| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-39866 | Lawnchair vulnerable to Command Injection via unquoted workflow dispatch input in release_update.yml | LawnchairLauncher | lawnchair | - | - | 2026-04-21 01:19:48 | Deep Dive |
| CVE-2026-39861 | Claude Code: Sandbox Escape via Symlink Following Allows Arbitrary File Write Outside Workspace | anthropics | claude-code | - | - | 2026-04-21 00:56:39 | Deep Dive |
| CVE-2026-39386 | Neko has Self-service Privilege Escalation for Authenticated Users | m1k1o | neko | High | 8.8 | 2026-04-21 00:50:35 | Deep Dive |
| CVE-2026-40264 | OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation | openbao | openbao | - | - | 2026-04-21 00:47:38 | Deep Dive |
| CVE-2026-39396 | OpenBao has Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS) | openbao | openbao | Low | 3.1 | 2026-04-21 00:44:54 | Deep Dive |
| CVE-2026-39388 | OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate | openbao | openbao | - | - | 2026-04-21 00:43:23 | Deep Dive |
| CVE-2026-39946 | OpenBao allows SQL Injection in PostgreSQL database secrets engine | openbao | openbao | 中危 | - | 2026-04-21 00:19:40 | Deep Dive |
| CVE-2026-39378 | nbconvert has an Arbitrary File Read via Path Traversal in HTMLExporter Image Embedding | jupyter | nbconvert | Medium | 6.5 | 2026-04-21 00:17:01 | Deep Dive |
| CVE-2026-39377 | nbconvert has an Arbitrary File Write via Path Traversal in Cell Attachment Filenames | jupyter | nbconvert | Medium | 6.5 | 2026-04-21 00:15:00 | Deep Dive |
| CVE-2026-39320 | Signal K Server has an Unauthenticated Regular Expression Denial of Service (ReDoS) via WebSocket Subscription Paths | SignalK | signalk-server | High | 7.5 | 2026-04-21 00:07:10 | Deep Dive |
| CVE-2026-29644 | XiangShan 安全漏洞 | - | - | - | - | 2026-04-21 00:00:00 | Deep Dive |
| CVE-2026-31018 | Dolibarr ERP & CRM 安全漏洞 | - | - | - | - | 2026-04-21 00:00:00 | Deep Dive |
| CVE-2026-31014 | Infoopia Dovestones AD Self Update 安全漏洞 | - | - | - | - | 2026-04-21 00:00:00 | Deep Dive |
| CVE-2026-31019 | Dolibarr ERP & CRM 安全漏洞 | - | - | - | - | 2026-04-21 00:00:00 | Deep Dive |
| CVE-2026-31013 | Infoopia Dovestones ADPhonebook 安全漏洞 | - | - | - | - | 2026-04-21 00:00:00 | Deep Dive |
| CVE-2026-37748 | Visitor Management System 安全漏洞 | - | - | - | - | 2026-04-21 00:00:00 | Deep Dive |
| CVE-2026-38834 | Tenda W30E 安全漏洞 | - | - | - | - | 2026-04-21 00:00:00 | Deep Dive |
| CVE-2026-38835 | Tenda W30E 安全漏洞 | - | - | - | - | 2026-04-21 00:00:00 | Deep Dive |
| CVE-2026-30452 | Textpattern CMS 安全漏洞 | - | - | - | - | 2026-04-21 00:00:00 | Deep Dive |
| CVE-2026-41527 | kleopatra 安全漏洞 | KDE | Kleopatra | Medium | 6.9 | 2026-04-21 00:00:00 | Deep Dive |