Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-48912 — Apache Answer: Improper authorization in avatar update cleanup allows authenticated users…

Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing ownership check in the avatar-cleanup logic allows any authenticated user to de…

answer | Authorization
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
0.0 NA
CVE-2026-48911 — Apache Answer: Unauthenticated OAuth Email-Binding Account Takeover via Existing User Con…

Insufficient Verification of Data Authenticity vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing authorization check in the external-login email binding flo…

answer | Authentication
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
0.0 NA
CVE-2026-48834 — Apache Answer: Denial of service via crafted Accept-Language header parsing

Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Unauthenticated attackers can cause a denial of service via a sp…

answer | Denial of Service
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
7.6 HIGH
CVE-2026-39924 — Flarum < 1.8.16 Session Persistence via Improper Access Token Revocation

Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid session token to retain full account access after a victim changes their password, …

Remote | Authentication
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
9.2 CRITICAL
CVE-2026-39923 — Flarum < 1.8.16 Password Reset Token Expiry Bypass via POST /reset

Flarum before 1.8.16 contains a password reset token expiry bypass vulnerability that allows unauthenticated attackers to reuse expired password reset tokens by submitting them directly to the reset …

Remote | Authentication
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
5.3 MEDIUM
CVE-2026-18531 — IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerable to multip…

IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use of a weak HMAC session signing secret.

maximo_application_suite | Remote | Cryptography
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
7.4 HIGH
CVE-2026-16442 — Keycloak-services: keycloak-services: saml idp-initiated broker login bypasses link-only …

A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fail…

single_sign-on data_grid build_of_keycloak | Remote | Authentication
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
4.3 MEDIUM
CVE-2026-15656 — IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerable to multip…

IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link t…

maximo_application_suite | Remote | Information Disclosure
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
9.4 CRITICAL
CVE-2026-15587 — Privilege Escalation in Google SecOps (Chronicle SOAR) via Crafted Authentication Header

Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to escalate privileges to system-level administrativ…

Remote | Authorization
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
8.8 HIGH
CVE-2026-15572 — Keycloak-services: keycloak-services: dcr protocol mapper type-swap policy bypass allows …

A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restricts which types of data mappers a client can use, …

build_of_keycloak | Remote | Authorization
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
4.7 MEDIUM
CVE-2026-13477 — IBM QRadar SIEM is vulnerable to remote code execution by privileged users

IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with normal user privileges on the system …

qradar | Remote | Injection
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
5.3 MEDIUM
CVE-2026-12762 — Insertion of Sensitive Information into Externally-Accessible File in IBM Business Automa…

IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensitive information exposed in manifest files.

cloud_pak_for_business_automation | Remote | Information Disclosure
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
3.8 LOW
CVE-2026-12730 — Improper Validation of Certificate with Host Mismatch in IBM Business Automation Workflow…

IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim Fix 009 IBM Busines…

Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
8.2 HIGH
CVE-2026-10025 — IBM QRadar SIEM has an XML External Entity (XXE) injection vulnerability

IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function…

qradar | Remote | XML External Entity
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
5.5 MEDIUM
CVE-2026-14587 — Unathenticated connection can hold Bolt channel open

Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask. When an unauthenticated client sends a selected protocol version followed by …

community_edition enterprise_edition | Remote | Misconfiguration
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
0.0 NA
CVE-2026-54876 — Client-Side Memory Leak in OCSP Response Checking

Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries. Impact sum…

| Denial of Service
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
7.5 HIGH
CVE-2026-17613 — CVE-2026-17613

Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated user to overwrite any files on the target server and subscribe to WebSocket eve…

Remote | Authorization
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
8.1 HIGH
CVE-2026-16102 — Keycloak-services: keycloak-services: default dcr policy allows role forgery via user pro…

A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User …

single_sign-on data_grid build_of_keycloak | Remote | Authorization
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
6.5 MEDIUM
CVE-2026-16100 — Keycloak-services: keycloak-services: unbounded metric cardinality in user event metrics …

A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because t…

single_sign-on data_grid build_of_keycloak | Remote | Information Disclosure
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
5.4 MEDIUM
CVE-2026-16071 — Keycloak-services: keycloak-services: ldap entry-dn user search bypasses configured users…

A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when a delegated administrator performs a search using…

single_sign-on data_grid build_of_keycloak | Remote | Information Disclosure
Aug 05, 2026 Aug 05, 2026
Aug 05, 2026
Aug 05, 2026
Showing 20 of 9798 Results