Total CVEs

139,456

Critical Severity

3,644

High Severity

13,084

Last 7 Days

1,257
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,261 - 7,280 of 35,861 CVEs
CVE-2026-9009 HIGH - 8.8

The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.7.2 via the filter_content function. This is due to passing the attacker-supplied 'callback_raw' shortcode attribute directly into call_user_...

Published: May 28, 2026
Source: NVD
CVE-2026-7533 MEDIUM - 4.3

The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.7. This is due to missing nonce verification in the `handle_oauth_redirect()` function, which is registered on the `admin_init` hook and processes Square OAuth tokens...

Published: May 28, 2026
Source: NVD
CVE-2026-3173 MEDIUM - 6.5

The Meta Field Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.5.1. This is due to the plugin allowing users to specify arbitrary object IDs and object types via block attributes without validating whether the authenticated user ha...

Published: May 28, 2026
Source: NVD
CVE-2026-9796 MEDIUM - 6.5

A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This allows the attacker to escalate their privileges to `realm-admin` for all users within the realm, gr...

Vendor: redhat
Product: build_of_keycloak
Published: May 28, 2026
Source: NVD
CVE-2026-9795 HIGH - 7.3

A flaw was found in Keycloak's Fine-Grained Admin Permissions (FGAPv2) feature. An administrator with limited client management permissions can exploit this vulnerability to assign any realm role, including highly privileged roles, to a client's scope mapping. This bypasses intended securi...

Vendor: redhat
Product: build_of_keycloak
Published: May 28, 2026
Source: NVD
CVE-2026-9794 MEDIUM - 5.3

A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted SOAP requests to the SAML ECP (Security Assertion Markup Language Enhanced Client or Proxy) endpoint with varying client IDs. By observing distinct faultstrings in the respons...

Vendor: redhat
Product: build_of_keycloak
Published: May 28, 2026
Source: NVD
CVE-2026-9793 MEDIUM - 5.9

A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may incorrectly process unsigned claims if the decrypted content is raw JSON, bypassing the configured signature policy. This allows a remote attacker to submit unauthorized claims, leading...

Vendor: redhat
Product: build_of_keycloak
Published: May 28, 2026
Source: NVD
CVE-2026-9792 MEDIUM - 6.5

A flaw was found in Keycloak's Client Policies, specifically within the `org.keycloak.protocol.oidc` component. When certain condition providers (client-type, client-roles, client-attributes, client-scopes) are used to enforce security restrictions, the `reject-ropc-grant` executor is silently ...

Vendor: redhat
Product: build_of_keycloak
Published: May 28, 2026
Source: NVD
CVE-2026-9791 MEDIUM - 4.3

A flaw was found in Keycloak. An authenticated user with existing organization membership can exploit this flaw by accessing user-facing APIs, such as the account API or by requesting an OpenID Connect (OIDC) token with the 'organization' scope. This allows organization metadata to be disc...

Vendor: redhat
Product: build_of_keycloak
Published: May 28, 2026
Source: NVD
CVE-2026-9241 MEDIUM - 4.3

The FOX โ€“ Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 1.4.6. This is due to the `get_value()` function in `classes/fixed/fixed_user_role.php` trusting the attacker-controlled...

Published: May 28, 2026
Source: NVD
CVE-2026-9228 MEDIUM - 4.3

The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.16 via the action_get_event_data due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with...

Published: May 28, 2026
Source: NVD
CVE-2026-7802 HIGH - 8.8

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscrib...

Published: May 28, 2026
Source: NVD
CVE-2026-5737 MEDIUM - 6.5

The Independent Analytics plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.14.9. This is due to a public tracking route at /wp-json/iawp/search that accepts attacker-controlled referrer_url values when the signature matches, combined with a sc...

Published: May 28, 2026
Source: NVD
CVE-2026-32999 CRITICAL - 9.0

Insufficient character filtering in backup agent signing module on Comet Backup server allows authenticated tenant administrator to execute an arbitrary code on behalf of a privileged user on the affected server and connected devices.

Vendor: WebPros
Product: Comet Backup
Published: May 28, 2026
Source: NVD

This vulnerability in Veeam Service Provider Console allows for remote code execution.

Vendor: Veeam
Product: Service Provider Console
Published: May 28, 2026
Source: NVD

A vulnerability allowing an authenticated user with the Backup Administrator role to write arbitrary files on Linux-based Veeam Backup & Replication server.

Vendor: Veeam
Product: Backup and Replication
Published: May 28, 2026
Source: NVD

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.

Vendor: Veeam
Product: Backup and Replication
Published: May 28, 2026
Source: NVD
CVE-2026-32995 HIGH - 7.5

The Rocket.Chat DDP method autoTranslate.translateMessage in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.5, <7.13.8, and <7.10.12 accepts a client-supplied IMessage object and passes it directly to translateMessage() without checking Meteor.userId() or verifying roo...

Vendor: Rocket.Chat
Product: Rocket.Chat
Published: May 28, 2026
Source: NVD
CVE-2026-2374 HIGH - 7.2

The Login No Captcha reCAPTCHA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `$_SERVER['PHP_SELF']` superglobal in all versions up to, and including, 1.8.0. This is due to the `authenticate()` function storing the unsanitized output of `basename($_SERVER['P...

Published: May 28, 2026
Source: NVD

A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense software versions prior to 3.01.3052. The vulnerability stems from the the PSAdminAgent service, which creates a Named Pipe with a weak Access Control List (ACL). This allows any authenticated local user to connect and send com...

Published: May 28, 2026
Source: NVD