Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26401
Total
1955
Critical
7975
High
8228
Medium
CVE ID Severity Score Description Published
CVE-2026-8912 HIGH 7.5 The Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the 'form_input' parameter in versions up to, and including, 28.1.6. This is due … May 19, 2026
CVE-2026-4883 CRITICAL 9.8 The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'piotnetforms_ajax_form_builder' function in all versions … May 19, 2026
CVE-2026-7860 UNKNOWN A possible information disclosure vulnerability exists in the Vaadin Maven plugin and Vaadin Gradle plugin that exposes the full set of environment variables in build … May 19, 2026
CVE-2026-7571 HIGH 7.1 A flaw was found in Keycloak. A low-privilege user, with knowledge of user credentials and client ID, can bypass a security control intended to disable … May 19, 2026
CVE-2026-7507 HIGH 7.5 A session fixation vulnerability was found in Keycloak's login-actions endpoints. An unauthenticated attacker could exploit this flaw by pre-creating an authentication session and tricking a … May 19, 2026
CVE-2026-7504 HIGH 8.1 A flaw was found in Keycloak's URL validation logic during redirect operations. By crafting a malicious request, an attacker could bypass validation to redirect users … May 19, 2026
CVE-2026-7307 HIGH 7.5 A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML) endpoint. … May 19, 2026
CVE-2026-4630 MEDIUM 6.8 A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Services Protection API endpoint. … May 19, 2026
CVE-2026-45442 MEDIUM 4.3 Missing Authorization vulnerability in Brainstorm Force Presto Player allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Presto Player: from n/a through 4.1.3. May 19, 2026
CVE-2026-43493 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Fix handling of MAY_BACKLOG requests MAY_BACKLOG requests can return EBUSY. Handle them … May 19, 2026
CVE-2026-43492 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() Yiming reports an integer underflow in mpi_read_raw_from_sgl() when … May 19, 2026
CVE-2026-43491 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: net: qrtr: ns: Limit the maximum server registration per node Current code does no bound … May 19, 2026
CVE-2026-37982 MEDIUM 6.8 A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `ExecuteActionsActionToken` tokens within Keycloak's WebAuthn (Web Authentication) flow. By intercepting … May 19, 2026
CVE-2026-37981 MEDIUM 4.3 A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows a remote authenticated user, who owns … May 19, 2026
CVE-2026-37979 MEDIUM 6.5 A flaw was found in Keycloak. This access control vulnerability in Keycloak's OpenID Connect (OIDC) token introspection endpoint allows a confidential client to bypass audience … May 19, 2026
CVE-2026-37978 MEDIUM 4.9 A flaw was found in Keycloak. A low-privilege administrator with the 'view-clients' role can exploit this by invoking the 'evaluate-scopes' Admin API endpoints with an … May 19, 2026
CVE-2026-8827 UNKNOWN The AddressRepository::getSqlQuery() method constructs a database query without properly sanitizing user input, leading to SQL Injection. The method is not invoked anywhere within the extension … May 19, 2026
CVE-2026-8727 UNKNOWN The Crawler extension passes the X-T3Crawler-Meta response header from crawled URLs directly to PHP's unserialize(). An attacker controlling a crawled endpoint can inject arbitrary serialized … May 19, 2026
CVE-2026-8726 UNKNOWN The extension fails to properly sanitize user input before using it in a database query. As a result, an unauthenticated attacker can inject arbitrary SQL … May 19, 2026
CVE-2026-46725 UNKNOWN The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input. A remote, unauthenticated attacker can supply a crafted serialized payload … May 19, 2026
CVE-2026-46724 UNKNOWN The file indexer does not normalize the configured directory path. A backend user with permission to edit indexer configurations can index documents from arbitrary locations … May 19, 2026
CVE-2026-46723 UNKNOWN The additional_tables configuration of the page and tt_content indexers accepts arbitrary table and field names. A backend user with permission to edit indexer configurations can … May 19, 2026
CVE-2026-46722 UNKNOWN The OOXML parsing of the file indexer does not disable external entity resolution. A crafted xlsx or pptx document placed in an indexed directory can … May 19, 2026
CVE-2026-46721 UNKNOWN The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on the frontend user group … May 19, 2026
CVE-2026-46586 HIGH 7.3 Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability in Apache OFBiz. This issue affects … May 19, 2026