| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-41303 | OpenClaw < 2026.3.28 - Authorization Bypass in Discord Text Approval Commands | OpenClaw | OpenClaw | High | 8.8 | 2026-04-20 23:08:16 | Deep Dive |
| CVE-2026-41302 | OpenClaw < 2026.3.31 - Server-Side Request Forgery via Unguarded fetch() in Marketplace Plugin Download | OpenClaw | OpenClaw | High | 7.6 | 2026-04-20 23:08:15 | Deep Dive |
| CVE-2026-41301 | OpenClaw 2026.3.22 < 2026.3.31 - Forged Nostr DM Pairing State Creation via Signature Verification Bypass | OpenClaw | OpenClaw | Medium | 5.3 | 2026-04-20 23:08:14 | Deep Dive |
| CVE-2026-41300 | OpenClaw < 2026.3.31 - Attacker-Discovered Endpoint Preservation in Remote Onboarding | OpenClaw | OpenClaw | Medium | 6.5 | 2026-04-20 23:08:13 | Deep Dive |
| CVE-2026-41299 | OpenClaw < 2026.3.28 - Client Identity Spoofing in chat.send Gateway Provenance Guard | OpenClaw | OpenClaw | High | 7.1 | 2026-04-20 23:08:13 | Deep Dive |
| CVE-2026-41298 | OpenClaw < 2026.4.2 - Authorization Bypass in Session Termination Endpoint | OpenClaw | OpenClaw | Medium | 5.4 | 2026-04-20 23:08:12 | Deep Dive |
| CVE-2026-41297 | OpenClaw < 2026.3.31 - Server-Side Request Forgery via Marketplace Plugin Download Redirect | OpenClaw | OpenClaw | High | 7.6 | 2026-04-20 23:08:11 | Deep Dive |
| CVE-2026-41296 | OpenClaw < 2026.3.31 - Sandbox Escape via TOCTOU Race in Remote FS Bridge readFile | OpenClaw | OpenClaw | High | 8.2 | 2026-04-20 23:08:10 | Deep Dive |
| CVE-2026-41295 | OpenClaw < 2026.4.2 - Untrusted Workspace Channel Shadow Code Execution during Built-in Channel Setup | OpenClaw | OpenClaw | High | 7.8 | 2026-04-20 23:08:10 | Deep Dive |
| CVE-2026-41294 | OpenClaw < 2026.3.28 - Environment Variable Injection via CWD .env File | OpenClaw | OpenClaw | High | 8.6 | 2026-04-20 23:08:09 | Deep Dive |
| CVE-2026-40045 | OpenClaw < 2026.4.2 - Cleartext Credential Transmission via Unencrypted WebSocket Gateway Endpoints | OpenClaw | OpenClaw | Medium | 5.7 | 2026-04-20 23:08:08 | Deep Dive |
| CVE-2026-34082 | Dify has IDOR in deleting someone else's chat conversation | langgenius | dify | - | - | 2026-04-20 23:03:18 | Deep Dive |
| CVE-2026-5721 | wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin <= 6.5.0.4 - Unauthenticated Stored Cross-Site Scripting via CSV/Excel Data Import | wpdatatables | wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin | Medium | 4.7 | 2026-04-20 22:25:27 | Deep Dive |
| CVE-2026-6729 | HKUDS OpenHarness Session Key Collision Privilege Escalation | HKUDS | OpenHarness | Medium | 6.3 | 2026-04-20 22:01:39 | Deep Dive |
| CVE-2026-0930 | Potential wolfSSHd Buffer out-of-bounds Read on Windows Handling Terminal Resize | wolfSSL | wolfSSH | - | - | 2026-04-20 21:28:33 | Deep Dive |
| CVE-2026-22051 | NetApp StorageGRID 安全漏洞 | NETAPP | StorageGRID (formerly StorageGRID Webscale) | - | - | 2026-04-20 21:27:37 | Deep Dive |
| CVE-2026-5450 | scanf %mc off-by-one heap buffer overflow | The GNU C Library | glibc | - | - | 2026-04-20 20:55:41 | Deep Dive |
| CVE-2026-5928 | Static buffer overflow in deprecated nis_local_principal | The GNU C Library | glibc | - | - | 2026-04-20 20:37:32 | Deep Dive |
| CVE-2026-33626 | LMDeploy Vulnerable to Server-Side Request Forgery (SSRF) via Vision-Language Image Loading | InternLM | lmdeploy | High | 7.5 | 2026-04-20 20:29:20 | Deep Dive |
| CVE-2026-4852 | Image Source Control Lite – Show Image Credits and Captions <= 3.9.1 - Authenticated (Author+) Stored Cross-Site Scripting via 'Image Source' Field | webzunft | Image Source Control Lite – Show Image Credits and Captions | Medium | 6.4 | 2026-04-20 20:26:53 | Deep Dive |