Title |
Severity |
Exploit |
Date |
Affected Version |
CVE-2025-3910
|
Medium
|
|
Apr 30, 2025
|
< 26.2.2
|
CVE-2025-3501
|
High
|
|
Apr 30, 2025
|
< 26.2.2
|
CVE-2025-2559
|
Medium
|
|
Mar 25, 2025
|
<= 26.1.4
|
CVE-2025-1391
|
Medium
|
|
Mar 10, 2025
|
>= 26.1.0 < 26.1.3
< 26.0.10
|
CVE-2023-0657
|
Low
|
|
Nov 17, 2024
|
< 22.0.10
>= 23.0.0 < 24.0.3
|
CVE-2022-2232
|
High
|
|
Nov 14, 2024
|
< 23.0.1
|
CVE-2024-3656
|
High
|
|
Oct 9, 2024
|
< 24.0.5
|
Keycloak Denial of Service via account lockout
|
Low
|
|
Jun 12, 2024
|
< 24.0.0
|
Keycloak's improper input validation allows using email as username
|
Low
|
|
Jun 12, 2024
|
< 24.0.1
|
Keycloak exposes sensitive information in Pushed Authorization Requests (PAR)
|
High
|
|
Jun 10, 2024
|
< 24.0.5
|