| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-39320 | Signal K Server has an Unauthenticated Regular Expression Denial of Service (ReDoS) via WebSocket Subscription Paths | SignalK | signalk-server | High | 7.5 | 2026-04-21 00:07:10 | Deep Dive |
| CVE-2026-29644 | XiangShan 安全漏洞 | - | - | - | - | 2026-04-21 00:00:00 | Deep Dive |
| CVE-2026-31018 | Dolibarr ERP & CRM 安全漏洞 | - | - | - | - | 2026-04-21 00:00:00 | Deep Dive |
| CVE-2026-31014 | Infoopia Dovestones AD Self Update 安全漏洞 | - | - | - | - | 2026-04-21 00:00:00 | Deep Dive |
| CVE-2026-31019 | Dolibarr ERP & CRM 安全漏洞 | - | - | - | - | 2026-04-21 00:00:00 | Deep Dive |
| CVE-2026-31013 | Infoopia Dovestones ADPhonebook 安全漏洞 | - | - | - | - | 2026-04-21 00:00:00 | Deep Dive |
| CVE-2026-37748 | Visitor Management System 安全漏洞 | - | - | - | - | 2026-04-21 00:00:00 | Deep Dive |
| CVE-2026-38834 | Tenda W30E 安全漏洞 | - | - | - | - | 2026-04-21 00:00:00 | Deep Dive |
| CVE-2026-38835 | Tenda W30E 安全漏洞 | - | - | - | - | 2026-04-21 00:00:00 | Deep Dive |
| CVE-2026-30452 | Textpattern CMS 安全漏洞 | - | - | - | - | 2026-04-21 00:00:00 | Deep Dive |
| CVE-2026-41527 | kleopatra 安全漏洞 | KDE | Kleopatra | Medium | 6.9 | 2026-04-21 00:00:00 | Deep Dive |
| CVE-2026-40706 | Tuxera NTFS-3G 安全漏洞 | Tuxera | NTFS-3G | High | 8.4 | 2026-04-21 00:00:00 | Deep Dive |
| CVE-2025-70420 | Genesys Latitude 安全漏洞 | - | - | - | - | 2026-04-21 00:00:00 | Deep Dive |
| CVE-2026-35570 | OpenClaude has Sandbox Bypass via Early-Exit Logic Flaw that Allows Path Traversal | Gitlawb | openclaude | High | 8.4 | 2026-04-20 23:24:08 | Deep Dive |
| CVE-2026-35588 | Glances has CQL Injection in its Cassandra Export Module via Unsanitized Config Values | nicolargo | glances | Medium | 6.3 | 2026-04-20 23:20:35 | Deep Dive |
| CVE-2026-35587 | Glances IP Plugin has SSRF via public_api that leads to credential leakage | nicolargo | glances | - | - | 2026-04-20 23:19:03 | Deep Dive |
| CVE-2026-34839 | Glances Vulnerable to Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due to Permissive CORS | nicolargo | glances | - | - | 2026-04-20 23:09:03 | Deep Dive |
| CVE-2026-41331 | OpenClaw < 2026.3.31 - Resource Consumption via Unauthorized Telegram Audio Preflight Transcription | OpenClaw | OpenClaw | Medium | 5.3 | 2026-04-20 23:08:18 | Deep Dive |
| CVE-2026-41330 | OpenClaw < 2026.3.31 - Environment Variable Override via Host Exec Policy | OpenClaw | OpenClaw | Medium | 4.4 | 2026-04-20 23:08:17 | Deep Dive |
| CVE-2026-41329 | OpenClaw < 2026.3.31 - Sandbox Bypass via Heartbeat Context Inheritance and senderIsOwner Escalation | OpenClaw | OpenClaw | Critical | 9.9 | 2026-04-20 23:08:16 | Deep Dive |