Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
1.8 LOW
CVE-2025-14575 — Uncontrolled Search Path Element in Qt Network OpenSSL TLS backend allows rogue CA certif…

An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (Unix) allows a local attacker to load a rogue CA certificate as a trusted syste…

| Path Traversal
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
7.5 HIGH
CVE-2026-8912 — Contest Gallery <= 28.1.6 - Unauthenticated SQL Injection

The Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the 'form_input' parameter in versions up to, and including, 28.1.6. This is due to insufficient escaping on the user suppl…

contest_gallery | Remote | Injection
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
9.8 CRITICAL
CVE-2026-4883 — Piotnet Forms <= 2.1.40 - Unauthenticated Arbitrary File Upload via Form File Upload

The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'piotnetforms_ajax_form_builder' function in all versions up to, and including…

piotnet_forms | Remote | Misconfiguration
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
1.6 LOW
CVE-2026-7860 — Possible information disclosure of environment variables in Vaadin Build Plugins via Fail…

A possible information disclosure vulnerability exists in the Vaadin Maven plugin and Vaadin Gradle plugin that exposes the full set of environment variables in build logs whenever the frontend build…

flow | Information Disclosure
May 19, 2026 May 21, 2026
May 19, 2026
May 21, 2026
7.1 HIGH
CVE-2026-7571 — Keycloak: keycloak: access token disclosure and implicit flow bypass via forged client da…

A flaw was found in Keycloak. A low-privilege user, with knowledge of user credentials and client ID, can bypass a security control intended to disable the implicit flow in OpenID Connect (OIDC) clie…

build_of_keycloak | Remote | Authentication
May 19, 2026 Jun 03, 2026
May 19, 2026
Jun 03, 2026
7.5 HIGH
CVE-2026-7507 — Org.keycloak/keycloak-services: session fixation in oidc login flow that can lead to acco…

A session fixation vulnerability was found in Keycloak's login-actions endpoints. An unauthenticated attacker could exploit this flaw by pre-creating an authentication session and tricking a victim i…

keycloak build_of_keycloak | Remote | Authentication
May 19, 2026 Jun 03, 2026
May 19, 2026
Jun 03, 2026
8.1 HIGH
CVE-2026-7504 — Org.keycloak/keycloak-services: open redirect when using wildcard valid redirect uris in …

A flaw was found in Keycloak's URL validation logic during redirect operations. By crafting a malicious request, an attacker could bypass validation to redirect users to unauthorized URLs, potentiall…

keycloak build_of_keycloak | Remote | Server-Side Request Forgery
May 19, 2026 Jun 03, 2026
May 19, 2026
Jun 03, 2026
7.5 HIGH
CVE-2026-7307 — Keycloak: keycloak: denial of service via specially crafted saml input

A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML) endpoint. This malicious input can cause high …

keycloak build_of_keycloak | Remote | Denial of Service
May 19, 2026 Jun 03, 2026
May 19, 2026
Jun 03, 2026
6.8 MEDIUM
CVE-2026-4630 — Keycloak: keycloak: unauthorized resource access and data modification via insecure direc…

A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Services Protection API endpoint. By knowing or obtai…

build_of_keycloak | Remote | Authorization
May 19, 2026 Jun 03, 2026
May 19, 2026
Jun 03, 2026
4.3 MEDIUM
CVE-2026-45442 — WordPress Presto Player plugin <= 4.1.3 - Broken Access Control vulnerability

Missing Authorization vulnerability in Brainstorm Force Presto Player allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Presto Player: from n/a through 4.1.…

presto_player | Remote | Authorization
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
9.8 CRITICAL
CVE-2026-43493 — crypto: pcrypt - Fix handling of MAY_BACKLOG requests

In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Fix handling of MAY_BACKLOG requests MAY_BACKLOG requests can return EBUSY. Handle them by checking for that va…

linux_kernel | Remote | Cryptography
May 19, 2026 Jun 01, 2026
May 19, 2026
Jun 01, 2026
0.0 NA
CVE-2026-43492 — lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl()

In the Linux kernel, the following vulnerability has been resolved: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() Yiming reports an integer underflow in mpi_read_raw_from_sgl() …

linux_kernel | Memory Corruption
May 19, 2026 May 22, 2026
May 19, 2026
May 22, 2026
0.0 NA
CVE-2026-43491 — net: qrtr: ns: Limit the maximum server registration per node

In the Linux kernel, the following vulnerability has been resolved: net: qrtr: ns: Limit the maximum server registration per node Current code does no bound checking on the number of servers added …

linux_kernel | Denial of Service
May 19, 2026 May 22, 2026
May 19, 2026
May 22, 2026
6.8 MEDIUM
CVE-2026-37982 — Keycloak: org.keycloak.authentication: keycloak: unauthorized account takeover via webaut…

A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `ExecuteActionsActionToken` tokens within Keycloak's WebAuthn (Web Authentication) flow. By intercep…

build_of_keycloak | Remote | Authentication
May 19, 2026 Jun 03, 2026
May 19, 2026
Jun 03, 2026
4.3 MEDIUM
CVE-2026-37981 — Keycloak: org.keycloak.authorization: keycloak: information disclosure via broken access …

A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows a remote authenticated user, who owns at least one User-Managed Access (UMA) r…

build_of_keycloak | Remote | Authorization
May 19, 2026 Jun 03, 2026
May 19, 2026
Jun 03, 2026
6.5 MEDIUM
CVE-2026-37979 — Keycloak: keycloak: information disclosure via oidc token introspection endpoint audience…

A flaw was found in Keycloak. This access control vulnerability in Keycloak's OpenID Connect (OIDC) token introspection endpoint allows a confidential client to bypass audience restrictions. An attac…

build_of_keycloak | Remote | Authorization
May 19, 2026 Jun 03, 2026
May 19, 2026
Jun 03, 2026
4.9 MEDIUM
CVE-2026-37978 — Keycloak: org.keycloak.services: keycloak: information disclosure via evaluate-scopes adm…

A flaw was found in Keycloak. A low-privilege administrator with the 'view-clients' role can exploit this by invoking the 'evaluate-scopes' Admin API endpoints with an arbitrary user ID (userId) para…

build_of_keycloak | Remote | Authorization
May 19, 2026 Jun 03, 2026
May 19, 2026
Jun 03, 2026
8.2 HIGH
CVE-2026-8827 — SQL Injection in extension "Address List" (tt_address)

The AddressRepository::getSqlQuery() method constructs a database query without properly sanitizing user input, leading to SQL Injection. The method is not invoked anywhere within the extension itsel…

Remote | Injection
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
7.1 HIGH
CVE-2026-8727 — Remote Code Execution in extension "Site Crawler" (crawler)

The Crawler extension passes the X-T3Crawler-Meta response header from crawled URLs directly to PHP's unserialize(). An attacker controlling a crawled endpoint can inject arbitrary serialized PHP obj…

Remote | Information Disclosure
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
8.2 HIGH
CVE-2026-8726 — SQL Injection in extension "News system" (news)

The extension fails to properly sanitize user input before using it in a database query. As a result, an unauthenticated attacker can inject arbitrary SQL through a URL parameter on pages using the "…

Remote | Injection
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
Showing 20 of 7032 Results