7.1

CVSS4.0

CVE-2026-42433 - OpenClaw < 2026.4.10 - Unauthorized Matrix Profile Config Persistence Access via operator.write Mes…

OpenClaw before 2026.4.10 contains an authorization bypass vulnerability allowing operator.write message-tool paths to access Matrix profile persistence requiring admin-level authority. Attackers can exploit insufficient access controls to mutate persistent profile configuration through non-owner m…

πŸ“… Published: May 5, 2026, 11:24 a.m. πŸ”„ Last Modified: May 5, 2026, 1:48 p.m.

5.1

CVSS4.0

CVE-2023-54349 - AmazCart CMS 3.4 Reflected Cross-Site Scripting via Search

AmazCart CMS 3.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search functionality. Attackers can enter script tags in the search box to execute arbitrary JavaScript that fires when searc…

πŸ“… Published: May 5, 2026, 11:24 a.m. πŸ”„ Last Modified: May 6, 2026, 9:21 a.m.

8.7

CVSS4.0

CVE-2023-54348 - ERPGo SaaS 3.9 CSV Injection via Vendor Creation

ERPGo SaaS 3.9 contains a CSV injection vulnerability that allows authenticated attackers to execute arbitrary code by injecting formula payloads into vendor name fields. Attackers can add malicious formulas like =10+20+cmd|' /C calc'!A0 in the vendor creation form, which execute when the exported …

πŸ“… Published: May 5, 2026, 11:24 a.m. πŸ”„ Last Modified: May 6, 2026, 9:21 a.m.

8.7

CVSS4.0

CVE-2023-54347 - OpenEMR 7.0.1 Authentication Brute Force Mitigation Bypass

OpenEMR 7.0.1 contains an authentication brute force vulnerability that allows attackers to bypass rate limiting protections by sending repeated login attempts to the main login endpoint. Attackers can submit POST requests with authUser and clearPass parameters to systematically test username and p…

πŸ“… Published: May 5, 2026, 11:24 a.m. πŸ”„ Last Modified: May 5, 2026, 11:24 a.m.

8.7

CVSS4.0

CVE-2023-54346 - WordPress Plugin Backup Migration 1.2.8 Unauthenticated Database Backup Download

WordPress Plugin Backup Migration 1.2.8 contains an information disclosure vulnerability that allows unauthenticated attackers to download complete database backups by accessing predictable file paths. Attackers can enumerate backup directories through configuration files and complete logs, then co…

πŸ“… Published: May 5, 2026, 11:24 a.m. πŸ”„ Last Modified: May 6, 2026, 9:21 a.m.

8.7

CVSS4.0

CVE-2023-54345 - Frappe Framework ERPNext 13.4.0 Remote Code Execution

Frappe Framework ERPNext 13.4.0 contains a sandbox escape vulnerability in RestrictedPython that allows authenticated users with System Manager role to execute arbitrary code by exploiting frame introspection. Attackers can create a server script via the /app/server-script endpoint and access the g…

πŸ“… Published: May 5, 2026, 11:24 a.m. πŸ”„ Last Modified: May 5, 2026, 8:07 p.m.

9.3

CVSS4.0

CVE-2023-54344 - Eclipse Equinox OSGi 3.7.2 Remote Code Execution via Console

Eclipse Equinox OSGi 3.7.2 and earlier contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by sending payloads to the console interface. Attackers can connect to the OSGi console port and send base64-encoded bash commands wrapped in for…

πŸ“… Published: May 5, 2026, 11:24 a.m. πŸ”„ Last Modified: May 6, 2026, 9:21 a.m.

9.3

CVSS4.0

CVE-2023-54342 - Eclipse Equinox OSGi 3.8-3.18 Console Remote Code Execution

Eclipse Equinox OSGi versions 3.8 through 3.18 contain a remote code execution vulnerability in the console interface that allows unauthenticated attackers to execute arbitrary code by exploiting the fork command functionality. Attackers can establish a telnet connection to the OSGi console, perfor…

πŸ“… Published: May 5, 2026, 11:24 a.m. πŸ”„ Last Modified: May 6, 2026, 9:21 a.m.

6.5

CVSS3.1

CVE-2025-42611 - Improper certificate validation in multiple RouterOS services

RouterOS provides various services that rely on correct verification of client and server certificates to secure confidentiality and integrity of communications. This includes OpenVPN, CAPsMAN, Dot1x (802.1X), among others. The vulnerability lies in shared certificate validation logic which uses…

πŸ“… Published: May 5, 2026, 10:58 a.m. πŸ”„ Last Modified: May 5, 2026, 3 p.m.

7.5

CVSS3.1

CVE-2026-6322 - fast-uri vulnerable to host confusion via percent-encoded authority delimiters

fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an allowed domain, an encoded at-sign, and a different domain was re-emitted with the at-sign as a raw userinfo separator…

πŸ“… Published: May 5, 2026, 10:29 a.m. πŸ”„ Last Modified: May 6, 2026, 9:21 a.m.
Total resulsts: 349182
Page 116 of 34,919
Β« previous page Β» next page
Filters