| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-43577 | OpenClaw < 2026.4.9 - Arbitrary File Read via Browser Interaction Routes | OpenClaw | OpenClaw | Medium | 6.5 | 2026-05-06 19:49:21 | Deep Dive |
| CVE-2026-43576 | OpenClaw < 2026.4.5 - Second-hop SSRF via CDP /json/version WebSocket URL | OpenClaw | OpenClaw | High | 7.7 | 2026-05-06 19:49:20 | Deep Dive |
| CVE-2026-43575 | OpenClaw 2026.2.21 < 2026.4.10 - Authentication Bypass in Sandbox noVNC Helper Route | OpenClaw | OpenClaw | Critical | 9.8 | 2026-05-06 19:49:20 | Deep Dive |
| CVE-2026-40309 | Masa CMS CSRF in trash management allows unauthorized permanent deletion of deleted content | MasaCMS | MasaCMS | - | - | 2026-05-06 19:42:24 | Deep Dive |
| CVE-2026-40174 | Masa CMS CSRF in user address management allows unauthorized address changes | MasaCMS | MasaCMS | - | - | 2026-05-06 19:40:24 | Deep Dive |
| CVE-2026-40171 | Jupyter Notebook and JupyterLab token theft via stored XSS in help command linker | jupyter | notebook | - | - | 2026-05-06 19:36:32 | Deep Dive |
| CVE-2026-40076 | OpenMRS Core arbitrary file write and code execution via Zip Slip in module upload | openmrs | openmrs-core | - | - | 2026-05-06 19:32:14 | Deep Dive |
| CVE-2026-8033 | PicoTronica e-Clinic Healthcare System ECHS Response Header v2 information disclosure | PicoTronica | e-Clinic Healthcare System ECHS | Medium | 5.3 | 2026-05-06 19:30:17 | Deep Dive |
| CVE-2026-8032 | PicoTronica e-Clinic Healthcare System ECHS echs.js hard-coded credentials | PicoTronica | e-Clinic Healthcare System ECHS | High | 7.3 | 2026-05-06 19:00:21 | Deep Dive |
| CVE-2026-0300 | PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal | Palo Alto Networks | Cloud NGFW | - | - | 2026-05-06 18:57:40 | Deep Dive |
| CVE-2026-41938 | Vvveb < 1.0.8.2 RCE via Media Upload Handler | givanz | Vvveb | High | 8.8 | 2026-05-06 18:42:36 | Deep Dive |
| CVE-2026-41930 | Vvveb < 1.0.8.2 Hard-coded Credentials Information Disclosure via phpMyAdmin | givanz | Vvveb | Critical | 9.8 | 2026-05-06 18:37:46 | Deep Dive |
| CVE-2026-41931 | Vvveb < 1.0.8.2 Information Disclosure via Debug Exception Handler | givanz | Vvveb | Medium | 5.3 | 2026-05-06 18:36:13 | Deep Dive |
| CVE-2026-41934 | Vvveb < 1.0.8.2 Authenticated RCE via Code Editor | givanz | Vvveb | High | 8.8 | 2026-05-06 18:34:54 | Deep Dive |
| CVE-2026-41936 | Vvveb < 1.0.8.2 XML External Entity Injection via Import | givanz | Vvveb | High | 8.1 | 2026-05-06 18:27:42 | Deep Dive |
| CVE-2024-30151 | HCL BigFix Service Management (SM) is susceptible to Broken Access Control Vulnerability | HCL | BigFix Service Management (SM) | High | 8.3 | 2026-05-06 18:14:12 | Deep Dive |
| CVE-2026-8021 | Google Chrome 代码注入漏洞 | Chrome | 中危 | - | 2026-05-06 18:13:16 | Deep Dive | |
| CVE-2026-8020 | Google Chrome 安全漏洞 | Chrome | - | - | 2026-05-06 18:13:16 | Deep Dive | |
| CVE-2026-8022 | Google Chrome 跨站请求伪造漏洞 | Chrome | 中危 | - | 2026-05-06 18:13:16 | Deep Dive | |
| CVE-2026-8017 | Google Chrome 安全漏洞 | Chrome | 中危 | - | 2026-05-06 18:13:15 | Deep Dive |