| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-41340 | OpenClaw < 2026.3.31 - Authentication Boundary Bypass via Telegram Legacy allowFrom Migration | OpenClaw | OpenClaw | Medium | 6.5 | 2026-04-23 21:57:59 | Deep Dive |
| CVE-2026-41339 | OpenClaw < 2026.4.2 - Information Disclosure via Gateway Connect Snapshot | OpenClaw | OpenClaw | Medium | 4.3 | 2026-04-23 21:57:59 | Deep Dive |
| CVE-2026-41338 | OpenClaw < 2026.3.31 - Time-of-Check-Time-of-Use (TOCTOU) Vulnerability in Sandbox File Operations | OpenClaw | OpenClaw | Medium | 5.0 | 2026-04-23 21:57:58 | Deep Dive |
| CVE-2026-41337 | OpenClaw < 2026.3.31 - Callback Origin Mutation in Plivo Voice-call Replay | OpenClaw | OpenClaw | Medium | 5.3 | 2026-04-23 21:57:57 | Deep Dive |
| CVE-2026-41336 | OpenClaw < 2026.3.31 - Arbitrary Hook Code Execution via OPENCLAW_BUNDLED_HOOKS_DIR Environment Variable Override | OpenClaw | OpenClaw | High | 7.8 | 2026-04-23 21:57:56 | Deep Dive |
| CVE-2026-41335 | OpenClaw < 2026.3.31 - Information Disclosure via Control UI Bootstrap JSON | OpenClaw | OpenClaw | Medium | 5.3 | 2026-04-23 21:57:55 | Deep Dive |
| CVE-2026-41334 | OpenClaw < 2026.3.31 - Decompression Bomb Denial of Service via Image Pixel-Limit Guard Bypass | OpenClaw | OpenClaw | Medium | 6.5 | 2026-04-23 21:57:55 | Deep Dive |
| CVE-2026-41333 | OpenClaw < 2026.3.31 - Authentication Rate Limiting Bypass via Fake DeviceToken | OpenClaw | OpenClaw | Low | 3.7 | 2026-04-23 21:57:54 | Deep Dive |
| CVE-2026-41332 | OpenClaw < 2026.3.28 - Code Execution via Missing Environment Variable Blocklist | OpenClaw | OpenClaw | Medium | 5.3 | 2026-04-23 21:57:53 | Deep Dive |
| CVE-2026-2708 | Libsoup: libsoup: http request smuggling via duplicate content-length headers | Red Hat | Red Hat Enterprise Linux 10 | Low | 3.7 | 2026-04-23 21:51:23 | Deep Dive |
| CVE-2026-32172 | Microsoft Power Apps Remote Code Execution Vulnerability | Microsoft | Microsoft Power Apps | High | 8.0 | 2026-04-23 21:37:43 | Deep Dive |
| CVE-2026-35431 | Microsoft Entra ID Entitlement Management Spoofing Vulnerability | Microsoft | Microsoft Entra | Critical | 10.0 | 2026-04-23 21:37:42 | Deep Dive |
| CVE-2026-24303 | Microsoft Partner Center Elevation of Privilege Vulnerability | Microsoft | Microsoft Partner Center | Critical | 9.6 | 2026-04-23 21:37:41 | Deep Dive |
| CVE-2026-26150 | Microsoft Purview eDiscovery Elevation of Privilege Vulnerability | Microsoft | Microsoft Purview eDiscovery | High | 8.6 | 2026-04-23 21:37:40 | Deep Dive |
| CVE-2026-33819 | Microsoft Bing Remote Code Execution Vulnerability | Microsoft | Microsoft Bing | Critical | 10.0 | 2026-04-23 21:35:50 | Deep Dive |
| CVE-2026-33102 | Microsoft 365 Copilot Elevation of Privilege Vulnerability | Microsoft | Microsoft 365 Copilot | Critical | 9.3 | 2026-04-23 21:35:49 | Deep Dive |
| CVE-2026-32210 | Microsoft Dynamics 365 (online) Spoofing Vulnerability | Microsoft | Microsoft Dynamics 365 (online) | Critical | 9.3 | 2026-04-23 21:35:48 | Deep Dive |
| CVE-2026-26210 | KTransformers Unsafe Deserialization RCE via balance_serve | kvcache-ai | ktransformers | Critical | 9.8 | 2026-04-23 21:24:49 | Deep Dive |
| CVE-2026-41274 | Flowise: Cypher Injection in GraphCypherQAChain | FlowiseAI | Flowise | - | - | 2026-04-23 21:12:52 | Deep Dive |
| CVE-2026-28525 | SWUpdate Integer Underflow in Multipart Upload Parser | sbabic | swupdate | Medium | 6.8 | 2026-04-23 20:59:31 | Deep Dive |