Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-18437 — MailPress <= 1.5.0 - Missing Authorization to Unauthenticated Contact Updates

The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `mailerpress/v1/contact` endpoint in …

Remote | Authorization
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
5.3 MEDIUM
CVE-2026-18436 — MailerPress <= 1.5.0 - Missing Authorization to Unauthenticated Arbitrary Modification vi…

The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the campaign revision-restore REST endpoint (POST /wp-json/mailpress/v1/campaign/<i…

Remote | Authorization
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
7.5 HIGH
CVE-2026-15722 — 389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from…

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into …

Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
7.5 HIGH
CVE-2026-11770 — 389-ds-base: 389-ds-base: pre-auth ldap filter injection in cleanallruv status check

A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler perfo…

Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
8.5 HIGH
CVE-2026-10079 — Stackrox: stackrox: deploy-time policy enforcement and visibility bypass via label inject…

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deplo…

advanced_cluster_security | Remote | Misconfiguration
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
0.0 NA
CVE-2026-64607 — Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to P…

HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header valu…

| Misconfiguration
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
0.0 NA
CVE-2026-62391 — Apache Kyuubi: kyuubi.session.local.dir.allow.list bypass via unprefixed Spark file-conf …

The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via…

kyuubi | Misconfiguration
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
0.0 NA
CVE-2026-17567 — Fluent Forms <= 6.2.8 - Unauthenticated Sensitive Information Exposure via Insecure Direc…

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including,…

| Information Disclosure
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
7.2 HIGH
CVE-2026-16843 — Hikvision Wireless Access Point Authenticated Command Injection

Some Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted…

Remote | Injection
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
8.1 HIGH
CVE-2026-65313 — Use of hard-coded VNC credentials in the engineering-workstation provisioning

A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applied to every workstati…

| Misconfiguration
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
5.3 MEDIUM
CVE-2026-65311 — Missing authentication for logging-configuration endpoint

The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoint that changes the server's logging level and target without requiring authent…

Remote | Misconfiguration
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
7.5 HIGH
CVE-2026-65310 — Missing authentication and permissive CORS policy

ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any authentication and permissive CORS on every respons…

Remote | Authentication
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
7.5 HIGH
CVE-2026-65309 — Storage of passwords in a reversible format

ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash. This allows an attacker able to read the…

Remote | Cryptography
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
4.2 MEDIUM
CVE-2026-18218 — Keycloak-services: keycloak-services: client not-before revocation ignored when realm not…

A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application (client) using a "not-before" po…

single_sign-on data_grid build_of_keycloak | Remote | Authentication
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
3.4 LOW
CVE-2026-18217 — Keycloak-services: keycloak-services: saml http-redirect binding response preserves query…

A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs when Keycloak handles SAML authentication requests using the…

single_sign-on data_grid build_of_keycloak | Remote | Authentication
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
6.8 MEDIUM
CVE-2026-18215 — Keycloak-services: keycloak-services: microsoft external access-token exchange bypasses c…

Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discovered where this restriction is ignored when using t…

single_sign-on data_grid build_of_keycloak | Remote | Authorization
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
6.8 MEDIUM
CVE-2026-18214 — Keycloak-services: keycloak-services: google external access-token exchange bypasses host…

Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was found where the token exchange feature, which allows…

single_sign-on data_grid build_of_keycloak | Remote | Authentication
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
4.2 MEDIUM
CVE-2026-18211 — Keycloak-services: keycloak-services: secure-client-uris policy bypass via localhost-pref…

A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This component is responsible for enforcing security requirements on client configurations, such as re…

single_sign-on data_grid build_of_keycloak | Remote | Server-Side Request Forgery
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
3.4 LOW
CVE-2026-18209 — Keycloak-services: keycloak-services: oidc redirect_uri fragment bypass in http parameter…

A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed to prevent HTTP paramet…

single_sign-on data_grid build_of_keycloak | Remote | Authentication
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
6.5 MEDIUM
CVE-2026-18208 — Keycloak-services: keycloak-services: inactive out-of-audience token introspection leaks …

A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access management solution used to secure modern applications and…

single_sign-on data_grid build_of_keycloak | Remote | Information Disclosure
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
Showing 20 of 9622 Results