A vulnerability classified as very critical was found in Linux Kernel up to 7.1.3. This issue affects some unknown processing of the file kvm_mm.h of the component guest_memfd. Executing a manipulation can lead to integer overflow.
This vulnerability appears as CVE-2026-64283. The attack requires local access. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability marked as critical has been reported in cozmoslabs User Profile Builder Plugin up to 3.15.5 on WordPress. This affects the function wppb_save_avatar_value. Performing a manipulation results in authorization bypass.
This vulnerability is identified as CVE-2026-3139. The attack can be initiated remotely. There is not any exploit available.
A vulnerability was found in OpenClaw up to 2026.3.10. It has been declared as problematic. The affected element is an unknown function. The manipulation results in time-of-check time-of-use.
This vulnerability is known as CVE-2026-32977. Attacking locally is a requirement. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability was found in OpenClaw up to 2026.3.10. It has been rated as problematic. The impacted element is an unknown function. This manipulation of the argument gateway.auth.token/gateway.auth.password causes not failing securely.
This vulnerability is handled as CVE-2026-32970. It is possible to launch the attack on the local host. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability categorized as problematic has been discovered in OpenClaw up to 2026.3.12. This affects the function fetchRemoteMedia of the component Error Message Handler. Such manipulation leads to sensitive information in log files.
This vulnerability is uniquely identified as CVE-2026-32982. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability labeled as critical has been found in OpenClaw up to 2026.3.7. Affected is an unknown function. Executing a manipulation can lead to time-of-check time-of-use.
The identification of this vulnerability is CVE-2026-32921. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
A vulnerability, which was classified as problematic, has been found in OpenClaw up to 2026.3.10. This issue affects some unknown processing of the file /config of the component Configuration Handler. Performing a manipulation results in authorization bypass.
This vulnerability is cataloged as CVE-2026-32976. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in OpenClaw up to 2026.3.10. Impacted is an unknown function of the component Temporary File Handler. Executing a manipulation can lead to time-of-check time-of-use.
This vulnerability is registered as CVE-2026-32988. The attack needs to be launched locally. No exploit is available.
You should upgrade the affected component.
A vulnerability has been found in teckel Minify HTML Plugin up to 2.1.12 on WordPress and classified as problematic. The affected element is the function minify_html_menu_options of the component Setting Handler. The manipulation leads to cross-site request forgery.
This vulnerability is documented as CVE-2026-3191. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
A vulnerability was found in OpenClaw up to 2026.3.11. It has been declared as problematic. This impacts an unknown function of the file OpenClaw/extensions/ of the component Workspace Handler. Such manipulation leads to inclusion of functionality from untrusted control sphere.
This vulnerability is traded as CVE-2026-32920. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability labeled as problematic has been found in OpenClaw up to 2026.3.10. This affects an unknown part. The manipulation results in clickjacking.
This vulnerability was named CVE-2026-32971. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
A vulnerability, which was classified as problematic, has been found in Sixth. The impacted element is an unknown function of the component Terminal Command Handler. The manipulation leads to injection.
This vulnerability is listed as CVE-2026-30310. The attack may be initiated remotely. There is no available exploit.
在一群初创公司之后,科技巨头如微软、英伟达、思科、戴尔、IBM、甚至 OpenAI 等数十家公司和组织联署发表公开信,呼吁美国政府不要过早限制开放权重模型,认为此举会扼杀竞争或导致本土创新放缓。公开信称,开放权重模型能促进竞争,确保 AI 技术的好处能广泛共享,避免其掌握在少数人手中,而闭源模型并不意味着绝对安全。没有署名的知名 AI 公司包括了 Google、Anthropic 以及 xAI/SpaceX,其中 SpaceX CEO 马斯克通过社交媒体口头表达了对公开信的支持,而 Anthropic 明显是站在支持限制开放权重模型的一边,该公司正投入 4000 万美元游说特朗普政府加强监管 AI 模型。
A vulnerability classified as problematic has been found in Linux Kernel up to 7.1.3. This vulnerability affects unknown code of the component elan_i2c. Performing a manipulation of the argument x_traces/y_traces/width results in divide by zero.
This vulnerability is reported as CVE-2026-64275. The attack requires a local approach. No exploit exists.
It is recommended to upgrade the affected component.