Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

50589
Total
4065
Critical
14978
High
14744
Medium
CVE ID Severity Score Description Published
CVE-2026-15722 HIGH 7.5 A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval … Jul 31, 2026
CVE-2026-11770 HIGH 7.5 A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because … Jul 31, 2026
CVE-2026-10079 HIGH 8.5 A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the … Jul 31, 2026
CVE-2026-65313 HIGH 8.1 A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applied to … Jul 31, 2026
CVE-2026-65311 MEDIUM 5.3 The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoint that changes the server's logging level and target … Jul 31, 2026
CVE-2026-65310 HIGH 7.5 ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any authentication and permissive CORS on … Jul 31, 2026
CVE-2026-65309 HIGH 7.5 ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash. This allows … Jul 31, 2026
CVE-2026-18218 MEDIUM 4.2 A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application … Jul 31, 2026
CVE-2026-18217 LOW 3.4 A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs when Keycloak handles SAML … Jul 31, 2026
CVE-2026-18215 MEDIUM 6.8 Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discovered where … Jul 31, 2026
CVE-2026-18214 MEDIUM 6.8 Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was … Jul 31, 2026
CVE-2026-18211 MEDIUM 4.2 A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This component is responsible for enforcing security requirements on client configurations, … Jul 31, 2026
CVE-2026-18209 LOW 3.4 A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed … Jul 31, 2026
CVE-2026-18208 MEDIUM 6.5 A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access management solution used to … Jul 31, 2026
CVE-2026-18206 LOW 3.7 A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services. The issue occurs when a realm administrator uses … Jul 31, 2026
CVE-2026-18203 MEDIUM 6.5 A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to … Jul 31, 2026
CVE-2026-16105 MEDIUM 4.9 A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoints in the admin REST API do not properly … Jul 31, 2026
CVE-2026-8155 MEDIUM 5.4 The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints, allowing any authenticated user (Subscriber+) to read, modify, or … Jul 31, 2026
CVE-2026-18452 CRITICAL 10.0 DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control … Jul 31, 2026
CVE-2026-16236 HIGH 8.8 The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing … Jul 31, 2026
CVE-2026-15381 LOW 3.7 The WP Go Maps WordPress plugin before 10.1.04 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated … Jul 31, 2026
CVE-2026-15258 HIGH 8.1 The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a … Jul 31, 2026
CVE-2026-15209 MEDIUM 6.5 The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a low-privileged authenticated user can … Jul 31, 2026
CVE-2026-15048 HIGH 7.5 The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to retrieve chat-history … Jul 31, 2026
CVE-2026-14931 MEDIUM 6.5 The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation and does not perform a capability check … Jul 31, 2026