|
41
|
5.4 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.3.25 contains an authorization bypass vulnerability in Google Chat group policy enforcement that relies on mutable space display names. Attackers can rebind group policies by cha…
New
|
CWE-807
Reliance on Untrusted Inputs in a Security Decision
|
CVE-2026-35617
|
2026-04-16 23:19 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
42
|
6.5 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in webhook authentication that allows attackers to brute-force weak webhook passwords without throttling. Remote attackers can…
New
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2026-35623
|
2026-04-16 23:17 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
43
|
6.3 |
MEDIUM
Local
|
adobe
|
acrobat acrobat_dc acrobat_reader_dc
|
Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability…
New
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2026-34626
|
2026-04-16 23:14 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
44
|
8.6 |
HIGH
Local
|
adobe
|
acrobat acrobat_dc acrobat_reader_dc
|
Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability…
New
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2026-34622
|
2026-04-16 23:14 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
45
|
7.8 |
HIGH
Local
|
openclaw
|
openclaw
|
OpenClaw before 2026.3.25 contains a privilege escalation vulnerability where silent local shared-auth reconnects auto-approve scope-upgrade requests, widening paired device permissions from operator…
New
|
CWE-648
Incorrect Use of Privileged APIs
|
CVE-2026-35625
|
2026-04-16 22:43 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
46
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Configuration File Modification Vulnerability in DRC Central Office Services (COS) allows an attacker to modify the server's configuration file, potentially leading to mass data exfil…
New
|
-
|
CVE-2026-5756
|
2026-04-16 22:16 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
47
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Reflected Cross-Site Scripting (XSS) Vulnerability in Radware Alteon 34.5.4.0 vADC load-balancer allows an attacker to inject malicious scripts into the website, potentially leading to unauthorized a…
New
|
-
|
CVE-2026-5754
|
2026-04-16 22:16 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
48
|
6.5 |
MEDIUM
Network
|
-
|
-
|
An improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows authenticated attackers with the users.edit permission to modify sensitive authentication and acco…
New
|
CWE-285
Improper Authorization
|
CVE-2026-38533
|
2026-04-16 22:16 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
49
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Header injection vulnerability in Apache APISIX.
The attacker can take advantage of certain configuration in forward-auth plugin to inject malicious headers.
This issue affects Apache APISIX: from 2…
New
|
CWE-75
Special Element Injection
|
CVE-2026-31908
|
2026-04-16 22:16 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
50
|
9.8 |
CRITICAL
Network
|
-
|
-
|
An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code and escalate privileges via the CSV registration field
New
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2026-31049
|
2026-04-16 22:16 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|