|
281
|
5.4 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.4.8 contains an authentication state management vulnerability where the resolvedAuth closure becomes stale after configuration reload. Newly accepted gateway connections continue…
New
|
CWE-613
Insufficient Session Expiration
|
CVE-2026-41916
|
2026-04-30 23:04 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282
|
6.1 |
MEDIUM
Local
|
openclaw
|
openclaw
|
OpenClaw before 2026.4.8 fails to remove git plumbing environment variables from the execution environment before host exec operations. Attackers can exploit this by setting GIT_DIR and related varia…
New
|
CWE-184
Incomplete Blacklist
|
CVE-2026-41915
|
2026-04-30 23:04 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283
|
5.4 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.4.8 contains a session management vulnerability where existing WebSocket sessions survive shared gateway token rotation. Attackers can maintain unauthorized access to WebSocket c…
New
|
CWE-613
Insufficient Session Expiration
|
CVE-2026-42421
|
2026-04-30 23:04 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284
|
8.8 |
HIGH
Network
|
tenda
|
f456_firmware
|
A vulnerability was detected in Tenda F456 1.0.0.5. The affected element is the function formQuickIndex of the file /goform/QuickIndex of the component httpd. Performing a manipulation of the argumen…
Update
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-7099
|
2026-04-30 23:04 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285
|
8.8 |
HIGH
Network
|
tenda
|
f456_firmware
|
A flaw has been found in Tenda F456 1.0.0.5. The impacted element is the function fromNatlimitof of the file /goform/Natlimit of the component httpd. Executing a manipulation can lead to buffer overf…
Update
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-7100
|
2026-04-30 23:03 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286
|
8.8 |
HIGH
Network
|
tenda
|
f456_firmware
|
A security vulnerability has been detected in Tenda F456 1.0.0.5. This affects the function fromRouteStatic of the file /goform/RouteStatic. The manipulation of the argument page leads to buffer over…
Update
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-7030
|
2026-04-30 23:03 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287
|
8.8 |
HIGH
Network
|
tenda
|
f456_firmware
|
A security vulnerability has been detected in Tenda F456 1.0.0.5. Impacted is the function fromDhcpListClient of the file /goform/DhcpListClient of the component httpd. Such manipulation of the argum…
Update
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-7098
|
2026-04-30 23:03 |
2026-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288
|
8.8 |
HIGH
Network
|
tenda
|
f456_firmware
|
A weakness has been identified in Tenda F456 1.0.0.5. The impacted element is the function fromaddressNat of the file /goform/addressNat. Executing a manipulation of the argument menufacturer/Go can …
Update
|
CWE-119 CWE-120
Incorrect Access of Indexable Resource ('Range Error') Classic Buffer Overflow
|
CVE-2026-7029
|
2026-04-30 23:03 |
2026-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289
|
8.5 |
HIGH
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.4.8 contains a server-side request forgery vulnerability in QQ Bot media download paths that bypass SSRF protection. Attackers can exploit unprotected media fetch endpoints to ac…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-41914
|
2026-04-30 23:02 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290
|
7.5 |
HIGH
Network
|
vmware
|
spring_boot
|
Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} and ${random.long} should never be used for secrets as they are numeric values wi…
New
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2026-40975
|
2026-04-30 22:57 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|