Known Vulnerabilities for Realm Cms by Realm Project
Listed below are 4 of the newest known vulnerabilities associated with "Realm Cms" by "Realm Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-65009 json | OpenRemote versions before 1.26.2 contain an information disclosure vulnerability in the SyslogResource REST endpoint that fa... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-56784 json | OpenRemote before 1.25.0 contains an insecure direct object reference (IDOR) vulnerability in the bulk alarm deletion endpoin... | Not Provided | 2026-06-23 | 2026-07-14 |
| CVE-2026-53440 json | Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet cont... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-50630 json | A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate response... | Not Provided | 2026-06-12 | 2026-06-12 |
| CVE-2026-49458 json | DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(node, { ... | Not Provided | 2026-07-14 | 2026-07-15 |
| CVE-2026-48978 json | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's WWW-A... | Not Provided | 2026-07-17 | 2026-07-21 |
| CVE-2026-47209 json | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the BaseHandler.set trap in bridge.js (line 1231) igno... | Not Provided | 2026-06-12 | 2026-06-12 |
| CVE-2026-47135 json | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, Symbol.for override in setup-sandbox.js only intercept... | Not Provided | 2026-06-12 | 2026-06-12 |
| CVE-2026-46455 json | Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. The camel-keycloak security helper Keycloa... | Not Provided | 2026-07-06 | 2026-07-06 |
| CVE-2026-46389 json | UDS Identity Config builds the Keycloak configuration image (realm, plugins, theme, truststore, JARs) consumed by UDS Core's ... | Not Provided | 2026-06-05 | 2026-06-05 |