Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.9 MEDIUM
CVE-2026-40045 — OpenClaw < 2026.4.2 - Cleartext Credential Transmission via Unencrypted WebSocket Gateway…

OpenClaw before 2026.4.2 accepts non-loopback cleartext ws:// gateway endpoints and transmits stored gateway credentials over unencrypted connections. Attackers can forge discovery results or craft s…

openclaw | Misconfiguration
Apr 21, 2026 Apr 21, 2026
Apr 21, 2026
Apr 21, 2026
6.3 MEDIUM
CVE-2026-35588 — Glances has CQL Injection in its Cassandra Export Module via Unsanitized Config Values

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Cassandra export module (`glances/exports/glances_cassandra/__init__.py`) interpolates `keyspace`, `table`…

glances | Injection
Apr 21, 2026 Apr 21, 2026
Apr 21, 2026
Apr 21, 2026
7.3 HIGH
CVE-2026-35587 — Glances IP Plugin has SSRF via public_api that leads to credential leakage

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, a Server-Side Request Forgery (SSRF) vulnerability exists in the Glances IP plugin due to improper validation …

glances | Remote | Server-Side Request Forgery
Apr 21, 2026 Apr 21, 2026
Apr 21, 2026
Apr 21, 2026
8.4 HIGH
CVE-2026-35570 — OpenClaude has Sandbox Bypass via Early-Exit Logic Flaw that Allows Path Traversal

OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Versions prior to 0.5.1 have a logic flaw in `bashToolHasPermission()` inside `src/tools/BashTool…

| Path Traversal
Apr 21, 2026 Apr 21, 2026
Apr 21, 2026
Apr 21, 2026
7.7 HIGH
CVE-2026-34839 — Glances Vulnerable to Cross-Origin Information Disclosure via Unauthenticated REST API (/…

Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Glances web server exposes a REST API (`/api/4/*`) that is accessible without authentication and allows cr…

glances | Remote | Information Disclosure
Apr 21, 2026 Apr 21, 2026
Apr 21, 2026
Apr 21, 2026
4.7 MEDIUM
CVE-2026-5721 — wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin <= 6.5.0.4 - Un…

The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.5.0.4. This is …

wpdatatables | Remote | Cross-Site Scripting
Apr 20, 2026 Apr 20, 2026
Apr 20, 2026
Apr 20, 2026
5.3 MEDIUM
CVE-2026-34082 — Dify has IDOR in deleting someone else's chat conversation

Dify is an open-source LLM app development platform. Prior to 1.13.1, the method `DELETE /console/api/installed-apps/<appId>/conversations/<conversationId>` has poor authorization checking and allows…

dify | Remote | Authorization
Apr 20, 2026 Apr 20, 2026
Apr 20, 2026
Apr 20, 2026
6.3 MEDIUM
CVE-2026-6729 — HKUDS OpenHarness Session Key Collision Privilege Escalation

HKUDS OpenHarness prior to PR #159 remediation contains a session key derivation vulnerability that allows authenticated participants in shared chats or threads to hijack other users' sessions by exp…

Remote | Authentication
Apr 20, 2026 Apr 20, 2026
Apr 20, 2026
Apr 20, 2026
0.0 NA
CVE-2026-29643 — XiangShan RISC-V Processor CSR Subsystem Improper Exceptional-Condition Handling Vulnerab…

XiangShan (Open-source high-performance RISC-V processor) commit edb1dfaf7d290ae99724594507dc46c2c2125384 (2024-11-28) contains an improper exceptional-condition handling flaw in its CSR subsystem (N…

| Denial of Service
Apr 20, 2026 Apr 20, 2026
Apr 20, 2026
Apr 20, 2026
2.3 LOW
CVE-2026-22051 — StorageGRID Information Disclosure Vulnerability

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.13 and 12.0.0.6 are susceptible to a Information Disclosure vulnerability. Successful exploit could allow an authenticated attacke…

storagegrid | Remote | Information Disclosure
Apr 20, 2026 Apr 20, 2026
Apr 20, 2026
Apr 20, 2026
2.3 LOW
CVE-2026-0930 — Potential wolfSSHd Buffer out-of-bounds Read on Windows Handling Terminal Resize

Potential read out of bounds case with wolfSSHd on Windows while handling a terminal resize request. An authenticated user could trigger the out of bounds read after establishing a connection which w…

wolfssh | Remote | Memory Corruption
Apr 20, 2026 Apr 20, 2026
Apr 20, 2026
Apr 20, 2026
0.0 NA
CVE-2026-5928 — Static buffer overflow in deprecated nis_local_principal

Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library versio…

glibc | Memory Corruption
Apr 20, 2026 Apr 20, 2026
Apr 20, 2026
Apr 20, 2026
0.0 NA
CVE-2026-5450 — scanf %mc off-by-one heap buffer overflow

Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 cou…

glibc | Memory Corruption
Apr 20, 2026 Apr 20, 2026
Apr 20, 2026
Apr 20, 2026
0.0 NA
CVE-2026-5358 — Static buffer overflow in deprecated nis_local_principal

The obsolete nis_local_principal function in the GNU C Library version 2.43 and older may overflow a buffer in the data section, which could allow an attacker to spoof a crafted response to a UDP req…

glibc | Memory Corruption
Apr 20, 2026 Apr 20, 2026
Apr 20, 2026
Apr 20, 2026
6.4 MEDIUM
CVE-2026-4852 — Image Source Control Lite – Show Image Credits and Captions <= 3.9.1 - Authenticated (Aut…

The Image Source Control Lite – Show Image Credits and Captions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Image Source' attachment field in all versions up to, and in…

Remote | Cross-Site Scripting
Apr 20, 2026 Apr 20, 2026
Apr 20, 2026
Apr 20, 2026
5.5 MEDIUM
CVE-2026-34403 — Nginx-UI vulnerable to Cross-Site WebSocket Hijacking (CSWSH) via missing origin validati…

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.5, all WebSocket endpoints in nginx-ui use a gorilla/websocket Upgrader with CheckOrigin unconditionally returning true…

nginx_ui | Remote | Authentication
Apr 20, 2026 Apr 20, 2026
Apr 20, 2026
Apr 20, 2026
7.5 HIGH
CVE-2026-33626 — LMDeploy Vulnerable to Server-Side Request Forgery (SSRF) via Vision-Language Image Loadi…

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions prior to 0.12.3 have a Server-Side Request Forgery (SSRF) vulnerability in LMDeploy's vision-language mod…

lmdeploy | Remote | Server-Side Request Forgery
Apr 20, 2026 Apr 20, 2026
Apr 20, 2026
Apr 20, 2026
7.7 HIGH
CVE-2026-33432 — Roxy-WI has Pre-Authentication LDAP Injection that Leads to Authentication Bypass

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions up to and including 8.2.8.2, when LDAP authentication is enabled, Roxy-WI constructs an LDAP search …

roxy-wi | Remote | Authentication
Apr 20, 2026 Apr 20, 2026
Apr 20, 2026
Apr 20, 2026
5.7 MEDIUM
CVE-2026-33431 — Roxy-WI Vulnerable to Authenticated Arbitrary File Read via Path Traversal in Config Vers…

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the POST /config/<service>/show API endpoint accepts a configver parameter that is dir…

roxy-wi | Remote | Path Traversal
Apr 20, 2026 Apr 20, 2026
Apr 20, 2026
Apr 20, 2026
8.6 HIGH
CVE-2026-33031 — Nginx-UI: Disabled users retain full API access through previously issued bearer tokens

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, a user who was disabled by an administrator can use previously issued API tokens for up to the token lifetime. In pr…

nginx_ui | Remote | Authentication
Apr 20, 2026 Apr 20, 2026
Apr 20, 2026
Apr 20, 2026
Showing 20 of 6039 Results