|
1021
|
6.5 |
MEDIUM
Network
|
redhat
|
build_of_keycloak
|
A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This…
Update
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-9796
|
2026-06-4 04:38 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1022
|
7.3 |
HIGH
Network
|
redhat
|
build_of_keycloak
|
A flaw was found in Keycloak's Fine-Grained Admin Permissions (FGAPv2) feature. An administrator with limited client management permissions can exploit this vulnerability to assign any realm role, in…
Update
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-9795
|
2026-06-4 04:38 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1023
|
5.3 |
MEDIUM
Network
|
redhat
|
build_of_keycloak
|
A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted SOAP requests to the SAML ECP (Security Assertion Markup Language Enhanced…
Update
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2026-9794
|
2026-06-4 04:37 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1024
|
6.5 |
MEDIUM
Network
|
redhat
|
build_of_keycloak
|
A flaw was found in Keycloak's Client Policies, specifically within the `org.keycloak.protocol.oidc` component. When certain condition providers (client-type, client-roles, client-attributes, client-…
Update
|
CWE-280
Improper Handling of Insufficient Permissions or Privileges
|
CVE-2026-9792
|
2026-06-4 04:37 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1025
|
6.8 |
MEDIUM
Network
|
redhat
|
build_of_keycloak
|
A flaw was found in Keycloak. When revokeRefreshToken=true is enabled and persistent session storage is in use, a server restart can reset internal timing mechanisms. This allows a remote attacker, w…
Update
|
CWE-613
Insufficient Session Expiration
|
CVE-2026-9802
|
2026-06-4 04:36 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1026
|
7.5 |
HIGH
Network
|
winmtr
|
winmtr
|
WinMTR 0.91 contains a denial of service vulnerability that allows attackers to crash the application by sending a malformed payload file containing a large buffer of repeated characters. Attackers c…
Update
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-25426
|
2026-06-4 04:31 |
2026-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1027
|
5.3 |
MEDIUM
Network
|
redhat
|
build_of_keycloak
|
A flaw was found in Keycloak's ClientRegistrationAuth component. A remote unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with a malformed 'Authori…
Update
|
CWE-125
Out-of-bounds Read
|
CVE-2026-9803
|
2026-06-4 04:28 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1028
|
9.8 |
CRITICAL
Network
|
deltasql_project
|
deltasql
|
Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to docs_upload.php with crafted multipart form…
Update
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2018-25412
|
2026-06-4 04:26 |
2026-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1029
|
9.8 |
CRITICAL
Network
|
trendnet
|
tew-432brp_firmware
|
A security flaw has been discovered in TRENDnet TEW-432BRP 3.10B20. This affects the function formSetPortTr of the file /goform/formSetPortTr. Performing a manipulation of the argument special_name r…
Update
|
CWE-119 CWE-121
Incorrect Access of Indexable Resource ('Range Error') Stack-based Buffer Overflow
|
CVE-2026-10064
|
2026-06-4 04:19 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1030
|
3.3 |
LOW
Local
|
-
|
-
|
A security vulnerability has been detected in Assimp up to 6.0.4. Affected by this issue is the function HL1MDLLoader::read_sequence_infos of the file HL1MDLLoader.cpp of the component Half-Life 1 MD…
Update
|
CWE-119 CWE-125
Incorrect Access of Indexable Resource ('Range Error') Out-of-bounds Read
|
CVE-2026-10233
|
2026-06-4 04:16 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|