|
1881
|
8.8 |
HIGH
Network
|
sailpoint
|
identityiq
|
This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the definition of a role without having an assigned…
|
CWE-863
Incorrect Authorization
|
CVE-2026-5712
|
2026-05-5 21:48 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1882
|
7.1 |
HIGH
Local
|
dell
|
dell\/alienware_purchased_apps
|
Dell/Alienware Purchased Apps, versions prior to 1.1.31.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could p…
|
CWE-59
Link Following
|
CVE-2026-27105
|
2026-05-5 21:37 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1883
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Betheme theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 28.4. This is due to the upload_icons() function workflow using a user-controlled upload pat…
|
CWE-22
Path Traversal
|
CVE-2026-6262
|
2026-05-5 21:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1884
|
8.8 |
HIGH
Network
|
-
|
-
|
The Betheme theme for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 28.4. This is due to the upload_icons() function workflow moving and unzipping user-controlled…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-6261
|
2026-05-5 21:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1885
|
7.5 |
HIGH
Network
|
-
|
-
|
OpenClaw versions 2026.4.9 before 2026.4.10 contain a denial of service vulnerability in the voice-call realtime WebSocket path that accepts oversized frames without proper validation. Remote attacke…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-42437
|
2026-05-5 21:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1886
|
7.7 |
HIGH
Network
|
-
|
-
|
OpenClaw before 2026.4.14 contains an improper access control vulnerability in browser snapshot, screenshot, and tab routes that fail to consistently validate the final browser target after navigatio…
|
CWE-862
Missing Authorization
|
CVE-2026-42436
|
2026-05-5 21:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1887
|
8.8 |
HIGH
Network
|
-
|
-
|
OpenClaw versions from 2026.2.22 before 2026.4.12 contain an insufficient shell-wrapper detection vulnerability allowing attackers to inject environment variable assignments at the argv level. Attack…
|
CWE-184
Incomplete Blacklist
|
CVE-2026-42435
|
2026-05-5 21:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1888
|
8.8 |
HIGH
Network
|
-
|
-
|
OpenClaw versions 2026.4.5 before 2026.4.10 contain a sandbox escape vulnerability allowing sandboxed agents to override exec routing by specifying host=node. Attackers can bypass sandbox boundaries …
|
CWE-863
Incorrect Authorization
|
CVE-2026-42434
|
2026-05-5 21:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1889
|
6.5 |
MEDIUM
Network
|
-
|
-
|
OpenClaw before 2026.4.10 contains an authorization bypass vulnerability allowing operator.write message-tool paths to access Matrix profile persistence requiring admin-level authority. Attackers can…
|
CWE-862
Missing Authorization
|
CVE-2026-42433
|
2026-05-5 21:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1890
|
6.1 |
MEDIUM
Network
|
-
|
-
|
AmazCart CMS 3.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search functionality. Att…
|
CWE-79
Cross-site Scripting
|
CVE-2023-54349
|
2026-05-5 21:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|