Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-41365 — OpenClaw < 2026.3.31 - Sender Allowlist Bypass via Graph API Thread History

OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability in MS Teams thread history fetched via Graph API. Attackers can retrieve thread messages that should be filtered by sender a…

openclaw | Remote | Authorization
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
8.1 HIGH
CVE-2026-41364 — OpenClaw < 2026.3.31 - Arbitrary File Write via Symlink Following in SSH Sandbox Tar Uplo…

OpenClaw before 2026.3.31 contains a symlink following vulnerability in SSH sandbox tar upload that allows remote attackers to write arbitrary files. Attackers can exploit this by uploading tar archi…

openclaw | Remote | Path Traversal
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
6.0 MEDIUM
CVE-2026-41363 — OpenClaw 2026.2.6 < 2026.3.28 - Arbitrary File Read via Feishu upload_image Parameter

OpenClaw versions 2026.2.6 through 2026.3.24 contain a path traversal vulnerability in the Feishu extension resolveUploadInput function that bypasses file-system sandbox restrictions. Attackers can e…

openclaw | Remote | Path Traversal
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
4.3 MEDIUM
CVE-2026-41362 — OpenClaw 2026.2.19 < 2026.3.31 - Webhook Replay Dedupe Cache Event Suppression via Shared…

OpenClaw versions 2026.2.19 before 2026.3.31 contain an improper cache isolation vulnerability in the Zalo webhook replay-dedupe mechanism that is shared across authenticated webhook targets. Attacke…

openclaw | Remote | Misconfiguration
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
4.7 MEDIUM
CVE-2026-40977 — Spring Boot PID File Corruption Vulnerability (Local File Corruption)

When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file's location can corrupt one file on the host each time the application is starte…

spring_boot | Misconfiguration
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
9.1 CRITICAL
CVE-2026-40976 — "Spring Boot Default Web Security Bypass"

In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web applica…

spring_boot | Remote | Authentication
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
4.8 MEDIUM
CVE-2026-40975 — Spring Boot Weak PRNG for Secrets

Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} and ${random.long} should never be used for secrets as they are numeric values wi…

spring_boot | Remote | Cryptography
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
5.0 MEDIUM
CVE-2026-40974 — Spring Boot Cassandra SSL Hostname Verification Bypass

Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3…

spring_boot | Misconfiguration
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
7.0 HIGH
CVE-2026-40973 — Spring Boot Persistent Session Directory Takeover Vulnerability

A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. When `server.servlet.session.persistent` is set to `true` and the attack p…

spring_boot | Path Traversal
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
7.5 HIGH
CVE-2026-40972 — Spring Boot Timing Attack Remote Code Execution

An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme circumstances this could result in the att…

spring_boot | Information Disclosure
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
8.8 HIGH
CVE-2026-27785 — Milesight Cameras Use of Hard-coded Credentials

Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials.

| Authentication
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
6.5 MEDIUM
CVE-2026-41526 — KDE KCoreAddons Shell Injection Vulnerability

In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing does not adequately handle metacharacters, leading …

| Injection
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
6.5 MEDIUM
CVE-2026-41525 — KDE Dolphin Flatpak Sandbox Escalation Vulnerability

KDE Dolphin before 25.12.3 allows applications in a Flatpak (or with AppArmor confinement) to open folders outside of the application sandbox without additional scrutiny. Dolphin's implementation of …

| Path Traversal
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
7.5 HIGH
CVE-2026-7194 — SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection

A weakness has been identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts an unknown function of the file /ajax.php?action=save_product. This manipulation of the argument…

Remote | Injection
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
5.5 MEDIUM
CVE-2026-7183 — aligungr UERANSIM Radio Link Simulation Layer rls_pdu.cpp DecodeRlsMessage uncaught excep…

A vulnerability has been found in aligungr UERANSIM up to 3.2.7. The affected element is the function rls::DecodeRlsMessage in the library src/lib/rls/rls_pdu.cpp of the component Radio Link Simulati…

Remote | Memory Corruption
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
5.3 MEDIUM
CVE-2026-7179 — OSPG binwalk WinCE Extraction Plugin winceextract.py read_null_terminated_string path tra…

A security vulnerability has been detected in OSPG binwalk up to 2.4.3. This vulnerability affects the function read_null_terminated_string of the file src/binwalk/plugins/winceextract.py of the comp…

| Path Traversal
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
5.0 MEDIUM
CVE-2026-40971 — Spring Boot RabbitMQ SSL Hostname Verification Bypass

When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitMQ broker. Affected: Spring Boot 4.0.0–4.0.5 (fix …

spring_boot | Misconfiguration
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
7.3 HIGH
CVE-2026-28747 — Milesight Cameras Authorization Bypass Through User-Controlled Key

A weak key generation vulnerability exists in specific firmware versions of Milesight AIOT cameras allows authorization to be bypassed.

| Authentication
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
7.5 HIGH
CVE-2026-7178 — ChatGPTNextWeb NextChat Artifacts Endpoint route.ts storeUrl server-side request forgery

A weakness has been identified in ChatGPTNextWeb NextChat up to 2.16.1. This affects the function storeUrl of the file app/api/artifacts/route.ts of the component Artifacts Endpoint. This manipulatio…

nextchat | Remote | Server-Side Request Forgery
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
7.5 HIGH
CVE-2026-7177 — ChatGPTNextWeb NextChat route.ts proxyHandler server-side request forgery

A security flaw has been discovered in ChatGPTNextWeb NextChat up to 2.16.1. Affected by this issue is the function proxyHandler of the file app/api/[provider]/[...path]/route.ts. The manipulation re…

nextchat | Remote | Server-Side Request Forgery
Apr 27, 2026 Apr 27, 2026
Apr 27, 2026
Apr 27, 2026
Showing 20 of 5798 Results