Total CVEs

125,663

Critical Severity

2,261

High Severity

7,819

Last 7 Days

1,181
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 421 - 440 of 22,068 CVEs
CVE-2026-41363 MEDIUM - 5.3

OpenClaw versions 2026.2.6 through 2026.3.24 contain a path traversal vulnerability in the Feishu extension resolveUploadInput function that bypasses file-system sandbox restrictions. Attackers can exploit improper path resolution during upload_image operations to read arbitrary files outside config...

Vendor: OpenClaw
Product: OpenClaw
Published: Apr 28, 2026
Source: NVD
CVE-2026-41362 MEDIUM - 4.3

OpenClaw versions 2026.2.19 before 2026.3.31 contain an improper cache isolation vulnerability in the Zalo webhook replay-dedupe mechanism that is shared across authenticated webhook targets. Attackers controlling one authenticated Zalo webhook path in multi-account deployments can suppress legitima...

Vendor: OpenClaw
Product: OpenClaw
Published: Apr 28, 2026
Source: NVD
CVE-2026-40977 MEDIUM - 4.7

When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file's location can corrupt one file on the host each time the application is started. Affected: Spring Boot 4.0.0โ€“4.0.5 (fix 4.0.6), 3.5.0โ€“3.5.13 (fix 3.5.14), 3.4.0โ€“3.4.15 (fix ...

Vendor: Spring
Product: Spring Boot
Published: Apr 28, 2026
Source: NVD
CVE-2026-40976 CRITICAL - 9.1

In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configuration of its own and rely on the default web security filt...

Vendor: Spring
Product: Spring Boot
Published: Apr 28, 2026
Source: NVD
CVE-2026-40975 MEDIUM - 4.8

Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} and ${random.long} should never be used for secrets as they are numeric values with a predictable range. Affected: Spring Boot 4.0.0โ€“4.0.5 (fix 4.0.6), 3.5.0โ€“3.5.13 (fix 3.5.14), 3....

Vendor: Spring
Product: Spring Boot
Published: Apr 28, 2026
Source: NVD
CVE-2026-40974 MEDIUM - 5.0

Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra. Affected: Spring Boot 4.0.0โ€“4.0.5 (fix 4.0.6), 3.5.0โ€“3.5.13 (fix 3.5.14), 3.4.0โ€“3.4.15 (fix 3.4.16), 3.3.0โ€“3.3.18 (fix 3.3.19), 2.7.0โ€“2.7.32 (fix 2.7.33); Cassand...

Vendor: Spring
Product: Spring Boot
Published: Apr 28, 2026
Source: NVD
CVE-2026-40973 HIGH - 7.0

A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. When `server.servlet.session.persistent` is set to `true` and the attack persists across application restarts, this may allow the attacker to read session information and hija...

Vendor: Spring
Product: Spring Boot
Published: Apr 28, 2026
Source: NVD
CVE-2026-40972 HIGH - 7.5

An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme circumstances this could result in the attacker determining the secret and uploading changed classes, thereby achieving remote code execution i...

Vendor: Spring
Product: Spring Boot
Published: Apr 28, 2026
Source: NVD
CVE-2026-27785 HIGH - 8.8

Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials.

Published: Apr 28, 2026
Source: NVD
CVE-2026-7194 HIGH - 7.3

A weakness has been identified in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts an unknown function of the file /ajax.php?action=save_product. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been mad...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7183 MEDIUM - 5.3

A vulnerability has been found in aligungr UERANSIM up to 3.2.7. The affected element is the function rls::DecodeRlsMessage in the library src/lib/rls/rls_pdu.cpp of the component Radio Link Simulation Layer. The manipulation of the argument pduLength leads to uncaught exception. The attack may be i...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7179 MEDIUM - 5.3

A security vulnerability has been detected in OSPG binwalk up to 2.4.3. This vulnerability affects the function read_null_terminated_string of the file src/binwalk/plugins/winceextract.py of the component WinCE Extraction Plugin. Such manipulation of the argument self.file_name leads to path travers...

Published: Apr 27, 2026
Source: NVD
CVE-2026-40971 MEDIUM - 5.0

When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitMQ broker. Affected: Spring Boot 4.0.0โ€“4.0.5 (fix 4.0.6), 3.5.0โ€“3.5.13 (fix 3.5.14) per vendor advisory.

Vendor: Spring
Product: Spring Boot
Published: Apr 27, 2026
Source: NVD
CVE-2026-28747 HIGH - 7.1

A weak key generation vulnerability exists in specific firmware versions of Milesight AIOT cameras allows authorization to be bypassed.

Published: Apr 27, 2026
Source: NVD
CVE-2026-7178 HIGH - 7.3

A weakness has been identified in ChatGPTNextWeb NextChat up to 2.16.1. This affects the function storeUrl of the file app/api/artifacts/route.ts of the component Artifacts Endpoint. This manipulation of the argument ID causes server-side request forgery. It is possible to initiate the attack remote...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7177 HIGH - 7.3

A security flaw has been discovered in ChatGPTNextWeb NextChat up to 2.16.1. Affected by this issue is the function proxyHandler of the file app/api/[provider]/[...path]/route.ts. The manipulation results in server-side request forgery. The attack may be performed from remote. The exploit has been r...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7160 HIGH - 8.8

A vulnerability was determined in Tenda HG3 2.0. This vulnerability affects the function formTracert of the file /boaform/formTracert. Executing a manipulation of the argument datasize can lead to command injection. The attack may be performed from remote. The exploit has been publicly disclosed and...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7159 HIGH - 7.3

A vulnerability was found in douinc mkdocs-mcp-plugin up to 0.4.1. This affects the function read_document/list_documents of the file server.py. Performing a manipulation of the argument docs_dir/file_path results in path traversal. The attack is possible to be carried out remotely. The exploit has ...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7191 HIGH - 7.2

Improper use of the static-eval npm package in the open source solution qnabot-on-aws versions 7.2.4 and earlier may allow an authenticated administrator to execute arbitrary code within the fulfillment Lambda execution context by injecting a crafted conditional chaining expression via the Content D...

Published: Apr 27, 2026
Source: NVD
CVE-2026-7158 HIGH - 7.3

A vulnerability has been found in dmitryglhf mcp-url-downloader up to 4b8cf2de55f6e8864a77d108e8a94a5b8e4394c6. Affected by this issue is the function _validate_url_safe of the file src/mcp_url_downloader/server.py. Such manipulation of the argument url leads to server-side request forgery. The atta...

Published: Apr 27, 2026
Source: NVD