Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-42100 — DoS in Sparx Pro Cloud Server

Improper Handling of Syntactically Invalid Structure in Sparx Pro Cloud Server allows Denial of Service (DoS) attack to be executed by sending an specially crafted SQL query. This causes the Pro Clou…

pro_cloud_server | Remote | Injection
May 19, 2026 Jun 02, 2026
May 19, 2026
Jun 02, 2026
7.7 HIGH
CVE-2026-42099 — Race Condition in Sparx Pro Cloud Server

Sparx Pro Cloud Server is vulnerable to a Race Condition in the /data_api/dl_internal_artifact.php endpoint. The application downloads the properties of the object pointed by guid parameter and saves…

pro_cloud_server | Remote | Race Condition
May 19, 2026 Jun 02, 2026
May 19, 2026
Jun 02, 2026
8.7 HIGH
CVE-2026-42098 — Authorization Bypass in Sparx Enterprise Architect

Sparx Enterprise Architect software has a security feature that limits user's actions to those specified in the role. An authenticated attacker can modify the Enterprise Architect client behavior (e…

enterprise_architect | Remote | Authorization
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
9.3 CRITICAL
CVE-2026-42097 — Authentication Bypass in Sparx Pro Cloud Server

Sparx Pro Cloud Server requires authentication based on requested URL. An attacker can omit the "model" query parameter and send the model name only in the binary blob in POST request allowing SQL qu…

pro_cloud_server | Remote | Authentication
May 19, 2026 Jun 02, 2026
May 19, 2026
Jun 02, 2026
8.8 HIGH
CVE-2026-42096 — Broken Access Control in Sparx Pro Cloud Server

Sparx Pro Cloud Server is vulnerable to Broken Access Control within communication with the database. Due to lack of permission checks, any low privileged user can run arbitrary SQL queries within da…

pro_cloud_server | Remote | Injection
May 19, 2026 Jun 02, 2026
May 19, 2026
Jun 02, 2026
7.8 HIGH
CVE-2026-23558 — grant table v2 race in status page mapping

The adjustments made for XSA-379 as well as those subsequently becoming XSA-387 still left a race window, when a HVM or PVH guest does a grant table version change from v2 to v1 in parallel with mapp…

xen | Race Condition
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
6.5 MEDIUM
CVE-2026-23557 — Xenstored DoS via XS_RESET_WATCHES command

Any guest can cause xenstored to crash by issuing a XS_RESET_WATCHES command within a transaction due to an assert() triggering. In case xenstored was built with NDEBUG #defined nothing bad will hap…

xen
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
6.5 MEDIUM
CVE-2025-40904 — HTML injection in Smart Polling in Guardian/CMC before 26.1.0

A Stored HTML Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenticated user with limited privileges can push malici…

cmc guardian cmc guardian | Remote | Cross-Site Scripting
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
5.9 MEDIUM
CVE-2025-40903 — HTML injection in Schedule Restore Archive in Guardian/CMC before 26.1.0

A Stored HTML Injection vulnerability was discovered in the Schedule Restore Archive functionality due to improper validation of an input parameter. An authenticated user with administrative privileg…

cmc guardian cmc guardian | Remote | Cross-Site Scripting
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
5.9 MEDIUM
CVE-2025-40902 — HTML injection in Users in Guardian/CMC before 26.1.0

A Stored HTML Injection vulnerability was discovered in the Users functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can create a mal…

cmc guardian cmc guardian | Remote | Cross-Site Scripting
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
5.9 MEDIUM
CVE-2025-40901 — HTML injection in Credentials Manager in Guardian/CMC before 26.1.0

A Stored HTML Injection vulnerability was discovered in the Credentials Manager functionality due to improper validation of an input parameter. An authenticated user with administrative privileges ca…

cmc guardian cmc guardian | Remote | Cross-Site Scripting
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
5.1 MEDIUM
CVE-2025-40900 — Angular template injection in Reports in Guardian/CMC before 26.1.0

An Angular template injection vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileges can define a mal…

cmc guardian cmc guardian | Remote | Cross-Site Scripting
May 19, 2026 May 20, 2026
May 19, 2026
May 20, 2026
1.8 LOW
CVE-2025-14575 — Uncontrolled Search Path Element in Qt Network OpenSSL TLS backend allows rogue CA certif…

An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (Unix) allows a local attacker to load a rogue CA certificate as a trusted syste…

| Path Traversal
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
7.5 HIGH
CVE-2026-8912 — Contest Gallery <= 28.1.6 - Unauthenticated SQL Injection

The Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the 'form_input' parameter in versions up to, and including, 28.1.6. This is due to insufficient escaping on the user suppl…

contest_gallery | Remote | Injection
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
9.8 CRITICAL
CVE-2026-4883 — Piotnet Forms <= 2.1.40 - Unauthenticated Arbitrary File Upload via Form File Upload

The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'piotnetforms_ajax_form_builder' function in all versions up to, and including…

piotnet_forms | Remote | Misconfiguration
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
1.6 LOW
CVE-2026-7860 — Possible information disclosure of environment variables in Vaadin Build Plugins via Fail…

A possible information disclosure vulnerability exists in the Vaadin Maven plugin and Vaadin Gradle plugin that exposes the full set of environment variables in build logs whenever the frontend build…

flow | Information Disclosure
May 19, 2026 May 21, 2026
May 19, 2026
May 21, 2026
7.1 HIGH
CVE-2026-7571 — Keycloak: keycloak: access token disclosure and implicit flow bypass via forged client da…

A flaw was found in Keycloak. A low-privilege user, with knowledge of user credentials and client ID, can bypass a security control intended to disable the implicit flow in OpenID Connect (OIDC) clie…

build_of_keycloak | Remote | Authentication
May 19, 2026 Jun 03, 2026
May 19, 2026
Jun 03, 2026
7.5 HIGH
CVE-2026-7507 — Org.keycloak/keycloak-services: session fixation in oidc login flow that can lead to acco…

A session fixation vulnerability was found in Keycloak's login-actions endpoints. An unauthenticated attacker could exploit this flaw by pre-creating an authentication session and tricking a victim i…

keycloak build_of_keycloak | Remote | Authentication
May 19, 2026 Jun 03, 2026
May 19, 2026
Jun 03, 2026
8.1 HIGH
CVE-2026-7504 — Org.keycloak/keycloak-services: open redirect when using wildcard valid redirect uris in …

A flaw was found in Keycloak's URL validation logic during redirect operations. By crafting a malicious request, an attacker could bypass validation to redirect users to unauthorized URLs, potentiall…

keycloak build_of_keycloak | Remote | Server-Side Request Forgery
May 19, 2026 Jun 03, 2026
May 19, 2026
Jun 03, 2026
7.5 HIGH
CVE-2026-7307 — Keycloak: keycloak: denial of service via specially crafted saml input

A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML) endpoint. This malicious input can cause high …

keycloak build_of_keycloak | Remote | Denial of Service
May 19, 2026 Jun 03, 2026
May 19, 2026
Jun 03, 2026
Showing 20 of 7126 Results