|
451
|
8.2 |
HIGH
Network
|
-
|
-
|
The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the ticket_id parameter.…
New
|
CWE-89
SQL Injection
|
CVE-2018-25404
|
2026-05-30 01:32 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
452
|
- |
|
-
|
-
|
Bolt CMS through 3.7.0 allows SQL Injection in the 'order' parameter of the content listing pages. An authenticated attacker with low-level privileges can exploit this through the OrderDirective comp…
New
|
-
|
CVE-2026-39229
|
2026-05-30 01:32 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
453
|
8.8 |
HIGH
Network
|
-
|
-
|
A weakness has been identified in Shibby Tomato 1.28. This vulnerability affects the function get_ups_field of the file tomatodata.cgi. Executing a manipulation of the argument Date can lead to stack…
New
|
CWE-119 CWE-121
Incorrect Access of Indexable Resource ('Range Error') Stack-based Buffer Overflow
|
CVE-2026-10065
|
2026-05-30 01:29 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
454
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in Media in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: …
New
|
CWE-416
Use After Free
|
CVE-2026-9945
|
2026-05-30 01:29 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
455
|
6.3 |
MEDIUM
Network
|
-
|
-
|
ACM/MCE assisted-service writes raw referenced pull-secret contents into `InfraEnv.status.conditions[].message` when pull-secret validation fails. A namespace principal with the stock `view` ClusterR…
New
|
CWE-201
Insertion of Sensitive Information Into Sent Data
|
CVE-2026-10101
|
2026-05-30 01:29 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
456
|
8.3 |
HIGH
Network
|
-
|
-
|
OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows non-owner authorized chat senders to issue device-pairing bootstrap codes without…
New
|
CWE-862
Missing Authorization
|
CVE-2026-32905
|
2026-05-30 01:29 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
457
|
4.3 |
MEDIUM
Network
|
-
|
-
|
OpenClaw before 2026.5.12 contains a privilege escalation vulnerability in Slack plugin approvals that allows exec-authorized users to resolve plugin approvals through the exec approver gate. Attacke…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-32906
|
2026-05-30 01:29 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
458
|
5.4 |
MEDIUM
Network
|
-
|
-
|
OpenClaw before 2026.4.29 contains a policy bypass vulnerability in QQBot admin commands that allows authenticated senders to skip DM-only and allowFrom policy checks. Attackers can route admin comma…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-34507
|
2026-05-30 01:29 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
459
|
8.0 |
HIGH
Network
|
-
|
-
|
OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to enforce configured approver identity. Non-approver users can click approval but…
New
|
CWE-862
Missing Authorization
|
CVE-2026-35630
|
2026-05-30 01:29 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
460
|
6.5 |
MEDIUM
Network
|
-
|
-
|
OpenClaw before 2026.4.29 contains an SSRF policy bypass vulnerability in browser debug and export routes that allows reuse of already-open blocked tabs. Attackers with access to these routes can byp…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-35673
|
2026-05-30 01:29 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|