233
|
6.5 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.3.28 contains an authorization bypass vulnerability in the /phone arm and /phone disarm endpoints that fails to properly enforce operator.admin scope checks for external channels…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-41375
|
2026-05-2 00:47 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
234
|
6.1 |
MEDIUM
Local
|
openclaw
|
openclaw
|
OpenClaw before 2026.3.31 contains an incomplete host-env-security-policy.json that fails to restrict compiler binary environment variables, allowing untrusted models to substitute CC, CXX, CARGO_BUI…
New
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2026-41373
|
2026-05-2 00:46 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
235
|
- |
|
-
|
-
|
Assertion failure vulnerability in the PCO (Protocol Configuration Options) parser in the SMF (Session Management Function) component of Open5GS before v2.7.5 allows remote attackers to cause denial …
New
|
-
|
CVE-2025-56568
|
2026-05-2 00:37 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
236
|
- |
|
-
|
-
|
JS8Call through 2.3.1 and JS8Call-improved before 3.0 have a stack-based buffer overflow via a radio transmission of @APRSIS GRID followed by a long Maidenhead locator. This occurs in grid2deg in APR…
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-42996
|
2026-05-2 00:37 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
237
|
5.4 |
MEDIUM
Network
|
-
|
-
|
@diplodoc/search-extension 1.0.0 through 3.x before 3.0.3 allows stored XSS via the title in a .md file.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-40201
|
2026-05-2 00:37 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
238
|
- |
|
-
|
-
|
An issue in open5gs v.2.7.3 allows a remote attacker to cause a denial of service via a crafted PDU Session Modification Request
New
|
-
|
CVE-2025-46115
|
2026-05-2 00:34 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
239
|
4.8 |
MEDIUM
Network
|
-
|
-
|
In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data process…
New
|
CWE-909
Missing Initialization of Resource
|
CVE-2026-40687
|
2026-05-2 00:33 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
240
|
- |
|
-
|
-
|
Bitwarden CLI 2026.4.0 from 2026-04-22T21:57Z to 2026-04-22T23:30Z, when obtained from npm, had embedded malicious code. This is related to a Checkmarx supply chain incident.
New
|
CWE-78
OS Command
|
CVE-2026-42994
|
2026-05-2 00:33 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|