Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-18437 — MailPress <= 1.5.0 - Missing Authorization to Unauthenticated Contact Updates

The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `mailerpress/v1/contact` endpoint in …

Remote | Authorization
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
5.3 MEDIUM
CVE-2026-18436 — MailerPress <= 1.5.0 - Missing Authorization to Unauthenticated Arbitrary Modification vi…

The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the campaign revision-restore REST endpoint (POST /wp-json/mailpress/v1/campaign/<i…

Remote | Authorization
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
7.5 HIGH
CVE-2026-15722 — 389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from…

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into …

Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
7.5 HIGH
CVE-2026-11770 — 389-ds-base: 389-ds-base: pre-auth ldap filter injection in cleanallruv status check

A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler perfo…

Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
8.5 HIGH
CVE-2026-10079 — Stackrox: stackrox: deploy-time policy enforcement and visibility bypass via label inject…

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deplo…

advanced_cluster_security | Remote | Misconfiguration
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
8.1 HIGH
CVE-2026-65313 — Use of hard-coded VNC credentials in the engineering-workstation provisioning

A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applied to every workstati…

| Misconfiguration
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
5.3 MEDIUM
CVE-2026-65311 — Missing authentication for logging-configuration endpoint

The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoint that changes the server's logging level and target without requiring authent…

Remote | Misconfiguration
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
7.5 HIGH
CVE-2026-65310 — Missing authentication and permissive CORS policy

ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any authentication and permissive CORS on every respons…

Remote | Authentication
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
7.5 HIGH
CVE-2026-65309 — Storage of passwords in a reversible format

ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash. This allows an attacker able to read the…

Remote | Cryptography
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
4.2 MEDIUM
CVE-2026-18218 — Keycloak-services: keycloak-services: client not-before revocation ignored when realm not…

A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application (client) using a "not-before" po…

single_sign-on data_grid build_of_keycloak | Remote | Authentication
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
3.4 LOW
CVE-2026-18217 — Keycloak-services: keycloak-services: saml http-redirect binding response preserves query…

A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs when Keycloak handles SAML authentication requests using the…

single_sign-on data_grid build_of_keycloak | Remote | Authentication
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
6.8 MEDIUM
CVE-2026-18215 — Keycloak-services: keycloak-services: microsoft external access-token exchange bypasses c…

Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discovered where this restriction is ignored when using t…

single_sign-on data_grid build_of_keycloak | Remote | Authorization
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
6.8 MEDIUM
CVE-2026-18214 — Keycloak-services: keycloak-services: google external access-token exchange bypasses host…

Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was found where the token exchange feature, which allows…

single_sign-on data_grid build_of_keycloak | Remote | Authentication
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
4.2 MEDIUM
CVE-2026-18211 — Keycloak-services: keycloak-services: secure-client-uris policy bypass via localhost-pref…

A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This component is responsible for enforcing security requirements on client configurations, such as re…

single_sign-on data_grid build_of_keycloak | Remote | Server-Side Request Forgery
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
3.4 LOW
CVE-2026-18209 — Keycloak-services: keycloak-services: oidc redirect_uri fragment bypass in http parameter…

A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed to prevent HTTP paramet…

single_sign-on data_grid build_of_keycloak | Remote | Authentication
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
6.5 MEDIUM
CVE-2026-18208 — Keycloak-services: keycloak-services: inactive out-of-audience token introspection leaks …

A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access management solution used to secure modern applications and…

single_sign-on data_grid build_of_keycloak | Remote | Information Disclosure
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
3.7 LOW
CVE-2026-18206 — Keycloak-services: keycloak-services: client policy source-host wildcard domain matching …

A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services. The issue occurs when a realm administrator uses a wildcard domain (like *.exa…

single_sign-on data_grid build_of_keycloak | Remote | Authorization
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
6.5 MEDIUM
CVE-2026-18203 — Keycloak-services: keycloak-services: group policy extendchildren matches sibling group p…

A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to extend permissions to child groups, the system incorrectly…

single_sign-on data_grid build_of_keycloak | Remote | Authorization
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
4.9 MEDIUM
CVE-2026-16105 — Keycloak-services: keycloak-services: missing per-role authorization on rolecontainerreso…

A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoints in the admin REST API do not properly enforce authorization checks when mana…

single_sign-on data_grid build_of_keycloak | Remote | Authorization
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
0.0 NA
CVE-2026-8155 — BuddyPress < 14.5.0 - Subscriber+ Private Messages Disclosure via IDOR

The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints, allowing any authenticated user (Subscriber+) to read, modify, or delete othe…

| Authorization
Jul 31, 2026 Jul 31, 2026
Jul 31, 2026
Jul 31, 2026
Showing 20 of 9517 Results