Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-31933 — Suricata stream: quadratic complexity in stream inspection

Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, specially crafted traffic can cause Suricata to slow down, affecting performance in IDS mode. This issue has been pa…

Remote | Denial of Service
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
7.5 HIGH
CVE-2026-31932 — Suricata krb5: quadratic complexity in krb5 buffering

Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, inefficiency in KRB5 buffering can lead to performance degradation. This issue has been patched in versions 7.0.15 a…

Remote | Denial of Service
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
7.5 HIGH
CVE-2026-31931 — Suricata tls: null dereference in tls.alpn rule keyword

Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, use of the "tls.alpn" rule keyword can cause Suricata to crash with a NULL dereference. This issue has been …

Remote | Denial of Service
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
5.7 MEDIUM
CVE-2026-30867 — CocoaMQTT: Denial of Service via Reachable Assertion in `PUBLISH` Packet Parsing

CocoaMQTT is a MQTT 5.0 client library for iOS and macOS written in Swift. Prior to version 2.2.2, a vulnerability exists in the packet parsing logic of CocoaMQTT that allows an attacker (or a compro…

Remote | Denial of Service
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
8.5 HIGH
CVE-2026-2737 — Possibility of unintended actions when an administrator clicks a malicious link in the Pr…

A vulnerability exists in Progress Flowmon versions prior to 12.5.8 and 13.0.6, whereby an administrator who clicks a malicious link provided by an attacker may inadvertently trigger unintended actio…

Remote | Cross-Site Request Forgery
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
9.1 CRITICAL
CVE-2026-2701 — RCE vulnerability in Progress ShareFile Storage Zones Controller (SZC)

Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.

Remote | Authentication
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
9.8 CRITICAL
CVE-2026-2699 — EAR vulnerability in Progress ShareFile Storage Zones Controller (SZC)

Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote…

Remote | Authentication
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
7.2 HIGH
CVE-2026-29782 — OpenSTAManager: Remote Code Execution via Insecure Deserialization in OAuth2

OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, the oauth2.php file in OpenSTAManager is an unauthenticated endpoint ($skip_permi…

openstamanager | Remote | Authentication
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
8.8 HIGH
CVE-2026-28805 — OpenSTAManager: Time-Based Blind SQL Injection via `options[stato]` Parameter

OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, multiple AJAX select handlers in OpenSTAManager are vulnerable to Time-Based Blin…

openstamanager | Remote | Injection
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
8.7 HIGH
CVE-2026-26928 — Lack of Dynamic Library Validation in SzafirHost

SzafirHost downloads necessary files in the context of the initiating web page. When called, SzafirHost updates its dynamic library. JAR files are correctly verified based on a list of trusted file h…

Remote | Misconfiguration
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
5.1 MEDIUM
CVE-2026-26927 — URL (HTTP Origin) call location spoofing in Szafir SDK Web

Szafir SDK Web is a browser plug-in that can run SzafirHost application which download the necessary files when launched. In Szafir SDK Web it is possible to change the URL (HTTP Origin) of the appli…

Remote | Authentication
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
5.8 MEDIUM
CVE-2026-5331 — OpenCart Extension Installer installer.php path traversal

A vulnerability was determined in OpenCart 4.1.0.3. This affects an unknown part of the file installer.php of the component Extension Installer Page. Executing a manipulation can lead to path travers…

Remote | Path Traversal
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
6.9 MEDIUM
CVE-2026-5330 — SourceCodester/mayuri_k Best Courier Management System User Delete ajax.php access control

A vulnerability was found in SourceCodester/mayuri_k Best Courier Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=delete_user of the component…

Remote | Authorization
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
6.5 MEDIUM
CVE-2026-5328 — shsuishang modulithshop ProductItemDao ProductIndexServiceImpl.java listItem sql injection

A weakness has been identified in shsuishang modulithshop up to 829bac71f507e84684c782b9b062b8bf3b5585d6. The impacted element is the function listItem of the file src/main/java/com/suisung/shopsuite…

Remote | Injection
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
8.1 HIGH
CVE-2026-4636 — Keycloak: keycloak: uma policy bypass allows authenticated users to gain unauthorized acc…

A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) policy validation. This allows the attacker to include resource identifiers owned…

Remote | Authorization
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
7.5 HIGH
CVE-2026-4634 — Keycloak: keycloak: denial of service via excessive processing of openid connect scope pa…

A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with an excessively long scope parameter to the OpenID Connect (OI…

Remote | Denial of Service
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
5.3 MEDIUM
CVE-2026-4325 — Keycloak: keycloak: replay of action tokens via improper handling of single-use entries

A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an attacker to delete arbitrary single-use en…

Remote | Misconfiguration
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
7.4 HIGH
CVE-2026-4282 — Keycloak: keycloak: privilege escalation via forged authorization codes due to singleuseo…

A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attacker to forge authoriz…

Remote | Authorization
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
7.3 HIGH
CVE-2026-3872 — Keycloak: keycloak: information disclosure due to redirect_uri validation bypass

A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect Uniform Resource Identifiers (URIs) that use a wi…

Remote | Information Disclosure
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
6.5 MEDIUM
CVE-2026-34890 — WordPress MSTW League Manager plugin <= 2.10 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mark O’Donnell MSTW League Manager allows DOM-Based XSS.This issue affects MSTW League Manager: f…

Remote | Cross-Site Scripting
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
Showing 20 of 6379 Results