Common Vulnerabilities and Exposures (CVE)

CVE-2026-57559

Oct 6, 2026 11:53:01 UTC

Memory corruption while processing service requests.

CVE-2026-2575

Oct 6, 2026 11:50:32 UTC

A flaw was found in Keycloak. An unauthenticated remote attacker can trigger an application level Denial of Service (DoS) by sending a highly compressed SAMLRequest through the SAML Redirect Binding. The server fails to enforce size limits ...

CVE-2026-59357

Oct 6, 2026 11:49:21 UTC

Insufficient verification of data authenticity (CWE-345) in the external OIDC login callback in Cloud Foundry UAA v4.5.0 to v79.6.0 (inclusive) allows an authenticated UAA user to bypass the OAuth authorization-code exchange and establish a...

CVE-2026-85153

Oct 6, 2026 11:47:26 UTC

This vulnerability exists in the Schmooze app due to the use of hardcoded credentials and cryptographic keys in the client application. An unauthenticated remote attacker could exploit this vulnerability by decompiling the distributed appli...

CVE-2026-15563

Oct 6, 2026 11:46:55 UTC

A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a malicious ORB, achieving MITM or DoS on further invocations.

CVE-2026-7507

Oct 6, 2026 11:46:47 UTC

A session fixation vulnerability was found in Keycloak's login-actions endpoints. An unauthenticated attacker could exploit this flaw by pre-creating an authentication session and tricking a victim into visiting a maliciously crafted link. ...

CVE-2026-7307

Oct 6, 2026 11:46:43 UTC

A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security Assertion Markup Language (SAML) endpoint. This malicious input can cause high CPU usage and worker thread starvation, l...

CVE-2026-105809

Oct 6, 2026 11:46:41 UTC

A vulnerability was identified in SourceCodester Simple Student Information System 1.0. This issue affects some unknown processing of the file /register.php of the component Profile Field Handler. The manipulation of the argument firstname/...

CVE-2026-4634

Oct 6, 2026 11:46:37 UTC

A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted POST request with an excessively long scope parameter to the OpenID Connect (OIDC) token endpoint. This leads to high re...

CVE-2026-2092

Oct 6, 2026 11:46:22 UTC

A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAML) broker endpoint does not properly validate encrypted assertions when the overall SAML response is not signed. An attacker with a valid signed SAML assertion ...

CVE-2026-0603

Oct 6, 2026 11:46:18 UTC

A flaw was found in Hibernate. A remote attacker with low privileges could exploit a second-order SQL injection vulnerability by providing specially crafted, unsanitized non-alphanumeric characters in the ID column when the InlineIdsOrClaus...

CVE-2025-12543

Oct 6, 2026 11:46:05 UTC

A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing ...

CVE-2025-9784

Oct 6, 2026 11:46:03 UTC

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server ...

CVE-2026-105918

Oct 6, 2026 11:45:14 UTC

A vulnerability has been found in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. Impacted is the function mysql_error of the file login.php of the component Login Endpoint. The manipulation of the ar...

CVE-2026-4889

Oct 6, 2026 11:42:02 UTC

SQL injection (SQLi) vulnerability in the eLoanApp application, specifically in the POST parameter 'logina' of the user process endpoint '/ajax/users.php?op=verify'. The parameter is vulnerable to boolean-based and time-based SQL injection....