Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.9 MEDIUM
CVE-2026-9801 — Keycloak: keycloak: denial of service via malformed ldap password policy response

A flaw was found in Keycloak. A remote attacker with high privileges, such as a realm administrator configuring a malicious Lightweight Directory Access Protocol (LDAP) server or an attacker compromi…

build_of_keycloak | Remote | Denial of Service
May 28, 2026 Jun 10, 2026
May 28, 2026
Jun 10, 2026
4.3 MEDIUM
CVE-2026-9798 — Keycloak: keycloak: brute-force protection bypass in ciba flow

A flaw was found in Keycloak, an open-source identity and access management solution. When a user account is temporarily locked due to repeated failed login attempts, an attacker with valid client cr…

build_of_keycloak | Remote | Authentication
May 28, 2026 Jun 03, 2026
May 28, 2026
Jun 03, 2026
6.8 MEDIUM
CVE-2026-9673 — Json-2-Csv CSV Injection

Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via the preventCsvInjection option which can be bypassed. An attacker can inject formulas into CSV fil…

| Injection
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
6.4 MEDIUM
CVE-2026-9644 — LiveSmart Video Chat <= 1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

The LiveSmart Video Chat Live Video Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'livesmart_widget' shortcode in all versions up to, and including, 1.2 due …

Remote | Cross-Site Scripting
May 28, 2026 May 28, 2026
May 28, 2026
May 28, 2026
8.8 HIGH
CVE-2026-9009 — Crawlomatic Multipage Scraper Post Generator <= 2.7.2 - Authenticated (Author+) Remote Co…

The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.7.2 via the filter_content function. This is due t…

Remote | Injection
May 28, 2026 May 28, 2026
May 28, 2026
May 28, 2026
4.3 MEDIUM
CVE-2026-7533 — Easy Digital Downloads <= 3.6.7 - Cross-Site Request Forgery to Payment Account Hijacking…

The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.7. This is due to missing nonce verification in the `handle_oauth…

easy_digital_downloads | Remote | Cross-Site Request Forgery
May 28, 2026 May 28, 2026
May 28, 2026
May 28, 2026
6.5 MEDIUM
CVE-2026-3173 — Meta Field Block <= 1.5.1 - Insecure Direct Object Reference to Authenticated (Contributo…

The Meta Field Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.5.1. This is due to the plugin allowing users to specify arbitrary …

Remote | Authorization
May 28, 2026 May 28, 2026
May 28, 2026
May 28, 2026
Showing 20 of 7887 Results