Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-31846 — Unauthenticated Credential Disclosure via /goform/ate in Nexxt Nebula 300+

Missing authentication in the /goform/ate endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows an adjacent unauthenticated attacker to retrieve sensitive device informa…

| Information Disclosure
Mar 23, 2026 Mar 26, 2026
Mar 23, 2026
Mar 26, 2026
3.7 LOW
CVE-2026-4633 — Keycloak: keycloak: user enumeration via differential error messages

A flaw was found in Keycloak. A remote attacker can exploit differential error messages during the identity-first login flow when Organizations are enabled. This vulnerability allows an attacker to d…

build_of_keycloak | Remote | Information Disclosure
Mar 23, 2026 Apr 01, 2026
Mar 23, 2026
Apr 01, 2026
5.0 MEDIUM
CVE-2026-4583 — Shenzhen HCC Technology MPOS M6 PLUS Bluetooth authentication replay

A vulnerability was detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Affected by this issue is some unknown functionality of the component Bluetooth Handler. Performing a manipulation result…

| Authentication
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
6.3 MEDIUM
CVE-2026-28809 — XXE in esaml SAML library allows local file read and potential SSRF

XML External Entity (XXE) vulnerability in esaml (and its forks) allows an attacker to cause the system to read local files and incorporate their contents into processed SAML documents, and potential…

esaml esaml esaml esaml | Remote | XML External Entity
Mar 23, 2026 Apr 06, 2026
Mar 23, 2026
Apr 06, 2026
5.0 MEDIUM
CVE-2026-4582 — Shenzhen HCC Technology MPOS M6 PLUS Bluetooth missing authentication

A security vulnerability has been detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Affected by this vulnerability is an unknown functionality of the component Bluetooth. Such manipulation le…

| Authentication
Mar 23, 2026 Apr 18, 2026
Mar 23, 2026
Apr 18, 2026
9.8 CRITICAL
CVE-2026-4581 — code-projects Simple Laundry System Parameters checklogin.php sql injection

A weakness has been identified in code-projects Simple Laundry System 1.0. Affected is an unknown function of the file /checklogin.php of the component Parameters Handler. This manipulation of the ar…

simple_laundry_system | Remote | Injection
Mar 23, 2026 Apr 18, 2026
Mar 23, 2026
Apr 18, 2026
4.3 MEDIUM
CVE-2026-4628 — Keycloak: org.keycloak.authorization: keycloak: unauthorized resource modification due to…

A flaw was found in Keycloak. An improper Access Control vulnerability in Keycloak’s User-Managed Access (UMA) resource_set endpoint allows attackers with valid credentials to bypass the allowRemoteR…

build_of_keycloak | Remote | Authorization
Mar 23, 2026 Apr 01, 2026
Mar 23, 2026
Apr 01, 2026
9.8 CRITICAL
CVE-2026-4580 — code-projects Simple Laundry System Parameters checkupdatestatus.php sql injection

A security flaw has been discovered in code-projects Simple Laundry System 1.0. This impacts an unknown function of the file /checkupdatestatus.php of the component Parameters Handler. The manipulati…

simple_laundry_system | Remote | Injection
Mar 23, 2026 Apr 03, 2026
Mar 23, 2026
Apr 03, 2026
9.8 CRITICAL
CVE-2026-4579 — code-projects Simple Laundry System Parameters viewdetail.php sql injection

A vulnerability was identified in code-projects Simple Laundry System 1.0. This affects an unknown function of the file /viewdetail.php of the component Parameters Handler. The manipulation of the ar…

simple_laundry_system | Remote | Injection
Mar 23, 2026 Apr 03, 2026
Mar 23, 2026
Apr 03, 2026
4.8 MEDIUM
CVE-2026-4578 — code-projects Exam Form Submission update_s3.php cross site scripting

A vulnerability was determined in code-projects Exam Form Submission 1.0. The impacted element is an unknown function of the file /admin/update_s3.php. Executing a manipulation of the argument sname …

exam_form_submission | Remote | Cross-Site Scripting
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
10.0 CRITICAL
CVE-2026-3587 — Hidden CLI Function Allows Root Access

An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface, leading to full compromise of the device.

Remote | Authorization
Mar 23, 2026 Mar 24, 2026
Mar 23, 2026
Mar 24, 2026
Showing 20 of 6311 Results