Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,662
Quick preset (or use dates below)
Clear Filters
Showing 2,221 - 2,240 of 13,436 CVEs
CVE-2026-9796 MEDIUM - 6.5

A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This allows the attacker to escalate their privileges to `realm-admin` for all users within the realm, gr...

Vendor: redhat
Product: build_of_keycloak
Published: May 28, 2026
Source: NVD
CVE-2026-9794 MEDIUM - 5.3

A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted SOAP requests to the SAML ECP (Security Assertion Markup Language Enhanced Client or Proxy) endpoint with varying client IDs. By observing distinct faultstrings in the respons...

Vendor: redhat
Product: build_of_keycloak
Published: May 28, 2026
Source: NVD
CVE-2026-9793 MEDIUM - 5.9

A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may incorrectly process unsigned claims if the decrypted content is raw JSON, bypassing the configured signature policy. This allows a remote attacker to submit unauthorized claims, leading...

Vendor: redhat
Product: build_of_keycloak
Published: May 28, 2026
Source: NVD
CVE-2026-9792 MEDIUM - 6.5

A flaw was found in Keycloak's Client Policies, specifically within the `org.keycloak.protocol.oidc` component. When certain condition providers (client-type, client-roles, client-attributes, client-scopes) are used to enforce security restrictions, the `reject-ropc-grant` executor is silently ...

Vendor: redhat
Product: build_of_keycloak
Published: May 28, 2026
Source: NVD
CVE-2026-9791 MEDIUM - 4.3

A flaw was found in Keycloak. An authenticated user with existing organization membership can exploit this flaw by accessing user-facing APIs, such as the account API or by requesting an OpenID Connect (OIDC) token with the 'organization' scope. This allows organization metadata to be disc...

Vendor: redhat
Product: build_of_keycloak
Published: May 28, 2026
Source: NVD
CVE-2026-9241 MEDIUM - 4.3

The FOX โ€“ Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 1.4.6. This is due to the `get_value()` function in `classes/fixed/fixed_user_role.php` trusting the attacker-controlled...

Published: May 28, 2026
Source: NVD
CVE-2026-9228 MEDIUM - 4.3

The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.16 via the action_get_event_data due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with...

Published: May 28, 2026
Source: NVD
CVE-2026-5737 MEDIUM - 6.5

The Independent Analytics plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.14.9. This is due to a public tracking route at /wp-json/iawp/search that accepts attacker-controlled referrer_url values when the signature matches, combined with a sc...

Published: May 28, 2026
Source: NVD
CVE-2026-4888 MEDIUM - 4.3

The Everest Forms โ€“ Contact Form, Payment Form, Quiz, Survey & Custom Form Builder plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the send_test_email() function in all versions up to, and including, 3.4.7. This makes it possible for authenti...

Published: May 28, 2026
Source: NVD
CVE-2026-46544 MEDIUM - 5.3

Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO accepts client-supplied session_id values in WebSocket task messages and reuses an existing in-memory session object if that session_id already exists. If a prior session ...

Vendor: microsoft
Product: UFO
Published: May 27, 2026
Source: NVD
CVE-2026-46538 MEDIUM - 5.9

Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO's constellation client tracks pending task responses by session_id only and does not verify that a TASK_END message came from the device that originally received the ...

Vendor: microsoft
Product: UFO
Published: May 27, 2026
Source: NVD
CVE-2026-46416 MEDIUM - 6.3

Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO creates one shared UFOWebSocketHandler instance and reuses it for multiple authenticated WebSocket connections. The handler stores per-connection protocol objects in mutab...

Vendor: microsoft
Product: UFO
Published: May 27, 2026
Source: NVD
CVE-2026-45703 MEDIUM - 6.4

Pimcore has a WordExport Authorization Bypass for Unauthorized Document Export

Vendor: composer
Product: pimcore/pimcore
Published: May 27, 2026
Source: GitHub

AsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected authorized keys to authenticate a traversal username

Vendor: pip
Product: asyncssh
Published: May 27, 2026
Source: GitHub
CVE-2026-47270 MEDIUM - 6.3

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, pam_usb is a PAM module loaded into the host process (sudo, login, GDM, GNOME Shell). Display managers such as GDM run multiple concurrent authentication threads. Three functions used by the deny_remot...

Vendor: mcdope
Product: pam_usb
Published: May 27, 2026
Source: NVD
CVE-2026-44710 MEDIUM - 4.6

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, src/device.c passed the return values of udisks_drive_get_serial(), udisks_drive_get_vendor(), and udisks_drive_get_model() directly to strcmp() without NULL checks. The GIO/UDisks API documentation st...

Vendor: mcdope
Product: pam_usb
Published: May 27, 2026
Source: NVD
CVE-2026-21785 MEDIUM - 4.0

A misconfigured Content Security Policy (CSP) in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0442 and earlier) fails to define directives without fallbacks, allowing attackers to bypass intended security restrictions and load unauthorized resources.

Vendor: HCLSoftware
Product: BigFix Remote Control Server
Published: May 27, 2026
Source: NVD

Synfony's HEAD Request Bypasses methods: ['GET'] Filter in #[IsGranted] / #[IsSignatureValid] / #[IsCsrfTokenValid]

Vendor: composer
Product: symfony/http-kernel
Published: May 27, 2026
Source: GitHub

Symfony's Cas2Handler Derives CAS service URL from Client Host Header โ†’ Cross-Service Ticket Replay

Vendor: composer
Product: symfony/security-http
Published: May 27, 2026
Source: GitHub

Symfony Vulnerable to SQL Injection in PdoAdapter::doClear() via Unsanitized $prefix

Vendor: composer
Product: symfony/cache
Published: May 27, 2026
Source: GitHub