2026-04-24
2026-04-24 00:16Z
CRIT

CVE-2026-25775 — SenseLive: A vulnerability in SenseLive X3050’s remote management service allows firmware retrieval and update operations

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-25775

A vulnerability in SenseLive X3050’s remote management service allows firmware retrieval and update operations to be performed without authentication or authorization. The service accepts firmware-related requests from any reachable host and does not verify user privileges, integrity of uploaded images, or the authenticity of provided firmware. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDSenseliveTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-24
2026-04-24 00:00Z
CRIT

Supply chain attacks hit Checkmarx and Bitwarden developer tools

Sophos X-Ops·news.sophos.comin the wild

On April 22, 2026, threat actors compromised the CI/CD pipelines of Checkmarx (KICS scanner) and Bitwarden (CLI tool), injecting credential-harvesting malware across Docker Hub, npm, Open VSX, and GitHub Actions. Both payloads targeted developer credentials (GitHub tokens, SSH keys, cloud provider keys, AI tool configs) and exfiltrated to a shared C2 domain, with the Bitwarden variant weaponizing stolen tokens to inject malicious workflows into victim repositories.

SRFApplicationTACTA0001TACTA0006TACTA0009SRFSupply ChainVNDCheckmarxVNDBitwardenTYPThreat Intel
92
Edit Score
2026-04-23
2026-04-23 22:16Z
HIGH

CVE-2026-41353 — OpenClaw: before 2026.3.22 contains an access control bypass vulnerability in the allowProfiles feature that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41353

OpenClaw before 2026.3.22 contains an access control bypass vulnerability in the allowProfiles feature that allows attackers to circumvent profile restrictions through persistent profile mutation and runtime profile selection. Remote attackers can exploit this by manipulating browser proxy profiles at runtime to access restricted profiles and bypass intended access controls. CVSSv3.1 8.1 (HIGH)

CWECWE 472VNDOpenclawTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-23
2026-04-23 22:16Z
HIGH

CVE-2026-41352 — OpenClaw: before 2026.3.31 contains a remote code execution vulnerability where a device-paired node can

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41352

OpenClaw before 2026.3.31 contains a remote code execution vulnerability where a device-paired node can bypass the node scope gate authentication mechanism. Attackers with device pairing credentials can execute arbitrary node commands on the host system without proper node pairing validation. CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-23
2026-04-23 22:16Z
HIGH

CVE-2026-41349 — OpenClaw: before 2026.3.28 contains an agentic consent bypass vulnerability allowing LLM agents to silently

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41349

OpenClaw before 2026.3.28 contains an agentic consent bypass vulnerability allowing LLM agents to silently disable execution approval via config.patch parameter. Remote attackers can exploit this to bypass security controls and execute unauthorized operations without user consent. CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-23
2026-04-23 22:16Z
CRIT

CVE-2026-41274 — Flowiseai Flowise: Prior to 3.1.0, the GraphCypherQAChain node forwards user-provided input directly into the Cypher query

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41274

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GraphCypherQAChain node forwards user-provided input directly into the Cypher query execution pipeline without proper sanitization. An attacker can inject arbitrary Cypher commands that are executed on the underlying Neo4j database, enabling data exfiltration, modification, or deletion. This vulnerability is fixed in 3.1.0. CVSSv3.1 9.8 (CRITICAL)

CWECWE 943VNDFlowiseaiVNDFlowiseTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-23
2026-04-23 22:16Z
CRIT

CVE-2026-35431 — Server: Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35431

Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network. CVSSv3.1 10.0 (CRITICAL)

CWECWE 918TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-04-23
2026-04-23 22:16Z
CRIT

CVE-2026-33819 — Deserialization: of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-33819

Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network. CVSSv3.1 10.0 (CRITICAL)

CWECWE 502TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-04-23
2026-04-23 22:16Z
CRIT

CVE-2026-33102 — Url: redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-33102

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 9.3 (CRITICAL)

CWECWE 601TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-04-23
2026-04-23 22:16Z
CRIT

CVE-2026-32210 — Server: Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32210

Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network. CVSSv3.1 9.3 (CRITICAL)

CWECWE 918TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-04-23
2026-04-23 22:16Z
HIGH

CVE-2026-32172 — Uncontrolled: search path element in Microsoft Power Apps allows an unauthorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32172

Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.0 (HIGH)

CWECWE 427VNDUncontrolledTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-04-23
2026-04-23 22:16Z
CRIT

CVE-2026-26210 — KTransformers: through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-26210

KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where the scheduler RPC server binds a ZMQ ROUTER socket to all interfaces with no authentication and deserializes incoming messages using pickle.loads() without validation. Attackers can send a crafted pickle payload to the exposed ZMQ socket to execute arbitrary code on the server with the privileges of the ktransformers process. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502VNDKtransformersTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-23
2026-04-23 22:16Z
HIGH

CVE-2026-26150 — Server: Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-26150

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 8.6 (HIGH)

CWECWE 918TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-04-23
2026-04-23 22:16Z
CRIT

CVE-2026-24303 — Microsoft: Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24303

Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network. CVSSv3.1 9.6 (CRITICAL)

CWECWE 284VNDMicrosoftTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-04-23
2026-04-23 21:16Z
CRIT

CVE-2026-6942 — radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6942

radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to execute arbitrary commands by bypassing the command filter through shell metacharacters in user-controlled input passed to r2_cmd_str(). Attackers can inject shell metacharacters through the jsonrpc interface parameters to achieve remote code execution on the host running radare2-mcp without requiring authentication. CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-23
2026-04-23 20:16Z
HIGH

CVE-2026-41277 — Flowiseai Flowise: Prior to 3.1.0, a Mass Assignment vulnerability in the DocumentStore creation endpoint allows authenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41277

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Mass Assignment vulnerability in the DocumentStore creation endpoint allows authenticated users to control the primary key (id) and internal state fields of DocumentStore entities. Because the service uses repository.save() with a client-supplied primary key, the POST create endpoint behaves as an implicit UPSERT operation. This enables overwriting existing DocumentStore CVSSv3.1 8.8 (HIGH)

CWECWE 639CWECWE 284CWECWE 915VNDFlowiseaiVNDFlowiseTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-23
2026-04-23 20:16Z
CRIT

CVE-2026-41276 — Flowiseai Flowise: Prior to 3.1.0, this vulnerability allows remote attackers to bypass authentication on affected installations

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41276

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this vulnerability allows remote attackers to bypass authentication on affected installations of FlowiseAI Flowise. Authentication is not required to exploit this vulnerability. The specific flaw exists within the resetPassword method of the AccountService class. There is no check performed to ensure that a password reset token has actually been generated for a user accoun CVSSv3.1 9.8 (CRITICAL)

CWECWE 287VNDFlowiseaiVNDFlowiseTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-23
2026-04-23 20:16Z
HIGH

CVE-2026-41273 — Flowiseai Flowise: Prior to 3.1.0, Flowise contains an authentication bypass vulnerability that allows an unauthenticated attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41273

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise contains an authentication bypass vulnerability that allows an unauthenticated attacker to obtain OAuth 2.0 access tokens associated with a public chatflow. By accessing a public chatflow configuration endpoint, an attacker can retrieve internal workflow data, including OAuth credential identifiers, which can then be used to refresh and obtain valid OAuth 2.0 acces CVSSv3.1 8.2 (HIGH)

CWECWE 306VNDFlowiseaiVNDFlowiseTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-04-23
2026-04-23 20:16Z
HIGH

CVE-2026-41271 — Flowiseai Flowise: Prior to 3.1.0, a Server-Side Request Forgery (SSRF) vulnerability exists in FlowiseAI's POST/GET API

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41271

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side Request Forgery (SSRF) vulnerability exists in FlowiseAI's POST/GET API Chain components that allows unauthenticated attackers to force the server to make arbitrary HTTP requests to internal and external systems. By injecting malicious prompt templates, attackers can bypass the intended API documentation constraints and redirect requests to sensitive internal CVSSv3.1 8.3 (HIGH)

CWECWE 918VNDFlowiseaiVNDFlowiseTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-04-23
2026-04-23 20:16Z
CRIT

CVE-2026-41268 — Flowiseai Flowise: Prior to 3.1.0, Flowise is vulnerable to a critical unauthenticated remote command execution (RCE)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41268

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise is vulnerable to a critical unauthenticated remote command execution (RCE) vulnerability. It can be exploited via a parameter override bypass using the FILE-STORAGE:: keyword combined with a NODE_OPTIONS environment variable injection. This allows for the execution of arbitrary system commands with root privileges within the containerized Flowise instance, requirin CVSSv3.1 9.8 (CRITICAL)

CWECWE 20VNDFlowiseaiVNDFlowiseTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-23
2026-04-23 20:16Z
HIGH

CVE-2026-41267 — Flowiseai Flowise: Prior to 3.1.0, an improper mass assignment (JSON injection) vulnerability in the account registration

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41267

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, an improper mass assignment (JSON injection) vulnerability in the account registration endpoint of Flowise Cloud allows unauthenticated attackers to inject server-managed fields and nested objects during account creation. This enables client-controlled manipulation of ownership metadata, timestamps, organization association, and role mappings, breaking trust boundaries in CVSSv3.1 8.1 (HIGH)

CWECWE 639CWECWE 915VNDFlowiseaiVNDFlowiseTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-23
2026-04-23 20:16Z
CRIT

CVE-2026-41265 — Flowiseai Flowise: Using prompt injection techniques, an unauthenticated attacker with the ability to send prompts to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41265

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run method of the Airtable_Agents class. The issue results from the lack of proper sandboxing when evaluating an LLM generated python script. Using prompt injection techniques, an unauthenticated attacker with the ability to send prompts to a chatflow using the Airtable Agent node may convince an LLM to respond with a malicious python sc CVSSv3.1 9.8 (CRITICAL)

CWECWE 77VNDFlowiseaiVNDFlowiseTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-23
2026-04-23 20:16Z
CRIT

CVE-2026-41264 — Flowiseai Flowise: Using prompt injection techniques, an unauthenticated attacker with the ability to send prompts to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41264

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run method of the CSV_Agents class. The issue results from the lack of proper sandboxing when evaluating an LLM generated python script. An attacker can leverage this vulnerability to execute code in the context of the user running the server. Using prompt injection techniques, an unauthenticated attacker with the ability to send prompts CVSSv3.1 9.8 (CRITICAL)

CWECWE 184VNDFlowiseaiVNDFlowiseTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-23
2026-04-23 20:16Z
HIGH

CVE-2026-41138 — Flowiseai Flowise: Prior to 3.1.0, there is a remote code execution vulnerability in AirtableAgent.ts caused by

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41138

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, there is a remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using Pandas. The user’s input is directly applied to the question parameter within the prompt template and it is reflected to the Python code without any sanitization. This vulnerability is fixed in 3.1.0. CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDFlowiseaiVNDFlowiseTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-23
2026-04-23 20:16Z
HIGH

CVE-2026-41137 — Flowiseai Flowise: Prior to 3.1.0, The CSVAgent allows providing a custom Pandas CSV read code.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-41137

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, The CSVAgent allows providing a custom Pandas CSV read code. Due to lack of sanitization, an attacker can provide a command injection payload that will get interpolated and executed by the server. This vulnerability is fixed in 3.1.0. CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDFlowiseaiVNDFlowiseTYPVulnerability
8.8
CVSS v3.1
94
Edit Score