Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-43000 — OpenStack Keystone Trust Delegation Privilege Escalation Vulnerability

An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to ad…

keystone | Remote | Authorization
May 28, 2026 Jun 02, 2026
May 28, 2026
Jun 02, 2026
8.8 HIGH
CVE-2026-42999 — OpenStack Keystone JSON Injection Vulnerability

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary …

keystone | Remote | Authorization
May 28, 2026 Jun 02, 2026
May 28, 2026
Jun 02, 2026
8.8 HIGH
CVE-2026-42998 — OpenStack Keystone Credential Authentication Impersonation

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the…

keystone | Remote | Authentication
May 28, 2026 Jun 02, 2026
May 28, 2026
Jun 02, 2026
7.3 HIGH
CVE-2026-30761 — SourceBans Material Admin File Upload RCE

An arbitrary file upload vulnerability in the pages/admin.uploadmapimg.php component of SourceBans Material Admin v1.1.6 allows attackers to execute arbitrary code via uploading a crafted image file.

Remote | Misconfiguration
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
7.3 HIGH
CVE-2026-30760 — SourceBans Material Admin Unauthenticated Arbitrary Data Manipulation Vulnerability

An issue in SourceBans Material Admin before v.1.1.6 (3ecd95e) allows attackers to manipulate arbitrary user data in the web app via a crafted XAJAX call.

Remote | Injection
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
Showing 20 of 7645 Results