Total CVEs

138,754

Critical Severity

3,601

High Severity

12,905

Last 7 Days

1,535
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,221 - 2,240 of 13,065 CVEs
CVE-2026-7552 MEDIUM - 5.3

The Geo Mashup plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.13.19. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to expose sensitive plugin co...

Published: May 28, 2026
Source: NVD
CVE-2026-6427 MEDIUM - 6.4

The a3 Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.7.6 This is due to a regex bug in the _filter_videos() method that breaks HTML attribute quoting when processing crafted <video> elements, combined with unescaped output i...

Published: May 28, 2026
Source: NVD
CVE-2026-9803 MEDIUM - 5.3

A flaw was found in Keycloak's ClientRegistrationAuth component. A remote unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with a malformed 'Authorization: Bearer' header to any client registration endpoint. This can lead to an ArrayI...

Vendor: redhat
Product: build_of_keycloak
Published: May 28, 2026
Source: NVD
CVE-2026-9802 MEDIUM - 6.8

A flaw was found in Keycloak. When revokeRefreshToken=true is enabled and persistent session storage is in use, a server restart can reset internal timing mechanisms. This allows a remote attacker, who has previously captured a user's refresh token, to replay that token even after it has been r...

Vendor: redhat
Product: build_of_keycloak
Published: May 28, 2026
Source: NVD
CVE-2026-9801 MEDIUM - 4.9

A flaw was found in Keycloak. A remote attacker with high privileges, such as a realm administrator configuring a malicious Lightweight Directory Access Protocol (LDAP) server or an attacker compromising an upstream LDAP server, could exploit this vulnerability. By sending a malformed LDAP password ...

Vendor: redhat
Product: build_of_keycloak
Published: May 28, 2026
Source: NVD
CVE-2026-9798 MEDIUM - 4.3

A flaw was found in Keycloak, an open-source identity and access management solution. When a user account is temporarily locked due to repeated failed login attempts, an attacker with valid client credentials can exploit the Client-Initiated Backchannel Authentication (CIBA) flow to bypass this brut...

Vendor: redhat
Product: build_of_keycloak
Published: May 28, 2026
Source: NVD
CVE-2026-9673 MEDIUM - 6.8

Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via the preventCsvInjection option which can be bypassed. An attacker can inject formulas into CSV files, which execute when the files are opened in spreadsheet applications.

Published: May 28, 2026
Source: NVD
CVE-2026-9644 MEDIUM - 6.4

The LiveSmart Video Chat Live Video Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'livesmart_widget' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. Th...

Published: May 28, 2026
Source: NVD
CVE-2026-7533 MEDIUM - 4.3

The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.7. This is due to missing nonce verification in the `handle_oauth_redirect()` function, which is registered on the `admin_init` hook and processes Square OAuth tokens...

Published: May 28, 2026
Source: NVD
CVE-2026-3173 MEDIUM - 6.5

The Meta Field Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.5.1. This is due to the plugin allowing users to specify arbitrary object IDs and object types via block attributes without validating whether the authenticated user ha...

Published: May 28, 2026
Source: NVD
CVE-2026-9796 MEDIUM - 6.5

A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This allows the attacker to escalate their privileges to `realm-admin` for all users within the realm, gr...

Vendor: redhat
Product: build_of_keycloak
Published: May 28, 2026
Source: NVD
CVE-2026-9794 MEDIUM - 5.3

A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted SOAP requests to the SAML ECP (Security Assertion Markup Language Enhanced Client or Proxy) endpoint with varying client IDs. By observing distinct faultstrings in the respons...

Vendor: redhat
Product: build_of_keycloak
Published: May 28, 2026
Source: NVD
CVE-2026-9793 MEDIUM - 5.9

A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may incorrectly process unsigned claims if the decrypted content is raw JSON, bypassing the configured signature policy. This allows a remote attacker to submit unauthorized claims, leading...

Vendor: redhat
Product: build_of_keycloak
Published: May 28, 2026
Source: NVD
CVE-2026-9792 MEDIUM - 6.5

A flaw was found in Keycloak's Client Policies, specifically within the `org.keycloak.protocol.oidc` component. When certain condition providers (client-type, client-roles, client-attributes, client-scopes) are used to enforce security restrictions, the `reject-ropc-grant` executor is silently ...

Vendor: redhat
Product: build_of_keycloak
Published: May 28, 2026
Source: NVD
CVE-2026-9791 MEDIUM - 4.3

A flaw was found in Keycloak. An authenticated user with existing organization membership can exploit this flaw by accessing user-facing APIs, such as the account API or by requesting an OpenID Connect (OIDC) token with the 'organization' scope. This allows organization metadata to be disc...

Vendor: redhat
Product: build_of_keycloak
Published: May 28, 2026
Source: NVD
CVE-2026-9241 MEDIUM - 4.3

The FOX โ€“ Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 1.4.6. This is due to the `get_value()` function in `classes/fixed/fixed_user_role.php` trusting the attacker-controlled...

Published: May 28, 2026
Source: NVD
CVE-2026-9228 MEDIUM - 4.3

The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.16 via the action_get_event_data due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with...

Published: May 28, 2026
Source: NVD
CVE-2026-5737 MEDIUM - 6.5

The Independent Analytics plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.14.9. This is due to a public tracking route at /wp-json/iawp/search that accepts attacker-controlled referrer_url values when the signature matches, combined with a sc...

Published: May 28, 2026
Source: NVD
CVE-2026-4888 MEDIUM - 4.3

The Everest Forms โ€“ Contact Form, Payment Form, Quiz, Survey & Custom Form Builder plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to, and including, 3.4.7. This makes it possible for authenti...

Published: May 28, 2026
Source: NVD
CVE-2026-46544 MEDIUM - 5.3

Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO accepts client-supplied session_id values in WebSocket task messages and reuses an existing in-memory session object if that session_id already exists. If a prior session ...

Vendor: microsoft
Product: UFO
Published: May 27, 2026
Source: NVD