|
281
|
6.8 |
MEDIUM
Network
|
-
|
-
|
A flaw was found in Keycloak. When revokeRefreshToken=true is enabled and persistent session storage is in use, a server restart can reset internal timing mechanisms. This allows a remote attacker, w…
New
|
CWE-613
Insufficient Session Expiration
|
CVE-2026-9802
|
2026-05-28 22:44 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A flaw was found in Keycloak's ClientRegistrationAuth component. A remote unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with a malformed 'Authori…
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-9803
|
2026-05-28 22:44 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283
|
7.0 |
HIGH
Local
|
-
|
-
|
A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory, the tool inserts t…
New
|
CWE-78
OS Command
|
CVE-2026-44604
|
2026-05-28 22:44 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284
|
9.0 |
CRITICAL
Network
|
-
|
-
|
A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is config…
New
|
CWE-78
OS Command
|
CVE-2026-4408
|
2026-05-28 22:44 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285
|
7.7 |
HIGH
Network
|
-
|
-
|
A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing …
New
|
CWE-59
Link Following
|
CVE-2026-9804
|
2026-05-28 22:44 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286
|
5.4 |
MEDIUM
Network
|
apache
|
shiro
|
With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Request Forgery (SSRF) vulnerability in Apache Shiro.
This issue affects Apache Shiro from 2.0-alpha…
New
|
CWE-601 CWE-918
Open Redirect Server-Side Request Forgery (SSRF)
|
CVE-2026-44598
|
2026-05-28 22:44 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287
|
6.1 |
MEDIUM
Network
|
mistune_project
|
mistune
|
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the mistune math plugin renders inline math ($...$) and block math ($$...$$) by concatenating the raw user-supplied con…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-44708
|
2026-05-28 22:44 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288
|
- |
|
-
|
-
|
Relative Path Traversal vulnerability in Apache Ignite REST API.
Authenticated REST API users can read any file on the server with "cmd=log" command and a log path crafted in a certain way.
This iss…
New
|
CWE-23
Relative Path Traversal
|
CVE-2025-48977
|
2026-05-28 22:44 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
selinux: use sk blob accessor in socket permission helpers
SELinux socket state lives in the composite LSM socket blob.
sock_has…
New
|
-
|
CVE-2026-46104
|
2026-05-28 22:44 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
scsi: mpt3sas: Limit NVMe request size to 2 MiB
The HBA firmware reports NVMe MDTS values based on the underlying drive
capabilit…
New
|
-
|
CVE-2026-46105
|
2026-05-28 22:44 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|