|
251
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker. This means that user with read permission could see the values in Connection UI, a…
New
|
CWE-200
Information Exposure
|
CVE-2026-25219
|
2026-04-16 05:16 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252
|
3.3 |
LOW
Network
|
-
|
-
|
---
title: Cross-Tenant Legacy Correlation Disclosure and Deletion
draft: false
hero:
image: /static/img/heros/hero-legal2.svg
content: "# Cross-Tenant Legacy Correlation Disclosure and Deletion"…
New
|
-
|
CVE-2026-21727
|
2026-04-16 05:16 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by double encoding, an attacker can read files at the Ruler API endpoint /loki/api/v1/…
New
|
-
|
CVE-2026-21726
|
2026-04-16 05:16 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254
|
7.5 |
HIGH
Network
|
-
|
-
|
Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager to take appropriate actions and pay attention to security details and security model of Airflow. So…
New
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2025-66236
|
2026-04-16 05:16 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (COS).
If the database is configured to use Tencent …
New
|
-
|
CVE-2025-41118
|
2026-04-16 05:16 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256
|
5.5 |
MEDIUM
Local
|
huawei
|
harmonyos
|
UAF vulnerability in the communication module.
Impact: Successful exploitation of this vulnerability may affect availability.
New
|
CWE-362
Race Condition
|
CVE-2026-34857
|
2026-04-16 05:16 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257
|
4.1 |
MEDIUM
Local
|
huawei
|
harmonyos
|
UAF vulnerability in the communication module.
Impact: Successful exploitation of this vulnerability may affect availability.
New
|
CWE-362
Race Condition
|
CVE-2026-34858
|
2026-04-16 05:13 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258
|
7.1 |
HIGH
Local
|
huawei
|
harmonyos emui
|
UAF vulnerability in the kernel module.
Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
New
|
CWE-416
Use After Free
|
CVE-2026-34859
|
2026-04-16 05:12 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
259
|
7.4 |
HIGH
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.3.25 contains a server-side request forgery vulnerability in multiple channel extensions that fail to properly guard configured base URLs against SSRF attacks. Attackers can expl…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-35629
|
2026-04-16 05:09 |
2026-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
260
|
4.7 |
MEDIUM
Local
|
huawei
|
harmonyos
|
Race condition vulnerability in the thermal management module.
Impact: Successful exploitation of this vulnerability may affect availability.
New
|
CWE-362
Race Condition
|
CVE-2026-34861
|
2026-04-16 05:09 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|