Total CVEs

131,459

Critical Severity

2,797

High Severity

9,990

Last 7 Days

1,142
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 1,321 - 1,340 of 27,864 CVEs
CVE-2026-7507 HIGH - 7.5

A session fixation vulnerability was found in Keycloak's login-actions endpoints. An unauthenticated attacker could exploit this flaw by pre-creating an authentication session and tricking a victim into visiting a maliciously crafted link. By leveraging the /login-actions/restart endpoint—which...

Published: May 19, 2026
Source: NVD
CVE-2026-7504 HIGH - 8.1

A flaw was found in Keycloak's URL validation logic during redirect operations. By crafting a malicious request, an attacker could bypass validation to redirect users to unauthorized URLs, potentially leading to the exposure of sensitive information within the domain or facilitating further att...

Published: May 19, 2026
Source: NVD
CVE-2026-7307 HIGH - 7.5

A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML) endpoint. This malicious input can cause high CPU usage and worker thread starvation, leading to a Denial of Service (DoS) where the server becomes...

Published: May 19, 2026
Source: NVD
CVE-2026-4630 MEDIUM - 6.8

A flaw was found in Keycloak. An authenticated client could exploit an Insecure Direct Object Reference (IDOR) vulnerability in the Authorization Services Protection API endpoint. By knowing or obtaining a resource's unique identifier (UUID) belonging to another Resource Server within the same ...

Published: May 19, 2026
Source: NVD
CVE-2026-45442 MEDIUM - 4.3

Missing Authorization vulnerability in Brainstorm Force Presto Player allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Presto Player: from n/a through 4.1.3.

Vendor: Brainstorm Force
Product: Presto Player
Published: May 19, 2026
Source: NVD
CVE-2026-43493 CRITICAL - 9.8

In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Fix handling of MAY_BACKLOG requests MAY_BACKLOG requests can return EBUSY. Handle them by checking for that value and filtering out EINPROGRESS notifications.

Vendor: Linux
Product: Linux
Published: May 19, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() Yiming reports an integer underflow in mpi_read_raw_from_sgl() when subtracting "lzeros" from the unsigned "nbytes". For this to happen, the sc...

Vendor: Linux
Product: Linux
Published: May 19, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: net: qrtr: ns: Limit the maximum server registration per node Current code does no bound checking on the number of servers added per node. A malicious client can flood NEW_SERVER messages and exhaust memory. Fix this issue by lim...

Vendor: Linux
Product: Linux
Published: May 19, 2026
Source: NVD
CVE-2026-37982 MEDIUM - 6.8

A flaw was found in Keycloak. This authentication vulnerability allows a remote attacker to replay `ExecuteActionsActionToken` tokens within Keycloak's WebAuthn (Web Authentication) flow. By intercepting an execute-actions email link, an attacker can register their own authenticator to a victim...

Vendor: Red Hat
Product: Red Hat Build of Keycloak
Published: May 19, 2026
Source: NVD
CVE-2026-37981 MEDIUM - 4.3

A flaw was found in Keycloak. A broken access control vulnerability in the Account Resources user lookup endpoint allows a remote authenticated user, who owns at least one User-Managed Access (UMA) resource, to enumerate and harvest personally identifiable information (PII) for all realm users. By s...

Vendor: Red Hat
Product: Red Hat Build of Keycloak
Published: May 19, 2026
Source: NVD
CVE-2026-37979 MEDIUM - 6.5

A flaw was found in Keycloak. This access control vulnerability in Keycloak's OpenID Connect (OIDC) token introspection endpoint allows a confidential client to bypass audience restrictions. An attacker-controlled client with valid credentials can retrieve sensitive token claims intended for ot...

Vendor: Red Hat
Product: Red Hat Build of Keycloak
Published: May 19, 2026
Source: NVD
CVE-2026-37978 MEDIUM - 4.9

A flaw was found in Keycloak. A low-privilege administrator with the 'view-clients' role can exploit this by invoking the 'evaluate-scopes' Admin API endpoints with an arbitrary user ID (userId) parameter. This vulnerability allows for cross-role personally identifiable informati...

Vendor: Red Hat
Product: Red Hat Build of Keycloak
Published: May 19, 2026
Source: NVD

The AddressRepository::getSqlQuery() method constructs a database query without properly sanitizing user input, leading to SQL Injection. The method is not invoked anywhere within the extension itself and therefore poses no direct risk in a default installation. However, custom extensions that call ...

Published: May 19, 2026
Source: NVD

The Crawler extension passes the X-T3Crawler-Meta response header from crawled URLs directly to PHP's unserialize(). An attacker controlling a crawled endpoint can inject arbitrary serialized PHP objects, leading to Remote Code Execution on the TYPO3 server. Exploitation requires administrative...

Published: May 19, 2026
Source: NVD

The extension fails to properly sanitize user input before using it in a database query. As a result, an unauthenticated attacker can inject arbitrary SQL through a URL parameter on pages using the "Date Menu of news articles" plugin. Exploitation requires the "Date Menu of news artic...

Published: May 19, 2026
Source: NVD

The extension passes an attacker-controlled cookie directly to PHP's unserialize() without safely processing the input. A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the TYPO3 server. Exploitation ...

Vendor: TYPO3
Product: Extension "Content Element Selector"
Published: May 19, 2026
Source: NVD

The file indexer does not normalize the configured directory path. A backend user with permission to edit indexer configurations can index documents from arbitrary locations on the server file system through path traversal sequences.

Vendor: TYPO3
Product: Extension "Faceted Search"
Published: May 19, 2026
Source: NVD

The additional_tables configuration of the page and tt_content indexers accepts arbitrary table and field names. A backend user with permission to edit indexer configurations can copy sensitive data from internal TYPO3 tables into the search index.

Vendor: TYPO3
Product: Extension "Faceted Search"
Published: May 19, 2026
Source: NVD

The OOXML parsing of the file indexer does not disable external entity resolution. A crafted xlsx or pptx document placed in an indexed directory can cause local files to be read or outbound HTTP requests to be performed, with the retrieved content being written to the search index.

Vendor: TYPO3
Product: Extension "Faceted Search"
Published: May 19, 2026
Source: NVD

The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on the frontend user group assignment. As a result, an attacker can assign an arbitrary frontend user group to a newly registered or edited account, gaining unauthorized access to conte...

Vendor: TYPO3
Product: Extension "Frontend User Registration"
Published: May 19, 2026
Source: NVD