Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-19607 — Keycloak-services: keycloak-services: broker-originated username collision causes account…

A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial authentication and account linking when a user logs in via an external identity …

single_sign-on build_of_keycloak | Remote | Authentication
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
7.2 HIGH
CVE-2026-17526 — Keycloak-services: keycloak-services: privilege escalation via impersonation role allows …

Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the impersonation role can impersonate a realm administrator. This allows the atta…

single_sign-on data_grid build_of_keycloak | Remote | Authorization
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
9.8 CRITICAL
CVE-2025-59953 — LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_respons…

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior to version 0.10.2, the LMdeploy implements an rpc server (AsyncRPCServer in zm…

lmdeploy | Remote | Injection
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
8.1 HIGH
CVE-2025-43936 — Dell ObjectScale Improper Authentication Vulnerability

Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability…

objectscale | Remote | Authentication
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
7.6 HIGH
CVE-2026-92616 — FileRise < 3.28.0 Privilege Escalation via WebDAV Session Inheritance

FileRise before version 3.28.0 contains a privilege escalation vulnerability that allows authenticated low-privilege attackers to gain unauthorized read and write access by exploiting improper sessio…

Remote | Authorization
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
7.1 HIGH
CVE-2026-92570 — reNgine through 2.2.0 Unauthorized Configuration File Read

reNgine through 2.2.0 contains an authorization bypass vulnerability in the GetFileContents API endpoint that allows any authenticated user to read bundled recon tool configuration files. Attackers w…

rengine | Remote | Authorization
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
5.3 MEDIUM
CVE-2026-92569 — Hippo4j through 1.5.0 SSRF via clientAddress Parameter

Hippo4j through 1.5.0 contains a server-side request forgery vulnerability in four ThreadPoolController endpoints that fail to validate the clientAddress parameter. Authenticated attackers can supply…

hippo4j | Remote | Server-Side Request Forgery
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
5.4 MEDIUM
CVE-2026-92568 — MLRun through 1.11.0 Server-Side Request Forgery via Webhook

MLRun through 1.11.0 contains a server-side request forgery vulnerability in the WebhookNotification handler that allows authenticated users to make the API server send arbitrary HTTP requests to int…

Remote | Server-Side Request Forgery
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
7.1 HIGH
CVE-2026-92567 — TDuck survey form through 5.0 Unauthorized Data Modification

TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/data/update endpoint that allows authenticated users to overwrite other users' form submiss…

Remote | Authorization
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
8.8 HIGH
CVE-2026-92566 — DataGear through 6.0.0 Unauthenticated SSRF via HTTP Dataset Preview

DataGear through 6.0.0 contains a server-side request forgery vulnerability in the /dataSet/preview/Http endpoint that allows unauthenticated attackers to execute arbitrary HTTP requests by supplying…

Remote | Server-Side Request Forgery
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
6.9 MEDIUM
CVE-2026-92565 — Rallly before 4.15.0 Information Disclosure via polls.get

Rallly before 4.15.0 contains an information disclosure vulnerability in the polls.get tRPC procedure that returns scheduled-event invitee names and email addresses to unauthenticated callers. Attack…

Remote | Information Disclosure
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
9.1 CRITICAL
CVE-2026-92395 — @fastify/proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet

@fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse proxies, and it backs Fastify request.ip and request.ips. In versions 3.0.0 through 5.1.0, a …

| Misconfiguration
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
5.0 MEDIUM
CVE-2026-92383 — PbootCMS User Management UserController.php mod cross-site request forgery

A security vulnerability has been detected in PbootCMS up to 3.2.24. This vulnerability affects the function UserController::del/UserController::mod of the file apps/admin/controller/system/UserContr…

Remote | Cross-Site Request Forgery
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
4.0 MEDIUM
CVE-2026-92381 — PbootCMS Template Rendering ContentController.php decode_string cross site scripting

A weakness has been identified in PbootCMS up to 3.2.22. This affects the function decode_string of the file apps/admin/controller/content/ContentController.php of the component Template Rendering. T…

Remote | Cross-Site Scripting
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
7.5 HIGH
CVE-2026-92380 — WuzhiCMS Remote Image Fetch index.php saveRemote server-side request forgery

A flaw has been found in WuzhiCMS up to 4.1.0. The impacted element is the function ckditor::saveRemote of the file coreframe/app/attachment/index.php of the component Remote Image Fetch. This manipu…

Remote | Server-Side Request Forgery
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
7.5 HIGH
CVE-2026-92366 — code-projects Matrimonial System Regular Search search.php sql injection

A vulnerability was determined in code-projects Matrimonial System 1.0. This affects an unknown part of the file /search.php of the component Regular Search. This manipulation of the argument sex/mot…

Remote | Injection
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
8.1 HIGH
CVE-2026-92087 — @fastify/auth vulnerable to Authorization Bypass via order-dependent evaluation of compos…

@fastify/auth is a Fastify plugin that composes multiple authentication and authorization strategies into a single route guard. In versions 5.0.0 through 5.1.0, when strategies are composed with the …

| Authorization
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
5.4 MEDIUM
CVE-2026-89031 — Blog2Social WordPress Plugin < 9.1.0 Broken Access Control via b2s_calendar_move_post

Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to modify the scheduled post records of other users. The b2s_calendar_move_post AJAX handler in includes/Ajax/Post.ph…

blog2social | Remote | Authorization
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
6.1 MEDIUM
CVE-2026-88976 — @platejs/core HTML deserialization can trigger browser behavior during parsing

Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.11, and in the discontinued 54.0.0-beta.0 through 54.0.0-beta.1 builds, Plate core HTML deserialization APIs parse supplied HTML strin…

plate | Remote | Cross-Site Scripting
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
8.8 HIGH
CVE-2026-88064 — Backstage: Improper input validation in TechDocs MkDocs configuration

Backstage is an open framework for building developer portals. Prior to 1.14.6 and from 1.15.0 until 1.15.4, the @backstage/plugin-techdocs-node package insufficiently validates mkdocs.yml supplied b…

Remote | Injection
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
Showing 20 of 14729 Results