|
621
|
9.8 |
CRITICAL
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.4.15 captures resolved bearer-auth configuration at startup, allowing revoked tokens to remain valid after SecretRef rotation. Gateway HTTP and WebSocket handlers fail to re-reso…
New
|
CWE-672
Operation on a Resource after Expiration or Release
|
CVE-2026-43585
|
2026-05-8 04:36 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
622
|
8.8 |
HIGH
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.4.10 contains an insufficient environment variable denylist vulnerability in its exec environment policy that allows operator-supplied overrides of high-risk interpreter startup …
New
|
CWE-184
Incomplete Blacklist
|
CVE-2026-43584
|
2026-05-8 04:36 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
623
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
nvmem: zynqmp_nvmem: Fix buffer size in DMA and memcpy
Buffer size used in dma allocation and memcpy is wrong.
It can lead to und…
Update
|
CWE-787
Out-of-bounds Write
|
CVE-2026-31743
|
2026-05-8 04:36 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
624
|
6.5 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw versions 2026.4.10 before 2026.4.14 fail to persist session context during delivery queue recovery for media replay. Attackers can exploit recovered queued outbound media to bypass group too…
New
|
CWE-862
Missing Authorization
|
CVE-2026-43583
|
2026-05-8 04:36 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
625
|
6.3 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.4.10 contains a server-side request forgery vulnerability in browser navigation policy that allows attackers to bypass hostname validation through DNS rebinding attacks. Attacker…
New
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-43582
|
2026-05-8 04:35 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
626
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
PM: EM: Fix NULL pointer dereference when perf domain ID is not found
dev_energymodel_nl_get_perf_domains_doit() calls
em_perf_do…
Update
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-31744
|
2026-05-8 04:33 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
627
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
reset: gpio: fix double free in reset_add_gpio_aux_device() error path
When __auxiliary_device_add() fails, reset_add_gpio_aux_de…
Update
|
CWE-415
Double Free
|
CVE-2026-31745
|
2026-05-8 04:31 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
628
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
s390/zcrypt: Fix memory leak with CCA cards used as accelerator
Tests showed that there is a memory leak if CCA cards are used as…
Update
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2026-31746
|
2026-05-8 04:29 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
629
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
comedi: me4000: Fix potential overrun of firmware buffer
`me4000_xilinx_download()` loads the firmware that was requested by
`req…
Update
|
CWE-787
Out-of-bounds Write
|
CVE-2026-31747
|
2026-05-8 04:26 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
630
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
comedi: me_daq: Fix potential overrun of firmware buffer
`me2600_xilinx_download()` loads the firmware that was requested by
`req…
Update
|
CWE-787
Out-of-bounds Write
|
CVE-2026-31748
|
2026-05-8 04:24 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|