2026-05-05
2026-05-05 12:16Z
HIGH

CVE-2026-6261 — Betheme: The Betheme theme for WordPress is vulnerable to Arbitrary File Upload in versions up

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6261

The Betheme theme for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 28.4. This is due to the upload_icons() function workflow moving and unzipping user-controlled ZIP files into a public uploads directory without validating extracted file types. This makes it possible for authenticated attackers, with author-level access and above, to upload arbitrary files (including PHP) and achieve remote code execution via the Icons icon-pack upload fl CVSSv3.1 8.8 (HIGH)

CWECWE 434VNDBethemeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-05
2026-05-05 12:16Z
HIGH

CVE-2026-43571 — OpenClaw: before 2026.4.10 contains a plugin trust bypass vulnerability that allows channel setup catalog

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43571

OpenClaw before 2026.4.10 contains a plugin trust bypass vulnerability that allows channel setup catalog lookups to resolve workspace plugin shadows before bundled channel plugins. Attackers can exploit this by crafting malicious workspace plugins that bypass intended trust gates during setup-time plugin loading. CVSSv3.1 8.8 (HIGH)

CWECWE 829VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-05
2026-05-05 12:16Z
HIGH

CVE-2026-43569 — OpenClaw: before 2026.4.9 contains an authentication bypass vulnerability allowing untrusted workspace plugins to be

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43569

OpenClaw before 2026.4.9 contains an authentication bypass vulnerability allowing untrusted workspace plugins to be auto-enabled during non-interactive onboarding when provider auth choices are shadowed. Attackers can exploit this by crafting malicious workspace plugins that are automatically selected and enabled during authentication setup without explicit user consent. CVSSv3.1 8.8 (HIGH)

CWECWE 829VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-05
2026-05-05 12:16Z
CRIT

CVE-2026-43566 — OpenClaw: versions 2026.4.7 before 2026.4.14 contain a privilege escalation vulnerability where heartbeat owner downgrade

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43566

OpenClaw versions 2026.4.7 before 2026.4.14 contain a privilege escalation vulnerability where heartbeat owner downgrade logic skips webhook wake events carrying untrusted content. Attackers can exploit this by sending untrusted webhook wake events to preserve owner-like execution context when the run should have been downgraded. CVSSv3.1 9.1 (CRITICAL)

CWECWE 184VNDOpenclawTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-05
2026-05-05 12:16Z
CRIT

CVE-2026-43534 — OpenClaw: before 2026.4.10 contains an input validation vulnerability that allows external hook metadata to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43534

OpenClaw before 2026.4.10 contains an input validation vulnerability that allows external hook metadata to be enqueued as trusted system events. Attackers can supply malicious hook names to escalate untrusted input into higher-trust agent context. CVSSv3.1 9.1 (CRITICAL)

CWECWE 345VNDOpenclawTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-05
2026-05-05 12:16Z
HIGH

CVE-2026-43533 — OpenClaw: before 2026.4.10 contains an arbitrary file read vulnerability in QQBot media tags that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43533

OpenClaw before 2026.4.10 contains an arbitrary file read vulnerability in QQBot media tags that allows attackers to reference host-local paths outside the intended media storage boundary. Attackers can craft malicious reply text containing media tags to disclose arbitrary local files through outbound media handling. CVSSv3.1 8.6 (HIGH)

CWECWE 23VNDOpenclawTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-05-05
2026-05-05 12:16Z
HIGH

CVE-2026-43530 — OpenClaw: versions 2026.2.23 before 2026.4.12 contain a weakened exec approval binding vulnerability in busybox

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43530

OpenClaw versions 2026.2.23 before 2026.4.12 contain a weakened exec approval binding vulnerability in busybox and toybox applet execution that allows attackers to obscure which applet would actually run. Attackers can exploit opaque multi-call binaries to bypass exec approval mechanisms and weaken risk classification of unsafe applet invocations. CVSSv3.1 8.8 (HIGH)

CWECWE 863VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-05
2026-05-05 12:16Z
HIGH

CVE-2026-43526 — OpenClaw: before 2026.4.12 contains a server-side request forgery vulnerability in QQBot reply media URL

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43526

OpenClaw before 2026.4.12 contains a server-side request forgery vulnerability in QQBot reply media URL handling that allows attackers to fetch arbitrary content. Attackers can exploit this by providing malicious media URLs that trigger SSRF requests, with fetched bytes subsequently re-uploaded through the channel. CVSSv3.1 8.2 (HIGH)

CWECWE 918VNDOpenclawTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-05
2026-05-05 12:16Z
HIGH

CVE-2026-42439 — OpenClaw: before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in the browser

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42439

OpenClaw before 2026.4.10 contains a server-side request forgery policy bypass vulnerability in the browser tabs action select and close routes. Attackers can bypass configured browser SSRF policy protections by exploiting the /tabs/action endpoint to perform unauthorized tab navigation operations. CVSSv3.1 8.5 (HIGH)

CWECWE 862VNDOpenclawTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-05-05
2026-05-05 12:16Z
HIGH

CVE-2026-42435 — OpenClaw: versions from 2026.2.22 before 2026.4.12 contain an insufficient shell-wrapper detection vulnerability allowing attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42435

OpenClaw versions from 2026.2.22 before 2026.4.12 contain an insufficient shell-wrapper detection vulnerability allowing attackers to inject environment variable assignments at the argv level. Attackers can bypass exec preflight handling to manipulate high-risk shell variables like SHELLOPTS and PS4, affecting execution semantics and security controls. CVSSv3.1 8.8 (HIGH)

CWECWE 184VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-05
2026-05-05 12:16Z
HIGH

CVE-2026-42434 — OpenClaw: Attackers can bypass sandbox boundaries and route execution to remote nodes instead of intended

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42434

OpenClaw versions 2026.4.5 before 2026.4.10 contain a sandbox escape vulnerability allowing sandboxed agents to override exec routing by specifying host=node. Attackers can bypass sandbox boundaries and route execution to remote nodes instead of intended sandbox paths. CVSSv3.1 8.8 (HIGH)

CWECWE 863VNDOpenclawTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-05
2026-05-05 12:16Z
HIGH

CVE-2023-54348 — ERPGo: SaaS 3.9 contains a CSV injection vulnerability that allows authenticated attackers to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2023-54348

ERPGo SaaS 3.9 contains a CSV injection vulnerability that allows authenticated attackers to execute arbitrary code by injecting formula payloads into vendor name fields. Attackers can add malicious formulas like =10+20+cmd|' /C calc'!A0 in the vendor creation form, which execute when the exported CSV file is opened in spreadsheet applications. CVSSv3.1 8.8 (HIGH)

CWECWE 1236VNDErpgoTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-05
2026-05-05 12:16Z
HIGH

CVE-2023-54345 — Frappe: Framework ERPNext 13.4.0 contains a sandbox escape vulnerability in RestrictedPython that allows authenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2023-54345

Frappe Framework ERPNext 13.4.0 contains a sandbox escape vulnerability in RestrictedPython that allows authenticated users with System Manager role to execute arbitrary code by exploiting frame introspection. Attackers can create a server script via the /app/server-script endpoint and access the gi_frame attribute to traverse the call stack and invoke os.popen to execute system commands. CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDFrappeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-05
2026-05-05 12:16Z
CRIT

CVE-2023-54344 — Eclipse: Equinox OSGi 3.7.2 and earlier contains a remote code execution vulnerability that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2023-54344

Eclipse Equinox OSGi 3.7.2 and earlier contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by sending payloads to the console interface. Attackers can connect to the OSGi console port and send base64-encoded bash commands wrapped in fork directives to achieve code execution and establish reverse shell connections. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDEclipseTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-05
2026-05-05 12:16Z
CRIT

CVE-2023-54342 — Eclipse: Equinox OSGi versions 3.8 through 3.18 contain a remote code execution vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2023-54342

Eclipse Equinox OSGi versions 3.8 through 3.18 contain a remote code execution vulnerability in the console interface that allows unauthenticated attackers to execute arbitrary code by exploiting the fork command functionality. Attackers can establish a telnet connection to the OSGi console, perform a telnet handshake, and send fork commands to download and execute malicious Java code, establishing a reverse shell connection. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDEclipseTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-05
2026-05-05 11:00Z
HIGH

C/C++ checklist challenges, solved

Trail of Bits·blog.trailofbits.com

Trail of Bits published a detailed walkthrough of two C/C++ security challenges: a Linux ping program vulnerable to command injection via inet_ntoa's global buffer reuse and inet_aton's acceptance of trailing garbage, and a Windows driver registry handler vulnerable to type confusion in RtlQueryRegistryValues when RTL_QUERY_REGISTRY_TYPECHECK is missing. The Windows vulnerability can escalate from DoS to kernel write primitive by exploiting REG_SZ type confusion to write arbitrary data to kernel stack memory.

SRFOsTACTA0004TACTA0002OSLinuxOSWindowsTYPResearchTYPVulnerabilitySTGPrivesc
78
Edit Score
2026-05-05
2026-05-05 07:16Z
HIGH

CVE-2026-6180 — Papercut Papercut_mf: A race condition exists in PaperCut MF when processing badge-swipe data from certain HP

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6180

A race condition exists in PaperCut MF when processing badge-swipe data from certain HP multifunction devices. Under specific network conditions involving dropped packets and out-of-order sequence counters, the server may incorrectly process fragmented data chunks. If a sequence reset notification fails to reach the server, the server may reject the initial data chunk while erroneously accepting subsequent chunks before a connection reset completes. This leads to the regis CVSSv3.1 8.1 (HIGH) · EPSS 12th percentile

CWECWE 20CWECWE 367VNDPapercutTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-05
2026-05-05 07:16Z
CRIT

CVE-2026-40797 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-40797

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder LLC WebinarIgnition allows Blind SQL Injection. This issue affects WebinarIgnition: from n/a through 4.08.253. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-05-05
2026-05-05 05:16Z
CRIT

CVE-2026-7823 — The manipulation of the argument enable results in os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7823

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setAppFilterCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument enable results in os command injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. CVSSv3.1 9.8 (CRITICAL)

CWECWE 77CWECWE 78TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-05
2026-05-05 04:16Z
CRIT

CVE-2026-5294 — Geeky: The Geeky Bot plugin for WordPress is vulnerable to Missing Authorization in versions up

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5294

The Geeky Bot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.2.2. This is due to a nopriv AJAX route allowing attacker-controlled model/function dispatch and reaching a plugin installer helper that downloads and unzips attacker-supplied ZIP files into wp-content/plugins/. This makes it possible for unauthenticated attackers to perform arbitrary plugin installation and achieve remote code execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 862VNDGeekyTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-05
2026-05-05 04:16Z
HIGH

CVE-2026-35228 — Vulnerability: Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-35228

Vulnerability in the Oracle MCP Server Helper Tool product of Oracle Open Source Projects (component: helper tool). The supported versions that is affected is 1.0.1-1.0.156. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle MCP Server Helper Tool. Successful attacks of this vulnerability can result in Oracle MCP Server Helper Tool executing malicious SQL. CVSSv3.1 8.7 (HIGH)

VNDVulnerabilityTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-05-05
2026-05-05 03:15Z
CRIT

CVE-2025-13618 — Mentoring: The Mentoring plugin for WordPress is vulnerable to privilege escalation in all versions up

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-13618

The Mentoring plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.8. This is due to the plugin not properly restricting the roles that users can register with in the mentoring_process_registration() function. This makes it possible for unauthenticated attackers to register with administrator-level user accounts. CVSSv3.1 9.8 (CRITICAL)

CWECWE 269VNDMentoringTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-05
2026-05-05 02:16Z
CRIT

CVE-2026-5722 — MoreConvert: The MoreConvert Pro plugin for WordPress is vulnerable to Authentication Bypass in all versions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-5722

The MoreConvert Pro plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.9.14. This is due to the guest waitlist verification flow not invalidating or regenerating verification tokens when the customer email address is changed. This makes it possible for unauthenticated attackers to authenticate as existing users, including administrators, by obtaining a valid guest verification token for an attacker-controlled email, changing th CVSSv3.1 9.8 (CRITICAL)

CWECWE 287VNDMoreconvertTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-05
2026-05-05 00:00Z
INFO

Your UEBA is lying to you: Why entity record quality decides everything

Elastic Security Labs·elastic.co

Elastic Security Labs publishes a technical deep-dive on User and Entity Behavior Analytics (UEBA) architecture, arguing that entity record quality—not ML models—determines detection fidelity. The post contrasts two extremes (bare username matching vs. IdP-only records), proposes a confidence-tiered governance model separating identity-provider-backed entities from endpoint-observed local accounts, and describes automatic entity resolution across fragmented identity systems to unify cross-provider risk signals.

SRFApplicationTACTA0001SRFIdentitySWElastic SecurityVNDElasticTYPResearchTECT1087
68
Edit Score
2026-05-05
2026-05-05 00:00Z
CRIT

InstallFix and Claude Code: How Fake Install Pages Lead to Real Compromise

Trend Micro Research·trendmicro.comin the wild

Trend Micro disclosed the InstallFix campaign, a multi-stage malware distribution operation leveraging fake Claude AI installer pages promoted via Google Ads to target users across multiple industries and regions. The attack chain uses mshta.exe, obfuscated PowerShell, VBScript COM abuse, AMSI bypass, SSL validation disabling, and victim-unique C&C URLs to achieve persistence and data collection; the final payload exhibits RedLine stealer indicators and collects browser/e-wallet credentials.

SRFApplicationTACTA0005TACTA0001TACTA0002TACTA0006SRFWebTACTA0009OSWindows
82
Edit Score