Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.3 CVE-2026-53690

SQL Injection in Redeight CMS_CVE-2026-53690

An SQL Injection vulnerability exists in Redeight CMS version 1.0 via the "userEmail" parameter in the POST "/admin/index.php" login endpoint. The ...

Redeight Redeight CMS 1.0 CVE
HIGH 8.8 CVE-2026-41053

Over-inclusive team membership expansion in GitHub App authentication provider for Rancher_CVE-2026-41053

Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal acces...

SUSE Rancher 2.14.0 CVE
CRITICAL 9.3 CVE-2026-14162

Advantech|Hospital Quering Management – Missing Authentication_CVE-2026-14162

Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access...

Advantech Hospital Quering Management CVE
HIGH 8.7 CVE-2026-14161

Advantech|Hospital Queuing Management – Sensitive Data Exposure_CVE-2026-14161

Hospital Quening Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access...

Advantech Hospital Queuing Management CVE
MEDIUM 6.1 CVE-2026-8403

Stored XSS in Exagate’s SYSGUARD 6001_CVE-2026-8403

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Eksagate Electronic Engineering and Computer ...

Eksagate Electronic Engineering and Computer Industry Trade Inc. SYSGUARD 6001 2.0.2 CVE
MEDIUM 5.7 CVE-2026-53433

Denial of Service in fzf_CVE-2026-53433

fzf is vulnerable to a Denial of Service (DoS) due to inefficient HTTP body processing in the --listen mode due to inefficient HTTP body processing...

fzf fzf CVE
MEDIUM 5.6 CVE-2026-53432

Integer Overflow in fzf_CVE-2026-53432

fzf is vulnerable to Integer Overflow leading to crash in FuzzyMatchV2 function. When input line length is approximately 2,200,000 bytes and patter...

fzf fzf CVE
MEDIUM 6.5 CVE-2026-4629

Keycloak: keycloak: privilege escalation through hardcoded role mapper injection_CVE-2026-4629

A flaw was found in Keycloak. A highly privileged user with `manage-clients` permission can exploit this vulnerability by injecting a hardcoded rol...

Red Hat Red Hat Build of Keycloak CVE
CRITICAL 9.5 CVE-2026-44946

SAML Authentication Replay in Rancher_CVE-2026-44946

A SAML authentication replay vulnerability in Rancher's Assertion Consumer Service (ACS) handler did not enforce one-time use of SAML assertion, po...

SUSE Rancher 2.14.0 CVE
MEDIUM 4.3 CVE-2026-14209

Keycloak-admin-ui: keycloak-admin-ui: keycloak: admin ui extension brute-force-user endpoint bypasses fgapv2 user view restrictions_CVE-2026-14209

A vulnerability was discovered in Keycloak's Admin UI extension that allows certain administrative users to bypass security restrictions. When Fine...

Red Hat Red Hat Build of Keycloak CVE