Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-9794 — Keycloak: keycloak: information disclosure via saml ecp endpoint

A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted SOAP requests to the SAML ECP (Security Assertion Markup Language Enhanced…

build_of_keycloak | Remote | Information Disclosure
May 28, 2026 Jun 03, 2026
May 28, 2026
Jun 03, 2026
7.5 HIGH
CVE-2026-9793 — Keycloak: keycloak: security policy bypass in jwe-encrypted request object processing

A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may incorrectly process unsigned claims if the decrypted content is raw JSON, bypassing …

build_of_keycloak | Remote | Authorization
May 28, 2026 Jun 03, 2026
May 28, 2026
Jun 03, 2026
6.5 MEDIUM
CVE-2026-9792 — Keycloak: keycloak: security restriction bypass allows unauthorized ropc token acquisition

A flaw was found in Keycloak's Client Policies, specifically within the `org.keycloak.protocol.oidc` component. When certain condition providers (client-type, client-roles, client-attributes, client-…

build_of_keycloak | Remote | Authentication
May 28, 2026 Jun 03, 2026
May 28, 2026
Jun 03, 2026
4.3 MEDIUM
CVE-2026-9791 — Keycloak-rhel9: organization data leak after feature disabled in keycloak

A flaw was found in Keycloak. An authenticated user with existing organization membership can exploit this flaw by accessing user-facing APIs, such as the account API or by requesting an OpenID Conne…

build_of_keycloak | Remote | Information Disclosure
May 28, 2026 Jun 03, 2026
May 28, 2026
Jun 03, 2026
4.3 MEDIUM
CVE-2026-9241 — FOX – Currency Switcher Professional for WooCommerce <= 1.4.6 - Authenticated (Subscriber…

The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 1.4.6. This is due …

May 28, 2026 May 28, 2026
May 28, 2026
May 28, 2026
4.3 MEDIUM
CVE-2026-9228 — Timetable and Event Schedule by MotoPress <= 2.4.16 - Insecure Direct Object Reference to…

The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.16 via the action_get_event_data due to …

timetable_and_event_schedule | Remote | Authorization
May 28, 2026 May 28, 2026
May 28, 2026
May 28, 2026
8.8 HIGH
CVE-2026-7802 — Frontend Admin by DynamiApps <= 3.29.2 - Missing Authorization to Authenticated (Subscrib…

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.2. This is due to the plugin not properly verifying that a user …

frontend_admin | Remote | Authorization
May 28, 2026 May 28, 2026
May 28, 2026
May 28, 2026
6.5 MEDIUM
CVE-2026-5737 — Independent Analytics <= 2.14.9 - Unauthenticated Server-Side Request Forgery via Trackin…

The Independent Analytics plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.14.9. This is due to a public tracking route at /wp-json/iawp/searc…

Remote | Server-Side Request Forgery
May 28, 2026 May 28, 2026
May 28, 2026
May 28, 2026
9.0 CRITICAL
CVE-2026-32999 — Comet Backup Code Execution Vulnerability

Insufficient character filtering in backup agent signing module on Comet Backup server allows authenticated tenant administrator to execute an arbitrary code on behalf of a privileged user on the aff…

Remote | Authentication
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
9.4 CRITICAL
CVE-2026-32998 — Veeam Service Provider Console Remote Code Execution Vulnerability

This vulnerability in Veeam Service Provider Console allows for remote code execution.

veeam_service_provider_console | Remote | Injection
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
8.6 HIGH
CVE-2026-32997 — Veeam Backup & Replication Server Authenticated File Write Vulnerability

A vulnerability allowing an authenticated user with the Backup Administrator role to write arbitrary files on Linux-based Veeam Backup & Replication server.

veeam_backup_\&_replication | Remote | Authorization
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
7.3 HIGH
CVE-2026-32996 — Veeam Agent for Microsoft Windows Local Privilege Escalation Vulnerability

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.

veeam_backup_\&_replication | Authorization
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
7.5 HIGH
CVE-2026-32995 — Rocket.Chat Information Disclosure

The Rocket.Chat DDP method autoTranslate.translateMessage in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.5, <7.13.8, and <7.10.12 accepts a client-supplied IMessage object and passes it dir…

rocket.chat | Remote | Authorization
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
7.2 HIGH
CVE-2026-2374 — Login No Captcha reCAPTCHA <= 1.8.0 - Unauthenticated Stored Cross-Site Scripting via PHP…

The Login No Captcha reCAPTCHA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `$_SERVER['PHP_SELF']` superglobal in all versions up to, and including, 1.8.0. This is due to…

login_no_captcha_recaptcha | Remote | Cross-Site Scripting
May 28, 2026 May 28, 2026
May 28, 2026
May 28, 2026
8.5 HIGH
CVE-2026-9789 — NitroSense V3: Security Vulnerability Information

A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense software versions prior to 3.01.3052. The vulnerability stems from the the PSAdminAgent service, which creates a Named Pipe wi…

| Authorization
May 28, 2026 May 28, 2026
May 28, 2026
May 28, 2026
8.8 HIGH
CVE-2026-8915 — Samsung Escargot Out-of-Bounds Write Buffer Overflow

Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 36f5fb58366a67b713c02f6fd985e924fcc09e31.

escargot | Remote | Memory Corruption
May 28, 2026 Jun 02, 2026
May 28, 2026
Jun 02, 2026
4.3 MEDIUM
CVE-2026-4888 — Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder <= 3.4.7 -…

The Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_…

everest_forms | Remote | Authentication
May 28, 2026 May 28, 2026
May 28, 2026
May 28, 2026
9.4 CRITICAL
CVE-2026-9739 — Google Chrome SSE DNS Rebinding

Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). During the beta phase, we implemented `allowed-origins` and `allowed-hosts` flags to align with MCP security guidelines. Howev…

Remote | Misconfiguration
May 27, 2026 May 29, 2026
May 27, 2026
May 29, 2026
5.3 MEDIUM
CVE-2026-46544 — Microsoft UFO reuses client-supplied WebSocket session IDs and replays stale task results…

Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO accepts client-supplied session_id values in WebSocket task messages a…

Remote | Authentication
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
5.9 MEDIUM
CVE-2026-46538 — Microsoft UFO accepts cross-device TASK_END messages by session_id only, allowing peer ta…

Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO's constellation client tracks pending task responses by session_id onl…

Remote | Injection
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
Showing 20 of 7171 Results