🛡️ CVE Intelligence Center
Common Vulnerabilities & Exposures — Security Intelligence Database
| CVE ID | Severity | CVSS | Description | Status | Published |
|---|---|---|---|---|---|
| CVE-2026-35669 | High | 8.8 |
OpenClaw before 2026.3.25 contains a privilege escalation vulnerability in gateway-authenticated plugin HTTP routes that…
|
✅ Patch | Apr 10, 2026 |
| CVE-2026-4351 | High | 8.1 |
The Perfmatters plugin for WordPress is vulnerable to arbitrary file overwrite via path traversal in all versions up to,…
|
— | Apr 10, 2026 |
| CVE-2026-35653 | High | 8.1 |
OpenClaw before 2026.3.24 contains an incorrect authorization vulnerability in the POST /reset-profile endpoint that all…
|
⚡ Exploit ✅ Patch | Apr 10, 2026 |
| CVE-2026-35660 | High | 8.1 |
OpenClaw before 2026.3.23 contains an insufficient access control vulnerability in the Gateway agent /reset endpoint tha…
|
✅ Patch | Apr 10, 2026 |
| CVE-2021-47961 | High | 8.1 |
A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to …
|
— | Apr 10, 2026 |
| CVE-2026-35641 | High | 7.8 |
OpenClaw before 2026.3.24 contains an arbitrary code execution vulnerability in local plugin and hook installation that …
|
⚡ Exploit | Apr 10, 2026 |
| CVE-2026-35668 | High | 7.7 |
OpenClaw before 2026.3.24 contains a path traversal vulnerability in sandbox enforcement allowing sandboxed agents to re…
|
⚡ Exploit | Apr 10, 2026 |
| CVE-2026-3360 | High | 7.5 |
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to an Insecure Direct Object Ref…
|
— | Apr 10, 2026 |
| CVE-2026-40073 | High | 7.5 |
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.57.1, under…
|
✅ Patch | Apr 10, 2026 |
| CVE-2026-40074 | High | 7.5 |
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.57.1, redir…
|
✅ Patch | Apr 10, 2026 |
| CVE-2026-35650 | High | 7.5 |
OpenClaw before 2026.3.22 contains an environment variable override handling vulnerability that allows attackers to bypa…
|
✅ Patch | Apr 10, 2026 |
| CVE-2026-6038 | High | 7.3 |
A vulnerability was identified in code-projects Vehicle Showroom Management System 1.0. This impacts an unknown function…
|
— | Apr 10, 2026 |
| CVE-2026-6024 | High | 7.3 |
A vulnerability was determined in Tenda i6 1.0.0.7(2204). Affected by this issue is the function R7WebsSecurityHandlerfu…
|
— | Apr 10, 2026 |
| CVE-2026-6004 | High | 7.3 |
A vulnerability was detected in code-projects Simple IT Discussion Forum 1.0. Impacted is an unknown function of the fil…
|
— | Apr 10, 2026 |
| CVE-2026-6037 | High | 7.3 |
A vulnerability was determined in code-projects Vehicle Showroom Management System 1.0. This affects an unknown function…
|
— | Apr 10, 2026 |
| CVE-2026-6031 | High | 7.3 |
A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0. This affects an unknown function of the …
|
— | Apr 10, 2026 |
| CVE-2026-6036 | High | 7.3 |
A vulnerability was found in code-projects Vehicle Showroom Management System 1.0. The impacted element is an unknown fu…
|
— | Apr 10, 2026 |
| CVE-2026-29002 | High | 7.2 |
CouchCMS contains a privilege escalation vulnerability that allows authenticated Admin-level users to create SuperAdmin …
|
⚡ Exploit | Apr 10, 2026 |
| CVE-2026-33704 | High | 7.1 |
Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user (including students) can write arb…
|
✅ Patch | Apr 10, 2026 |
| CVE-2026-4162 | High | 7.1 |
The Gravity SMTP plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.4. Th…
|
— | Apr 10, 2026 |