Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 3 April 2026
RSS134 vulnerabilities published on 3 April 2026
Severity:
OpenClaw: Open to CSRF attacks in trusted-proxy mode
GHSA-mhr7-2xmv-4c4q
OpenClaw's HTTP endpoints don't properly check where requests come from when using trusted-proxy mode, which could allow a malicious website to trick users into performing actions they don't intend. T...
5.3
Electron: Malicious Input Can Leak Sensitive Data on macOS and Linux
GHSA-3c8v-cfp5-9885
CVE-2026-34776
Electron apps on macOS and Linux may leak sensitive information when handling certain inputs. This issue only affects apps that use a specific feature and run as the same user. To fix, update to a pat...
5.3
OpenClaw Misses Important Security Settings for Docker and Git
GHSA-9gp8-hjxr-6f34
The OpenClaw software has a security issue that allows it to bypass important security settings for Docker and Git, potentially exposing sensitive data. This issue affects versions of OpenClaw up to 2...
4.8
Electron: Attackers can hijack Windows protocol handlers
GHSA-mwmh-mq4g-g6gr
CVE-2026-34773
If you're using Electron, check if you're passing untrusted input to the setAsDefaultProtocolClient method on Windows. If you are, an attacker could potentially take control of your app's protocol han...
4.7
Incorrect password comparison in Roundcube Webmail leads to password change
CVE-2026-35541
A security issue in Roundcube Webmail allows an attacker to change a user's password without knowing the current one. This could be exploited by someone who has access to the user's account. To fix th...
4.2
Electron: Malicious app can hijack login on Windows
GHSA-jfqx-fxh3-c62j
CVE-2026-34768
If an Electron app is installed in a folder with a space in its name, an attacker could trick Windows into running a different program at login. This could happen if the app is installed by a standard...
3.9
Roundcube Webmail: Unauthenticated attackers can write arbitrary files
CVE-2026-35537
This security issue affects older versions of Roundcube Webmail. An attacker could potentially write files on your server without being authenticated, which could lead to data loss or damage. Update t...
3.7
GRID Organiser App (Android) uses hardcoded encryption key
CVE-2026-5454
The GRID Organiser App on Android versions up to 1.0.5 stores an encryption key directly in the app's code, making it vulnerable to unauthorized access if an attacker gains access to the device. This ...
1.9
Rico só vantagem pra investir App for Android has a Security Key Leak
CVE-2026-5453
A security weakness has been found in the Rico só vantagem pra investir App for Android. This means that a hacker could potentially access sensitive information by manipulating a specific setting. App...
1.9
UCC CampusConnect App for Android Uses Hardcoded Security Key
CVE-2026-5452
A security flaw in the UCC CampusConnect App for Android versions up to 14.3.5 could allow an attacker to access sensitive information. This is because the app uses a hardcoded security key, rather th...
1.9
Electron: Malicious Device Can Be Selected by Untrusted App
GHSA-9899-m83m-qhpj
CVE-2026-34766
An Electron app may allow a device to be selected that doesn't meet the app's security filters. This is fixed in updated versions of Electron. To stay secure, update to Electron 41.0.0-beta.8, 40.7.0,...
3.3
Roundcube Webmail search function allows attackers to inject malicious commands
CVE-2026-35538
A security issue in Roundcube Webmail allows an attacker to potentially inject malicious commands or bypass security checks when searching emails. This could be used to hijack user sessions or steal s...
3.1
Discord Voice Chat Access Can Be Bypassed in OpenClaw
GHSA-x2m8-53h4-6hch
A security issue in OpenClaw's Discord integration allows anyone to join voice chats in certain channels, even if they shouldn't be able to. This is because the system doesn't properly check if a user...
2.3
OpenClaw: Unsecured Web Sessions After Password Change
GHSA-rfqg-qgf8-xr9x
If you're using OpenClaw version 2026.3.28 or earlier, an attacker who already has access to your system could potentially stay connected even after you change your password. This is a relatively low-...
2.3
Signal K Server: Unprivileged User Can Read Sensitive Data
CVE-2026-35038
GHSA-qh3j-mrg8-f234
Signal K Server versions prior to 2.24.0 allow a user with limited access to view sensitive information they shouldn't be able to see. This is a security risk because it could expose confidential data...
2.1
OpenClaw Can Reload Inactive Settings After Restart
GHSA-3pm9-5j7m-59vc
An issue in OpenClaw's startup migration process can cause it to reload previously revoked settings from a file after a restart. This can potentially allow users to bypass security restrictions. To fi...
2.1
Telnyx Webhook Signature Bypass in OpenClaw
GHSA-37v6-fxx8-xjmx
A security issue in the OpenClaw package allows attackers to bypass verification of Telnyx webhooks, potentially allowing malicious requests to be treated as legitimate. This could lead to unauthorize...
1.7
Apache Commons Compress: Uncontrolled Resource Consumption
ECHO-abe8-b546-ad42
The Apache Commons Compress library has a bug that can cause a denial-of-service (DoS) attack if an attacker sends a specially crafted file. This can lead to a server crash or slowdown. Update to a fi...
Apache HTTP Server allows remote attacker to access sensitive files
ECHO-185f-c78c-4e82
A flaw in the Apache HTTP Server can allow an attacker to access files on a website that they shouldn't be able to access. This could happen if the server is not configured correctly. To fix this, upd...
Microsoft Office Memory Corruption Leads to Remote Code Execution
ECHO-758d-edbe-6881
A vulnerability in Microsoft Office can allow attackers to execute malicious code on a victim's computer by sending a specially crafted file. This could potentially allow a hacker to take control of t...
Apache HTTP Server Cross-Site Scripting (XSS) in mod_proxy_ajp
ECHO-9e39-7166-9c17
Apache's HTTP Server has a security issue that allows an attacker to inject malicious code into web pages. This can happen when a user visits a website that uses Apache's mod_proxy_ajp module to conne...
Adobe Flash Player allows attackers to run malicious code
ECHO-bc93-24a8-8727
Adobe Flash Player has a security vulnerability that could allow hackers to execute unauthorized code on a user's computer. This could lead to data theft, system compromise, or other malicious activit...
Apache HTTP Server Unauthenticated Remote Code Execution
ECHO-f8cb-56ce-2d8e
Apache HTTP Server's mod_proxy module has a vulnerability that allows an attacker to execute code on a remote server without needing a password. This could allow an attacker to take control of the ser...
Apache HTTP Server Allows Remote Code Execution
ECHO-2e96-17f7-cc4b
Apache's web server software has a flaw that could let hackers run malicious code on your server. This means an attacker could take control of your server and do whatever they want. You should update ...
Apache HTTP Server: Malicious Files Can Be Served
ECHO-ac58-cda1-4c8b
Apache HTTP Server may allow attackers to serve malicious files. This could happen if a server is configured to use a directory traversal attack, allowing attackers to serve files outside of the inten...