Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
50169
Total
4054
Critical
14909
High
14667
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-44615 | MEDIUM | 6.5 | Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker with permission to rename a note, or access to folder operations, could … | Jul 31, 2026 |
| CVE-2026-17567 | MEDIUM | 5.3 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all … | Jul 31, 2026 |
| CVE-2026-16843 | HIGH | 7.2 | Some Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by … | Jul 31, 2026 |
| CVE-2026-18437 | MEDIUM | 5.3 | The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the … | Jul 31, 2026 |
| CVE-2026-18436 | MEDIUM | 5.3 | The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the campaign revision-restore REST endpoint (POST /wp-json/mailpress/v1/campaign/<id>/restore-revision/<revision_id>). … | Jul 31, 2026 |
| CVE-2026-15722 | HIGH | 7.5 | A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval … | Jul 31, 2026 |
| CVE-2026-11770 | HIGH | 7.5 | A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because … | Jul 31, 2026 |
| CVE-2026-10079 | HIGH | 8.5 | A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the … | Jul 31, 2026 |
| CVE-2026-65313 | HIGH | 8.1 | A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applied to … | Jul 31, 2026 |
| CVE-2026-65311 | MEDIUM | 5.3 | The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoint that changes the server's logging level and target … | Jul 31, 2026 |
| CVE-2026-65310 | HIGH | 7.5 | ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any authentication and permissive CORS on … | Jul 31, 2026 |
| CVE-2026-65309 | HIGH | 7.5 | ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash. This allows … | Jul 31, 2026 |
| CVE-2026-18218 | MEDIUM | 4.2 | A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application … | Jul 31, 2026 |
| CVE-2026-18217 | LOW | 3.4 | A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs when Keycloak handles SAML … | Jul 31, 2026 |
| CVE-2026-18215 | MEDIUM | 6.8 | Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discovered where … | Jul 31, 2026 |
| CVE-2026-18214 | MEDIUM | 6.8 | Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was … | Jul 31, 2026 |
| CVE-2026-18211 | MEDIUM | 4.2 | A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This component is responsible for enforcing security requirements on client configurations, … | Jul 31, 2026 |
| CVE-2026-18209 | LOW | 3.4 | A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed … | Jul 31, 2026 |
| CVE-2026-18208 | MEDIUM | 6.5 | A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access management solution used to … | Jul 31, 2026 |
| CVE-2026-18206 | LOW | 3.7 | A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services. The issue occurs when a realm administrator uses … | Jul 31, 2026 |
| CVE-2026-18203 | MEDIUM | 6.5 | A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to … | Jul 31, 2026 |
| CVE-2026-16105 | MEDIUM | 4.9 | A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoints in the admin REST API do not properly … | Jul 31, 2026 |
| CVE-2026-8155 | MEDIUM | 5.4 | The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints, allowing any authenticated user (Subscriber+) to read, modify, or … | Jul 31, 2026 |
| CVE-2026-18452 | CRITICAL | 10.0 | DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control … | Jul 31, 2026 |
| CVE-2026-16236 | HIGH | 8.8 | The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing … | Jul 31, 2026 |