Threat Intelligence Feed

Real-Time Cyber Threat Data

Vulnerability intelligence, CVE tracking, and threat actor analysis — powered by OpenCTI and curated for cyber insurance professionals.

197 threats
Critical 29
High 155
Medium 13
Low 0
197
Total Threats
29
Critical
155
High
184
Vulnerabilities
Known Exploited

Last updated: May 8, 2026

Sort:
critical 1mo ago

🔍 CVE-2026-40281

CVE UNKNOWN with CVSS 10. Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint validates metadata keys for control characters but leaves metadata values unsanitized. A newline character in a metadata value splits the ExifTool stdin line into two separate argum

cve UNKNOWN cvss-10
10
CVSS
critical 1mo ago

🔍 CVE-2026-43575

CVE UNKNOWN with CVSS 9.8. OpenClaw versions 2026.2.21 before 2026.4.10 contain an authentication bypass vulnerability in the sandbox noVNC helper route that exposes interactive browser session credentials. Attackers can access the noVNC helper route without bridge authentication to gain unauthorized access to the interactive

cve UNKNOWN cvss-9
9.8
CVSS
critical 1mo ago

🔍 CVE-2026-44109

CVE UNKNOWN with CVSS 9.8. OpenClaw before 2026.4.15 contains an authentication bypass vulnerability in Feishu webhook and card-action validation that allows unauthenticated requests to reach command dispatch. Missing encryptKey configuration and blank callback tokens fail open instead of rejecting requests, enabling attacker

cve UNKNOWN cvss-9
9.8
CVSS
critical 1mo ago

🔍 CVE-2026-43581

CVE UNKNOWN with CVSS 9.6. OpenClaw before 2026.4.10 contains an improper network binding vulnerability in the sandbox browser CDP relay that exposes Chrome DevTools Protocol on 0.0.0.0. Attackers can access the DevTools protocol outside intended local sandbox boundaries by exploiting the overly broad binding configuration.

cve UNKNOWN cvss-9
9.6
CVSS
critical 1mo ago

🔍 CVE-2026-43578

CVE UNKNOWN with CVSS 9.1. OpenClaw versions 2026.3.31 before 2026.4.10 contain a privilege escalation vulnerability where heartbeat owner downgrade detection misses local background async exec completion events. Attackers can exploit this by providing untrusted completion content to leave a run in a more privileged context t

cve UNKNOWN cvss-9
9.1
CVSS
high 1mo ago

🔍 CVE-2026-8016

CVE UNKNOWN with CVSS 8.8. Use after free in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

cve UNKNOWN cvss-8
8.8
CVSS
high 1mo ago

🔍 CVE-2026-43584

CVE UNKNOWN with CVSS 8.8. OpenClaw before 2026.4.10 contains an insufficient environment variable denylist vulnerability in its exec environment policy that allows operator-supplied overrides of high-risk interpreter startup variables including VIMINIT, EXINIT, LUA_INIT, and HOSTALIASES. Attackers can exploit this by manipul

cve UNKNOWN cvss-8
8.8
CVSS
high 1mo ago

🔍 CVE-2026-44110

CVE UNKNOWN with CVSS 8.8. OpenClaw before 2026.4.15 contains an authorization bypass vulnerability in Matrix room control-command authorization that trusts DM pairing-store entries. Attackers with DM-paired sender IDs can execute room control commands without being in configured allowlists by posting in bot rooms, potentiall

cve UNKNOWN cvss-8
8.8
CVSS
high 1mo ago

🔍 CVE-2026-44115

CVE UNKNOWN with CVSS 8.8. OpenClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted heredoc bodies. Attackers can bypass allowlist validation by embedding shell expansion tokens in heredoc bodies to execute unapproved commands at runtime.

cve UNKNOWN cvss-8
8.8
CVSS
high 1mo ago

🔍 CVE-2023-1888: CVE-2023-1888

CVE CVE-2023-1888 with CVSS 8.8. The Directorist plugin for WordPress is vulnerable to an arbitrary user password reset in versions up to, and including, 7.5.4. This is due to a lack of validation checks within login.php. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to reset the p

cve CVE-2023-1888 cvss-8
8.8
CVSS
high 1mo ago

🔍 CVE-2023-2237: CVE-2023-2237

CVE CVE-2023-2237 with CVSS 8.8. The WP Replicate Post plugin for WordPress is vulnerable to SQL Injection via the post_id parameter in versions up to, and including, 4.0.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for contributo

cve CVE-2023-2237 cvss-8
8.8
CVSS
high 1mo ago

🔍 CVE-2023-2249: CVE-2023-2249

CVE CVE-2023-2249 with CVSS 8.8. The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, and including, 2.1.7. This is due to the insecure use of file_get_contents without appropriate verification of the data being supplied to the function.

cve CVE-2023-2249 cvss-8
8.8
CVSS
high 1mo ago

🔍 CVE-2026-44116

CVE UNKNOWN with CVSS 8.6. OpenClaw before 2026.4.22 contains a server-side request forgery vulnerability in the Zalo plugin's sendPhoto function that fails to validate outbound photo URLs through the SSRF guard. Attackers can bypass SSRF protection by providing malicious photo URLs to the Zalo Bot API, enabling unauthorized

cve UNKNOWN cvss-8
8.6
CVSS
high 1mo ago

🔍 CVE-2023-1895: CVE-2023-1895

CVE CVE-2023-1895 with CVSS 8.5. The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Server Side Request Forgery via the get_remote_content REST API endpoint in versions up to, and including, 1.8.3. This can allow authenticated attackers with subscriber-level permissions or above to make web requests to arbitrary lo

cve CVE-2023-1895 cvss-8
8.5
CVSS
high 1mo ago

🔍 CVE-2026-8018

CVE UNKNOWN with CVSS 8.1. Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: Low)

cve UNKNOWN cvss-8
8.1
CVSS
high 1mo ago

🔍 CVE-2026-43585

CVE UNKNOWN with CVSS 8.1. OpenClaw before 2026.4.15 captures resolved bearer-auth configuration at startup, allowing revoked tokens to remain valid after SecretRef rotation. Gateway HTTP and WebSocket handlers fail to re-resolve authentication per-request, enabling attackers to use rotated-out bearer tokens for unauthorized

cve UNKNOWN cvss-8
8.1
CVSS
high 1mo ago

🔍 CVE-2026-44114

CVE UNKNOWN with CVSS 7.8. OpenClaw before 2026.4.20 fails to properly reserve the OPENCLAW_ runtime-control environment namespace in workspace dotenv files, allowing attackers to override critical runtime variables. Malicious workspaces can set variables like OPENCLAW_GIT_DIR to manipulate trusted OpenClaw runtime behavior d

cve UNKNOWN cvss-7
7.8
CVSS
high 1mo ago

🔍 CVE-2026-44118

CVE UNKNOWN with CVSS 7.8. OpenClaw before 2026.4.22 derives loopback MCP owner context from spoofable server-issued bearer tokens in request headers. Non-owner loopback clients can present themselves as owner to bypass owner-gated operations by manipulating the sender-owner header metadata.

cve UNKNOWN cvss-7
7.8
CVSS
high 1mo ago

🔍 CVE-2026-43576

CVE UNKNOWN with CVSS 7.7. OpenClaw before 2026.4.5 contains a server-side request forgery vulnerability in the CDP /json/version WebSocket endpoint that allows attackers to pivot to untrusted second-hop targets. The webSocketDebuggerUrl response field is not properly validated, enabling attackers to redirect connections to a

cve UNKNOWN cvss-7
7.7
CVSS
high 1mo ago

🔍 CVE-2026-43580

CVE UNKNOWN with CVSS 7.7. OpenClaw before 2026.4.10 contains an incomplete navigation guard vulnerability that allows attackers to trigger navigation without complete SSRF policy enforcement. Browser press/type style interactions, including pressKey and type submit flows, can bypass post-action security checks to execute una

cve UNKNOWN cvss-7
7.7
CVSS
high 1mo ago

🔍 CVE-2026-8007

CVE UNKNOWN with CVSS 7.5. Insufficient validation of untrusted input in Cast in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)

cve UNKNOWN cvss-7
7.5
CVSS
high 1mo ago

🔍 CVE-2026-8032

CVE UNKNOWN with CVSS 7.3. A flaw has been found in PicoTronica e-Clinic Healthcare System ECHS 5.7. The impacted element is an unknown function of the file /cdemos/echs/priv/echs.js. This manipulation of the argument ADMIN_KEY causes hard-coded credentials. The attack is possible to be carried out remotely. The exploit has b

cve UNKNOWN cvss-7
7.3
CVSS
high 1mo ago

🔍 CVE-2023-2484: CVE-2023-2484

CVE CVE-2023-2484 with CVSS 7.2. The Active Directory Integration plugin for WordPress is vulnerable to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 4.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This

cve CVE-2023-2484 cvss-7
7.2
CVSS
high 1mo ago

🔍 CVE-2023-2607: CVE-2023-2607

CVE CVE-2023-2607 with CVSS 7.2. The Multiple Page Generator Plugin for WordPress is vulnerable to time-based SQL Injection via the orderby and order parameters in versions up to, and including, 3.3.17 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This make

cve CVE-2023-2607 cvss-7
7.2
CVSS
medium 1mo ago

📄 Not-so-SimpleHelp exploits enabling deployment of Sliver backdoor

Threat report published 2025-02-07T00:08:41.573Z. Types: threat-report. A sophisticated breach was identified where threat actors exploited vulnerabilities in SimpleHelp's Remote Monitoring and Management client to infiltrate a network. The attack involved post-compromise

threat-report
6
CVSS
medium 1mo ago

📄 Russian State Actors: Development in Group Attributions

Threat report published 2025-03-08T11:40:18.794Z. Types: threat-report. This analysis explores the evolution of Russian state-backed cyber actors and their operations. It highlights the activities of several prominent groups, including UNC2589, APT44 (Sandworm), APT29, an

threat-report
6
CVSS
medium 1mo ago

📄 Desert Dexter.Attacks on Middle Eastern Countries

Threat report published 2025-03-11T16:42:12.802Z. Types: threat-report. A malicious campaign targeting residents of Middle East and North Africa has been discovered, active since September 2024. The attackers create fake news groups on social media and publish posts with

threat-report
6
CVSS
medium 1mo ago

📄 Camera off: Akira deploys ransomware via webcam

Threat report published 2025-03-11T14:20:07.740Z. Types: threat-report. Akira, a prominent ransomware group, accounted for 15% of incidents in 2024, showcasing novel evasion techniques. In a recent attack, Akira circumvented an Endpoint Detection and Response (EDR) tool b

threat-report
6
CVSS
medium 1mo ago

📄 Analysis of Lazarus Group's Attack Targeting Windows Web Servers

Threat report published 2025-03-11T14:20:42.819Z. Types: threat-report. The Lazarus group has been targeting Windows web servers, particularly in South Korea, installing webshells and C2 scripts to use compromised servers as proxies. The attacks involve multiple stages, i

threat-report
6
CVSS
medium 1mo ago

📄 Trump Cryptocurrency Delivers ConnectWise RAT

Threat report published 2025-03-11T17:34:55.389Z. Types: threat-report. An email campaign impersonating Binance is offering fake TRUMP coins to lure victims into downloading a malicious 'Binance Desktop' application, which actually installs ConnectWise RAT. The attackers

threat-report
6
CVSS

Weekly Digest

Get the week's top threats in 5 minutes

Every Monday: curated vulnerability analysis, insurance impact assessment, and actionable risk insights — delivered to your inbox.