Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.1 CVE-2026-4874

Org.keycloak.protocol.oidc.grants: org.keycloak.services.managers: keycloak: server-side request forgery via oidc token endpoint manipulation_CVE-2026-4874

A flaw was found in Keycloak. An authenticated attacker can perform Server-Side Request Forgery (SSRF) by manipulating the `client_session_host` pa...

Red Hat Red Hat Build of Keycloak CVE
LOW 2.6 CVE-2025-55277

HCL Aftermarket DPC is affected by Use of Vulnerable/Outdated Versions vulnerability_CVE-2025-55277

HCL Aftermarket DPC is affected by Use of Vulnerable/Outdated Versions vulnerability using which an attacker may make use of the exploits available...

HCL Aftermarket DPC version 1.0.0 CVE
LOW 3.1 CVE-2025-55276

HCL Aftermarket DPC is affected by Internal IP Disclosure vulnerability_CVE-2025-55276

HCL Aftermarket DPC is affected by Internal IP Disclosure vulnerability will give attackers a clearer map of the organization’s network layout.

HCL Aftermarket DPC version 1.0.0 CVE
LOW 3.7 CVE-2025-55275

HCL Aftermarket DPC is affected by Admin Session Concurrency vulnerability_CVE-2025-55275

HCL Aftermarket DPC is affected by Admin Session Concurrency vulnerability using which an attacker can exploit concurrent sessions to hijack or imp...

HCL Aftermarket DPC version 1.0.0 CVE
LOW 2.6 CVE-2025-55274

HCL Aftermarket DPC is affected by Cross-Origin Resource Sharing vulnerability_CVE-2025-55274

HCL Aftermarket DPC is affected by Cross-Origin Resource Sharing vulnerability. CORS misconfigurations includes the exposure of sensitive user info...

HCL Aftermarket DPC version 1.0.0 CVE
LOW 3.1 CVE-2025-55272

HCL Aftermarket DPC is affected by Banner Disclosure vulnerability_CVE-2025-55272

HCL Aftermarket DPC is affected by Banner Disclosure vulnerability where attackers gain insights into the system’s software and version details whi...

HCL Aftermarket DPC version 1.0.0 CVE
LOW 3.1 CVE-2025-55271

HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerability_CVE-2025-55271

HCL Aftermarket DPC is affected by HTTP Response Splitting vulnerability where in depending on how the web application handles the split response, ...

HCL Aftermarket DPC version 1.0.0 CVE
LOW 3.5 CVE-2025-55270

HCL Aftermarket DPC is affected by Improper Input Validation_CVE-2025-55270

HCL Aftermarket DPC is affected by Improper Input Validation which allows an attacker to inject executable code and can carry out attacks such as X...

HCL Aftermarket DPC version 1.0.0 CVE
LOW 2.2 CVE-2026-3109

Missing timestamp validation in Zoom webhook handler_CVE-2026-3109

Mattermost Plugins versions

Mattermost Mattermost CVE
LOW 1.3 CVE-2026-33402

SAK-52311: Sakai site-manage group titles can contain XSS content_CVE-2026-33402

Sakai is a Collaboration and Learning Environment (CLE). In versions 23.0 through 23.4 and 25.0 through 25.1, group titles and description can cont...

sakaiproject sakai >= 23.0, < 23.5 CVE