Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
1.6 LOW
CVE-2026-7860 — Possible information disclosure of environment variables in Vaadin Build Plugins via Fail…

A possible information disclosure vulnerability exists in the Vaadin Maven plugin and Vaadin Gradle plugin that exposes the full set of environment variables in build logs whenever the frontend build…

| Information Disclosure
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
7.1 HIGH
CVE-2026-7571 — Keycloak: keycloak: access token disclosure and implicit flow bypass via forged client da…

A flaw was found in Keycloak. A low-privilege user, with knowledge of user credentials and client ID, can bypass a security control intended to disable the implicit flow in OpenID Connect (OIDC) clie…

Remote | Authentication
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
7.5 HIGH
CVE-2026-7507 — Org.keycloak/keycloak-services: session fixation in oidc login flow that can lead to acco…

A session fixation vulnerability was found in Keycloak's login-actions endpoints. An unauthenticated attacker could exploit this flaw by pre-creating an authentication session and tricking a victim i…

Remote | Authentication
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
8.1 HIGH
CVE-2026-7504 — Org.keycloak/keycloak-services: open redirect when using wildcard valid redirect uris in …

A flaw was found in Keycloak's URL validation logic during redirect operations. By crafting a malicious request, an attacker could bypass validation to redirect users to unauthorized URLs, potentiall…

Remote | Server-Side Request Forgery
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
7.5 HIGH
CVE-2026-7307 — Keycloak: keycloak: denial of service via specially crafted saml input

A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML) endpoint. This malicious input can cause high …

Remote | Denial of Service
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
6.8 MEDIUM
CVE-2026-4630 — Keycloak: keycloak: unauthorized resource access and data modification via insecure direc…

A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Services Protection API endpoint. By knowing or obtai…

Remote | Authorization
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
4.3 MEDIUM
CVE-2026-45442 — WordPress Presto Player plugin <= 4.1.3 - Broken Access Control vulnerability

Missing Authorization vulnerability in Brainstorm Force Presto Player allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Presto Player: from n/a through 4.1.…

Remote | Authorization
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
0.0 NA
CVE-2026-43493 — crypto: pcrypt - Fix handling of MAY_BACKLOG requests

In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Fix handling of MAY_BACKLOG requests MAY_BACKLOG requests can return EBUSY. Handle them by checking for that va…

| Cryptography
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
0.0 NA
CVE-2026-43492 — lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl()

In the Linux kernel, the following vulnerability has been resolved: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() Yiming reports an integer underflow in mpi_read_raw_from_sgl() …

| Memory Corruption
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
0.0 NA
CVE-2026-43491 — net: qrtr: ns: Limit the maximum server registration per node

In the Linux kernel, the following vulnerability has been resolved: net: qrtr: ns: Limit the maximum server registration per node Current code does no bound checking on the number of servers added …

| Denial of Service
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
6.8 MEDIUM
CVE-2026-37982 — Keycloak: org.keycloak.authentication: keycloak: unauthorized account takeover via webaut…

A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `ExecuteActionsActionToken` tokens within Keycloak's WebAuthn (Web Authentication) flow. By intercep…

Remote | Authentication
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
4.3 MEDIUM
CVE-2026-37981 — Keycloak: org.keycloak.authorization: keycloak: information disclosure via broken access …

A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows a remote authenticated user, who owns at least one User-Managed Access (UMA) r…

Remote | Authorization
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
6.5 MEDIUM
CVE-2026-37979 — Keycloak: keycloak: information disclosure via oidc token introspection endpoint audience…

A flaw was found in Keycloak. This access control vulnerability in Keycloak's OpenID Connect (OIDC) token introspection endpoint allows a confidential client to bypass audience restrictions. An attac…

Remote | Authorization
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
4.9 MEDIUM
CVE-2026-37978 — Keycloak: org.keycloak.services: keycloak: information disclosure via evaluate-scopes adm…

A flaw was found in Keycloak. A low-privilege administrator with the 'view-clients' role can exploit this by invoking the 'evaluate-scopes' Admin API endpoints with an arbitrary user ID (userId) para…

Remote | Authorization
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
0.0 NA
CVE-2026-4883 — Piotnet Forms <= 2.1.40 - Unauthenticated Arbitrary File Upload via Form File Upload

The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'piotnetforms_ajax_form_builder' function in all versions up to, and including…

| Misconfiguration
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
0.0 NA
CVE-2026-8912 — Contest Gallery <= 28.1.6 - Unauthenticated SQL Injection

The Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the 'form_input' parameter in versions up to, and including, 28.1.6. This is due to insufficient escaping on the user suppl…

| Injection
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
8.2 HIGH
CVE-2026-8827 — SQL Injection in extension "Address List" (tt_address)

The AddressRepository::getSqlQuery() method constructs a database query without properly sanitizing user input, leading to SQL Injection. The method is not invoked anywhere within the extension itsel…

Remote | Injection
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
7.1 HIGH
CVE-2026-8727 — Remote Code Execution in extension "Site Crawler" (crawler)

The Crawler extension passes the X-T3Crawler-Meta response header from crawled URLs directly to PHP's unserialize(). An attacker controlling a crawled endpoint can inject arbitrary serialized PHP obj…

Remote | Information Disclosure
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
8.2 HIGH
CVE-2026-8726 — SQL Injection in extension "News system" (news)

The extension fails to properly sanitize user input before using it in a database query. As a result, an unauthenticated attacker can inject arbitrary SQL through a URL parameter on pages using the "…

Remote | Injection
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
9.2 CRITICAL
CVE-2026-46725 — Remote Code Execution in extension "Content Element Selector" (ceselector)

The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input. A remote, unauthenticated attacker can supply a crafted serialized payload to t…

Remote | Injection
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
Showing 20 of 6281 Results