Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-4325 — Keycloak: keycloak: replay of action tokens via improper handling of single-use entries

A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an attacker to delete arbitrary single-use en…

keycloak build_of_keycloak | Remote | Misconfiguration
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
7.4 HIGH
CVE-2026-4282 — Keycloak: keycloak: privilege escalation via forged authorization codes due to singleuseo…

A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attacker to forge authoriz…

keycloak build_of_keycloak | Remote | Authorization
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
7.3 HIGH
CVE-2026-3872 — Keycloak: keycloak: information disclosure due to redirect_uri validation bypass

A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect Uniform Resource Identifiers (URIs) that use a wi…

keycloak build_of_keycloak | Remote | Information Disclosure
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
6.5 MEDIUM
CVE-2026-34890 — WordPress MSTW League Manager plugin <= 2.10 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mark O’Donnell MSTW League Manager allows DOM-Based XSS.This issue affects MSTW League Manager: f…

Remote | Cross-Site Scripting
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
6.5 MEDIUM
CVE-2026-5327 — efforthye fast-filesystem-mcp index.ts handleGetDiskUsage command injection

A security flaw has been discovered in efforthye fast-filesystem-mcp up to 3.5.1. The affected element is the function handleGetDiskUsage of the file src/index.ts. Performing a manipulation results i…

fast-filesystem-mcp | Remote | Injection
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
0.0 NA
CVE-2026-23417 — bpf: Fix constant blinding for PROBE_MEM32 stores

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix constant blinding for PROBE_MEM32 stores BPF_ST | BPF_PROBE_MEM32 immediate stores are not handled by bpf_jit_blind_insn…

linux_kernel | Misconfiguration
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
0.0 NA
CVE-2026-23416 — mm/mseal: update VMA end correctly on merge

In the Linux kernel, the following vulnerability has been resolved: mm/mseal: update VMA end correctly on merge Previously we stored the end of the current VMA in curr_end, and then upon iterating …

linux_kernel | Memory Corruption
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
0.0 NA
CVE-2026-23415 — futex: Fix UaF between futex_key_to_node_opt() and vma_replace_policy()

In the Linux kernel, the following vulnerability has been resolved: futex: Fix UaF between futex_key_to_node_opt() and vma_replace_policy() During futex_key_to_node_opt() execution, vma->vm_policy …

linux_kernel | Race Condition
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
0.0 NA
CVE-2026-23414 — tls: Purge async_hold in tls_decrypt_async_wait()

In the Linux kernel, the following vulnerability has been resolved: tls: Purge async_hold in tls_decrypt_async_wait() The async_hold queue pins encrypted input skbs while the AEAD engine references…

linux_kernel | Memory Corruption
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
0.0 NA
CVE-2026-23413 — clsact: Fix use-after-free in init/destroy rollback asymmetry

In the Linux kernel, the following vulnerability has been resolved: clsact: Fix use-after-free in init/destroy rollback asymmetry Fix a use-after-free in the clsact qdisc upon init/destroy rollback…

linux_kernel | Memory Corruption
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
0.0 NA
CVE-2026-23412 — netfilter: bpf: defer hook memory release until rcu readers are done

In the Linux kernel, the following vulnerability has been resolved: netfilter: bpf: defer hook memory release until rcu readers are done Yiming Qian reports UaF when concurrent process is dumping h…

linux_kernel | Memory Corruption
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
5.5 MEDIUM
CVE-2026-5326 — SourceCodester Leave Application System User Information index.php authorization

A vulnerability was identified in SourceCodester Leave Application System 1.0. Impacted is an unknown function of the file /index.php?page=manage_user of the component User Information Handler. Such …

Remote | Authorization
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
8.7 HIGH
CVE-2026-32145 — Multipart form body parser bypasses body size limits in wisp

Allocation of Resources Without Limits or Throttling vulnerability in gleam-wisp wisp allows a denial of service via multipart form body parsing. The multipart_body function bypasses configured max_…

wisp | Remote | Denial of Service
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
6.3 MEDIUM
CVE-2026-5246 — Cesanta Mongoose P-384 Public Key mongoose.c mg_tls_verify_cert_signature authorization

A vulnerability was determined in Cesanta Mongoose up to 7.20. Affected is the function mg_tls_verify_cert_signature of the file mongoose.c of the component P-384 Public Key Handler. Executing a mani…

mongoose | Remote | Authorization
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
6.3 MEDIUM
CVE-2026-5245 — Cesanta Mongoose mDNS Record mongoose.c handle_mdns_record stack-based overflow

A vulnerability was found in Cesanta Mongoose up to 7.20. This impacts the function handle_mdns_record of the file mongoose.c of the component mDNS Record Handler. Performing a manipulation of the ar…

mongoose | Remote | Memory Corruption
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
5.3 MEDIUM
CVE-2026-33617 — MB connect line mbCONNECT24 vulnerable to an unauthenticated information disclosure in th…

An unauthenticated remote attacker can access a configuration file containing database credentials. This can result in a some loss of confidentiality, but there is no endpoint exposed to use these cr…

mbconnect24 mymbconnect24 | Remote | Information Disclosure
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
7.5 HIGH
CVE-2026-33616 — MB connect line mbCONNECT24 vulnerable to an unauthenticated SQL injection in the mb24api…

An unauthenticated remote attacker can exploit an unauthenticated blind SQL Injection vulnerability in the mb24api endpoint due to improper neutralization of special elements in a SQL SELECT command.…

mbconnect24 mymbconnect24 | Remote | Injection
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
9.1 CRITICAL
CVE-2026-33615 — MB connect line mbCONNECT24 vulnerable to an unauthenticated SQL injection in the setinfo…

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the setinfo endpoint due to improper neutralization of special elements in a SQL UPDATE command. This …

mbconnect24 mymbconnect24 | Remote | Injection
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
7.5 HIGH
CVE-2026-33614 — MB connect line mbCONNECT24 vulnerable to an unauthenticated SQL injection in the getinfo…

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getinfo endpoint due to improper neutralization of special elements in a SQL SELECT command. This …

mbconnect24 mymbconnect24 | Remote | Injection
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
7.2 HIGH
CVE-2026-33613 — MB connect line mbCONNECT24 vulnerable to RCE in generateSrpArray

Due to the improper neutralisation of special elements used in an OS command, a remote attacker can exploit an RCE vulnerability in the generateSrpArray function, resulting in full system compromise.…

mbconnect24 mymbconnect24 | Remote | Injection
Apr 02, 2026 Apr 02, 2026
Apr 02, 2026
Apr 02, 2026
Showing 20 of 6357 Results