| CVE-2025-20020 |
|
12.08.2026 |
|
| CVE-2025-24488 |
|
12.08.2026 |
|
| CVE-2025-24837 |
|
12.08.2026 |
|
| CVE-2025-25275 |
|
12.08.2026 |
|
| CVE-2025-27245 |
|
12.08.2026 |
|
| CVE-2025-27570 |
|
12.08.2026 |
|
| CVE-2025-30178 |
|
12.08.2026 |
|
| CVE-2025-31943 |
|
12.08.2026 |
|
| CVE-2025-32084 |
|
12.08.2026 |
|
| CVE-2025-32087 |
|
12.08.2026 |
|
| CVE-2025-32737 |
|
12.08.2026 |
|
| CVE-2025-35977 |
|
12.08.2026 |
|
| CVE-2025-35988 |
|
12.08.2026 |
|
| CVE-2026-15803 |
|
12.08.2026 |
|
| CVE-2026-19548 |
Binutils: binutils: multiple use-after-free in add_archive_element via lto plugin processing |
12.08.2026 |
|
| CVE-2026-54183 |
Apache Airflow: Airflow Variables were not masked in the UI for authenticated users |
12.08.2026 |
|
| CVE-2026-58076 |
Apache Airflow: Unguarded import_string() of airflow_exc_ser / base_exc_ser exception nodes in BaseSerialization.deserialize enables DAG-author RCE on Scheduler / API Server |
12.08.2026 |
|
| CVE-2026-59242 |
Apache Airflow: Arbitrary airflow.* class instantiation on the API server via the XCom deserialize endpoint |
12.08.2026 |
|
| CVE-2026-59244 |
Apache Airflow: Secrets masker: `var.json` Variable values not masked in the Rendered Templates UI |
12.08.2026 |
|
| CVE-2026-69107 |
Potential unauthorized artifact access in JFrog Artifactory |
12.08.2026 |
5.9 |
| CVE-2026-73292 |
Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation |
12.08.2026 |
8.3 |
| CVE-2026-73293 |
Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision |
12.08.2026 |
8.8 |
| CVE-2026-73294 |
Semaphore U: OS Command Injection |
12.08.2026 |
9.9 |
| CVE-2026-73325 |
Fujitsu OneCompression 1.2.0 Arbitrary Code Execution via torch.load Deserialization |
12.08.2026 |
|
| CVE-2026-64639 |
|
12.08.2026 |
|
| CVE-2026-65017 |
Apache Airflow: Config API: team-scoped Celery broker secret disclosed to a Viewer (multi-team masking bypass) |
12.08.2026 |
|
| CVE-2026-65926 |
Private Release Bundle versions may be disclosed under specific configurations |
12.08.2026 |
3.1 |
| CVE-2026-65937 |
WhatsUp Gold versions prior to 26.0.2 contain multiple stored cross-site scripting (XSS) vulnerabilities across the web UI |
12.08.2026 |
8 |
| CVE-2026-65938 |
WhatsUp Gold versions prior to 26.0.2 contain an improper authorization vulnerability in the Scheduled Reports API. |
12.08.2026 |
4.3 |
| CVE-2026-65939 |
WhatsUp Gold versions prior to 26.0.2 contain an arbitrary file write vulnerability in the LogToFile action handler. |
12.08.2026 |
6.8 |
| CVE-2026-65940 |
WhatsUp Gold versions prior to 26.0.2 excessive file system permissions allows a privileged attacker to write arbitrary files to a web-accessible location on the host server. |
12.08.2026 |
6.8 |
| CVE-2026-65941 |
WhatsUp Gold versions prior to 26.0.2 contain an unauthenticated remote code execution vulnerability in an internal report scheduling service. |
12.08.2026 |
8.8 |
| CVE-2026-66016 |
Rendered Artifactory Helm manifests may contain generated TLS private keys |
12.08.2026 |
6.7 |
| CVE-2026-66384 |
Authenticated users may write data outside the intended Docker cache path |
12.08.2026 |
5.3 |
| CVE-2026-67260 |
Apache Airflow: DAG-author remote code execution on the Scheduler via awaiting_input next_kwargs deserialization |
12.08.2026 |
|
| CVE-2026-67587 |
Apache Airflow: DAG-author remote code execution on the Scheduler via a Serde `Callback` deserialization gadget |
12.08.2026 |
|
| CVE-2026-68076 |
Apache Airflow: Connections test API: team-scope guard bypass resolves another team's environment Connection |
12.08.2026 |
|
| CVE-2026-68758 |
Authenticated users may access restricted Artifactory support information |
12.08.2026 |
6.5 |
| CVE-2026-68759 |
Integration credential holders may impersonate users in JFrog Access |
12.08.2026 |
7.2 |
| CVE-2026-68968 |
Apache Airflow: Authorization bypass in the Backfill API through conflicting interpretations of the backfill id |
12.08.2026 |
|
| CVE-2026-68969 |
Apache Airflow: Bulk Variable and Connection endpoints record secret values in the audit log in cleartext |
12.08.2026 |
|
| CVE-2026-68970 |
Apache Airflow: Values of a list-shaped Variable are not masked in task logs and the Rendered Templates UI |
12.08.2026 |
|
| CVE-2026-68971 |
Apache Airflow: Cross-team authorization bypass in the asset materialization and dag-run result endpoints |
12.08.2026 |
|
| CVE-2026-69105 |
Potential package cache integrity issue in JFrog Artifactory |
12.08.2026 |
8.1 |
| CVE-2026-70547 |
Potential unauthorized metadata exposure in JFrog Artifactory |
12.08.2026 |
4.3 |
| CVE-2026-14478 |
Incorrect Permission Assignment in Autodesk Installer Named Pipes |
12.08.2026 |
7.8 |
| CVE-2026-14479 |
Denial of Service in Autodesk Installer IPC Channel |
12.08.2026 |
5.5 |
| CVE-2026-18171 |
Docker Sandboxes read-only runtime mount writable through its shared-export alias |
12.08.2026 |
|
| CVE-2026-66375 |
Low-privilege users may remove protected Artifactory metadata |
12.08.2026 |
8.1 |
| CVE-2026-66376 |
Deleted users may temporarily retain access to JFrog Artifactory |
12.08.2026 |
4.2 |
| CVE-2026-66377 |
Anonymous users may access restricted Artifactory repository information |
12.08.2026 |
5.3 |
| CVE-2026-66378 |
Authenticated users may access private NuGet metadata |
12.08.2026 |
4.3 |
| CVE-2026-66379 |
Authenticated users may view private Puppet module metadata |
12.08.2026 |
4.3 |
| CVE-2026-66380 |
Authenticated users may access private OCI referrer metadata |
12.08.2026 |
4.3 |
| CVE-2026-66381 |
Repository readers may access content outside configured upstream paths |
12.08.2026 |
5.3 |
| CVE-2026-66382 |
Authenticated users may write files outside the intended Artifactory work directory |
12.08.2026 |
4.3 |
| CVE-2026-68752 |
Project Resource Managers may escalate privileges in JFrog Artifactory |
12.08.2026 |
7.2 |
| CVE-2026-68753 |
Anonymous users may access restricted Artifactory content under specific configurations |
12.08.2026 |
5.3 |
| CVE-2026-68754 |
Publishers without delete permission can overwrite docker layer information |
12.08.2026 |
6.5 |
| CVE-2026-68755 |
Bundle writers may alter trusted release information in JFrog Artifactory |
12.08.2026 |
4.3 |
| CVE-2026-68756 |
Potential insecure deserialization in JFrog Artifactory |
12.08.2026 |
6.6 |
| CVE-2026-68757 |
Potential improper SAML signature verification in JFrog Artifactory |
12.08.2026 |
7.5 |
| CVE-2026-68760 |
Potential remember-me authentication bypass in JFrog Artifactory |
12.08.2026 |
5.3 |
| CVE-2026-73291 |
Seerr: Path traversal to RCE via /avatarproxy image cache filename from upstream ETag |
12.08.2026 |
7.1 |
| CVE-2026-73263 |
Prowler: RCE on Prowler App workers via kubeconfig auth-provider cmd-path |
12.08.2026 |
9.9 |
| CVE-2026-73264 |
Prowler: Server-Side Request Forgery (SSRF) in Lighthouse Provider |
12.08.2026 |
7.6 |
| CVE-2026-73265 |
RustFS: Version-specific object reads authorize the non-version action |
12.08.2026 |
6.5 |
| CVE-2026-73284 |
RustFS: AddServiceAccount Handler Allows Creation of Root-Parent Service Accounts |
12.08.2026 |
8.8 |
| CVE-2026-73285 |
RustFS: OPA policy plugin omits ExistingObjectTag conditions, allowing tag-based authorization policies to treat tagged objects as untagged |
12.08.2026 |
7.5 |
| CVE-2026-73286 |
RustF: Request headers can populate server-derived IAM condition keys, letting a caller satisfy identity-based policy conditions |
12.08.2026 |
8.1 |
| CVE-2026-73287 |
RustFS: FTPS MKD bypasses IAM CreateBucket authorization |
12.08.2026 |
5.4 |
| CVE-2026-73288 |
RustFS: Object Lock (WORM) protections are treated as absent when bucket metadata cannot be read, allowing retained objects to be deleted |
12.08.2026 |
|
| CVE-2026-73289 |
RustFS: ForAllValues/ForAnyValue negated string conditions are transposed, inverting IAM and bucket-policy decisions |
12.08.2026 |
8.1 |
| CVE-2026-73290 |
RustFS: Anonymous ListObjectVersions bypasses RestrictPublicBuckets through the ListBucket fallback |
12.08.2026 |
5.3 |
| CVE-2026-73431 |
Reusable Account Activation and Recovery Tokens Allow Repeated Account Takeover in vulnerability-lookup |
12.08.2026 |
|
| CVE-2026-73432 |
Stored Server-Side Request Forgery in Remote-Instance Synchronization Allows Access to Internal Services in vulnerability-lookup |
12.08.2026 |
|
| CVE-2025-59319 |
|
12.08.2026 |
|
| CVE-2025-59320 |
|
12.08.2026 |
|
| CVE-2025-59321 |
|
12.08.2026 |
|
| CVE-2025-59322 |
|
12.08.2026 |
|
| CVE-2025-59323 |
|
12.08.2026 |
|
| CVE-2025-59324 |
|
12.08.2026 |
|
| CVE-2026-47233 |
Admidio: Any logged-in user can delete inventory fields via `mode=field_delete` — incomplete fix of #2024 |
12.08.2026 |
6.5 |
| CVE-2026-47234 |
Admidio writes session IDs and auto-login cookie values to application logs |
12.08.2026 |
4.4 |
| CVE-2026-49262 |
Aimeos Pagible CMS vulnerable to Server Side Request Forgery (SSRF) via DNS rebinding in admin proxy |
12.08.2026 |
3 |
| CVE-2026-49349 |
regclient may leak authentication credentials to external blob stores |
12.08.2026 |
6.8 |
| CVE-2026-50561 |
Yuxi has a JWT Authentication Bypass Leading to Cross-Instance Administrator Token Reuse |
12.08.2026 |
9.4 |
| CVE-2026-67286 |
Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0 |
12.08.2026 |
|
| CVE-2026-67287 |
Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 |
12.08.2026 |
|
| CVE-2026-73262 |
Prowler: Stored XSS in HTML reports through unescaped cloud resource tags |
12.08.2026 |
5.4 |
| CVE-2026-73374 |
Stored Cross-Site Scripting (XSS) via Unescaped CNA Reference Tags in vulnerability-lookup |
12.08.2026 |
|
| CVE-2026-73405 |
Authorization Bypass in SSE Pub/Sub Allows Unconfirmed Accounts to Access Stream Events in vulnerability-lookup |
12.08.2026 |
|
| CVE-2025-59325 |
|
12.08.2026 |
|
| CVE-2025-59326 |
|
12.08.2026 |
|
| CVE-2025-59327 |
|
12.08.2026 |
|
| CVE-2026-16999 |
XXE in Ministry of Justice's UYAP Document Editor |
12.08.2026 |
6.3 |
| CVE-2026-67285 |
Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 |
12.08.2026 |
|
| CVE-2026-47227 |
Admidio module-administrator can delete or reorder categories owned by other modules via dead authorization check in `modules/categories.php` |
12.08.2026 |
6.5 |
| CVE-2026-47228 |
Admidio's CSRF in registration `send_login` mode resets arbitrary user passwords |
12.08.2026 |
5.2 |
| CVE-2026-47229 |
Admidio: CSRF in SSO client `enable` action toggles SAML/OIDC clients without token validation |
12.08.2026 |
5.4 |
| CVE-2026-47230 |
Admidio: IDOR in documents-files.php allows cross-folder file rename and description changes by unauthorized uploaders |
12.08.2026 |
6.5 |
| CVE-2026-47231 |
Admidio has IDOR in `documents-files.php` `mode=move_save` that lets any folder-uploader exfiltrate files from private folders |
12.08.2026 |
8.1 |
| CVE-2026-47232 |
Admidio PKCS#12 private key export action lacks CSRF protection |
12.08.2026 |
4.3 |
| CVE-2026-47226 |
Admidio: Authorization bypass in file_delete enables cross-folder file removal by authenticated users without delete privileges |
12.08.2026 |
6.5 |
| CVE-2026-53996 |
NetBSD hdaudio(4) Driver Privilege Bypass Use-After-Free via HDAUDIO_FGRP_SETCONFIG ioctl |
12.08.2026 |
|
| CVE-2026-26035 |
|
12.08.2026 |
8.8 |
| CVE-2026-57858 |
Cal.com Cal.diy 6.2.0 Stored XSS via BookingPageTagManager Analytics Tracking ID |
12.08.2026 |
|
| CVE-2026-70466 |
|
12.08.2026 |
4.8 |
| CVE-2026-70467 |
|
12.08.2026 |
3.4 |
| CVE-2026-70468 |
|
12.08.2026 |
7.3 |
| CVE-2026-71407 |
|
12.08.2026 |
5.1 |
| CVE-2026-71408 |
|
12.08.2026 |
5 |
| CVE-2026-70465 |
|
12.08.2026 |
7.3 |
| CVE-2026-11325 |
cloudflare/pages-action is deprecated — migration required by September 18th, 2026 |
12.08.2026 |
8.8 |
| CVE-2026-15045 |
Wallet System for WooCommerce < 2.7.10 - Customer+ Checkout Price Manipulation via Unvalidated Wallet Amount |
12.08.2026 |
6.5 |
| CVE-2026-15213 |
Welcart e-Commerce < 2.11.33 - Unauthenticated Payment Bypass via Forged Settlement Callback |
12.08.2026 |
5.3 |
| CVE-2026-16621 |
Payment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via PayPal Advanced Return Handler |
12.08.2026 |
5.3 |
| CVE-2026-16747 |
Kirki < 6.2.1 - Unauthenticated Arbitrary Shortcode Execution via Form Email Actions |
12.08.2026 |
6.5 |
| CVE-2026-16990 |
Payment Button for PayPal <= 1.2.3.44 - Unauthenticated Payment Price Manipulation |
12.08.2026 |
5.3 |
| CVE-2026-17008 |
Quick PayPal Payments <= 5.7.50 - Unauthenticated Payment Bypass via PayPal IPN |
12.08.2026 |
5.3 |
| CVE-2026-18044 |
Estatik Real Estate Plugin < 4.3.4 - Unauthenticated Arbitrary-Recipient Mail Relay via Signed-Value Mismatch |
12.08.2026 |
3.7 |
| CVE-2026-70560 |
Ultimate POS Stored XSS via First Name Field in Leave Notifications |
12.08.2026 |
|
| CVE-2026-68868 |
Apache Airflow Google provider: google Secret Manager backend: team scope is never applied, exposing every team's Connections and Variables |
12.08.2026 |
|
| CVE-2026-18652 |
Velociraptor STACK Type Download Path Bypasses Denied Prefix Check |
12.08.2026 |
4.9 |
| CVE-2026-64951 |
Velociraptor DoS triggered by Divide by Zero panic |
12.08.2026 |
3.5 |
| CVE-2026-64952 |
Velociraptor Hunt Deletion With Insufficient Permission Check |
12.08.2026 |
6.5 |
| CVE-2026-64955 |
Velociraptor CSV Formula Injection in Export Pipeline |
12.08.2026 |
6.1 |
| CVE-2026-67284 |
Joomla Extension - tabaoca.org - Improper ACL checks allow file operations in Cotton Cloud < 2.0.2 |
12.08.2026 |
|
| CVE-2026-18663 |
389-ds-base: 389-ds-base: pre-authentication double-free in get_ldapmessage_controls_ext() via critical session tracking control |
12.08.2026 |
|
| CVE-2026-67282 |
Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 |
12.08.2026 |
|
| CVE-2026-67283 |
Joomla Extension - tabaoca.org - Improper ACL implementation allows allow file operations in Cotton Cloud < 2.0.2 |
12.08.2026 |
|
| CVE-2026-19566 |
Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix lengths |
12.08.2026 |
|
| CVE-2025-41769 |
Unauthenticated Buffer Overflow in PROFINET Service |
12.08.2026 |
|
| CVE-2025-41770 |
Unauthenticated Denial of Service |
12.08.2026 |
|
| CVE-2025-41771 |
SQL injection |
12.08.2026 |
|
| CVE-2026-19426 |
FitSoft|POS Sytstem - Missing Authentication |
12.08.2026 |
8.2 |
| CVE-2026-12976 |
LearnPress < 4.4.4 - Subscriber+ Sensitive Information Exposure via AI Assistant |
12.08.2026 |
|
| CVE-2026-13168 |
Eventin < 4.1.20 - Contributor+ Customer PII Disclosure via REST API |
12.08.2026 |
|
| CVE-2026-13171 |
Eventin < 4.1.20 - Unauthenticated Account Creation via Waiting List Endpoint |
12.08.2026 |
|
| CVE-2026-13177 |
Eventin < 4.1.20 - Contributor+ Order Information Disclosure via IDOR |
12.08.2026 |
|
| CVE-2026-13612 |
KiviCare < 4.5.2 - Patient+ Cross-Patient Bill, Invoice and Appointment Disclosure via IDOR |
12.08.2026 |
|
| CVE-2026-13613 |
KiviCare < 4.5.2 - Doctor/Receptionist+ SQL Injection via settings/listing REST Endpoint |
12.08.2026 |
|
| CVE-2026-14857 |
WP Crowdfunding < 2.2.1 - Subscriber+ Campaign Update Modification via IDOR |
12.08.2026 |
|
| CVE-2026-14858 |
WP Crowdfunding < 2.2.1 - Subscriber+ Order Data Disclosure via IDOR |
12.08.2026 |
|
| CVE-2026-14859 |
WP Crowdfunding < 2.2.1 - Subscriber+ Campaign Creation via Missing Authorization |
12.08.2026 |
|
| CVE-2026-14925 |
Import WP < 2.14.23 - Unauthenticated Sensitive Information Exposure via Export File Download |
12.08.2026 |
|
| CVE-2026-15039 |
Gift Cards For WooCommerce Pro < 4.2.10 - Unauthenticated Arbitrary File Upload |
12.08.2026 |
|
| CVE-2026-15249 |
Patterns Kit <= 1.0.3 - Contributor+ Stored XSS via YouTube Popup Link |
12.08.2026 |
|
| CVE-2026-15388 |
Cookie Consent < 0.0.10 - Subscriber+ Consent Settings Update and Consent Log Disclosure |
12.08.2026 |
|
| CVE-2026-16051 |
WPMU DEV Dashboard < 5.0.1 - Remote Code Execution via Hub Install Action |
12.08.2026 |
|
| CVE-2026-16066 |
Welcart e-Commerce < 2.11.34 - Author+ Stored XSS via Product Name |
12.08.2026 |
|
| CVE-2026-16253 |
Total Upkeep (BoldGrid Backup) < 1.17.3 - Unauthenticated Sensitive Data Disclosure and Forced Site Restore via Predictable cron_secret (regression of CVE-2020-36848) |
12.08.2026 |
|
| CVE-2026-16294 |
Blubrry PowerPress < 11.17.1 - Contributor+ Server-Side Request Forgery via Podcast Episode Chapters URL |
12.08.2026 |
|
| CVE-2026-16538 |
TeraWallet - Wallet for WooCommerce < 1.6.10 - Subscriber+ Wallet Balance Inflation via Discounted Top-Up |
12.08.2026 |
|
| CVE-2026-16737 |
WP Travel Engine < 6.8.5 - Unauthenticated Booking Details Disclosure and Modification via wte_add_trip_to_cart |
12.08.2026 |
|
| CVE-2026-16977 |
Form Maker by 10Web < 1.15.45 - Subscriber+ SQL Injection via display_name |
12.08.2026 |
|
| CVE-2026-17013 |
WP Photo Album Plus < 9.2.07.002 - Reflected XSS via lbstart |
12.08.2026 |
|
| CVE-2026-18035 |
User Access Manager < 2.3.15 - Unauthenticated Restricted Content Disclosure via REST API |
12.08.2026 |
|
| CVE-2026-18046 |
Cookie Consent < 0.0.10 - Subscriber+ MaxMind License Key Update |
12.08.2026 |
|
| CVE-2026-18048 |
WP Photo Album Plus < 9.2.07.002 - Unauthenticated Arbitrary ZIP File Deletion via delmyzip Path Traversal |
12.08.2026 |
|
| CVE-2026-18049 |
WP Photo Album Plus < 9.2.07.002 - Unauthenticated Option Disclosure via gettogo |
12.08.2026 |
|
| CVE-2026-18057 |
Events Manager < 7.4.1 - Subscriber+ Booking Consent Record Tampering via SQL Injection |
12.08.2026 |
|
| CVE-2026-18230 |
WP Directory Kit < 1.5.6 - Subscriber+ SQL Injection via section Parameter |
12.08.2026 |
|
| CVE-2026-18366 |
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator |
12.08.2026 |
|
| CVE-2026-18391 |
WooCommerce Subscriptions < 9.1.0 - Unauthenticated RCE via PHP Object Injection |
12.08.2026 |
|
| CVE-2026-18474 |
WP Directory Kit < 1.5.6 - Unauthenticated SQL Injection via search_location and search_category |
12.08.2026 |
|
| CVE-2026-18789 |
Ezoic < 2.23.1 - Unauthenticated Database Export via Content Export REST Routes |
12.08.2026 |
|
| CVE-2026-18943 |
WPC Admin Columns < 2.3.4 - Subscriber+ Arbitrary User/Post/Term Meta Disclosure |
12.08.2026 |
|
| CVE-2026-18962 |
WP Photo Album Plus < 9.2.09.002 - Subscriber+ Cross-Album File Upload via Missing Authorization |
12.08.2026 |
|
| CVE-2026-19050 |
ProSolution WP Client < 2.0.9 - Subscriber+ SSRF via proSol_url_validate |
12.08.2026 |
|
| CVE-2026-19052 |
ProSolution WP Client < 2.0.9 - Subscriber+ proSol_ajaxTablesync and proSol_ajaxClearlog Calls |
12.08.2026 |
|
| CVE-2026-19073 |
Order Sync with Zendesk for WooCommerce < 2.2.3 - Unauthenticated Customer Order Data Disclosure |
12.08.2026 |
|
| CVE-2026-19217 |
Royal Elementor Addons < 1.7.1065 - Contributor+ Stored XSS via Icon Box Widget |
12.08.2026 |
|
| CVE-2026-66659 |
WordPress Tablesome Table plugin <= 1.2.9 - SQL Injection vulnerability |
12.08.2026 |
9.3 |
| CVE-2026-19594 |
Path Traversal and HTTP Parameter Pollution in Snowflake Python API (snowflake.core) Allow Confused-Deputy Privilege Escalation |
12.08.2026 |
8.1 |
| CVE-2026-12234 |
TOCTOU double-fetch in `zsock_sendmsg`/`recvmsg` userspace verifiers allows kernel-heap out-of-bounds write |
12.08.2026 |
7.8 |
| CVE-2026-12235 |
Out-of-bounds write in Xtensa llext PLT relocation from malformed ELF (CWE-787) |
12.08.2026 |
6.3 |
| CVE-2026-64954 |
Velociraptor collect_client() Permissions Bypass |
12.08.2026 |
8.2 |
| CVE-2026-12232 |
Out-of-bounds read via unvalidated stream_id in Intel ALH DAI get_properties |
12.08.2026 |
6.1 |
| CVE-2026-12233 |
Uninitialized mutex in TLS trusted-credential backend causes kernel NULL-deref DoS under contention |
12.08.2026 |
5.9 |
| CVE-2025-15687 |
Open5GS SMF Diameter Gx Credit-Control-Answer smf_gx_cca_cb denial of service |
12.08.2026 |
|
| CVE-2025-15684 |
Open5GS CER init.c diam_log_func assertion |
12.08.2026 |
|
| CVE-2025-15685 |
Open5GS freeDiameter memory corruption |
12.08.2026 |
|
| CVE-2025-15686 |
Open5GS HSS Service fd_msg_sess_get denial of service |
12.08.2026 |
|
| CVE-2026-18961 |
Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect <= 1.4.3 - Unauthenticated Authentication Bypass via Spotify OAuth Callback |
12.08.2026 |
8.1 |
| CVE-2026-19587 |
|
12.08.2026 |
6.5 |
| CVE-2026-19588 |
|
12.08.2026 |
6.5 |
| CVE-2026-9318 |
tablib versions prior to 3.10.0 Stored XSS via HTML Export Dataset Title |
12.08.2026 |
|
| CVE-2026-64927 |
Multicloud-operators-channel: multicloud-operators-channel: cross-namespace secret and configmap mutation via spec.secretref.namespace confused deputy |
12.08.2026 |
|
| CVE-2026-66878 |
Multicloud-operators-subscription: multicloud-operators-subscription: fetchchannelreferences honours channel.spec.secretref.namespace enabling cross-namespace secret exfiltration |
12.08.2026 |
|
| CVE-2026-70398 |
Multicloud-integrations: multicloud-integrations: gitopscluster.spec.argoserver.argonamespace writes spoke bearer tokens to attacker-chosen namespace |
12.08.2026 |
|
| CVE-2026-72526 |
Multicloud-integrations: multicloud-integrations: pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-cluster annotation |
12.08.2026 |
|
| CVE-2026-73122 |
Multicloud-operators-channel: multicloud-operators-channel: auto-generated role grants every managed-cluster agent secrets:get,list,watch in channel namespaces |
12.08.2026 |
|
| CVE-2024-14044 |
Open5GS Diameter Rx pcrf-rx-path.c pcrf_rx_aar_cb buffer overflow |
12.08.2026 |
|
| CVE-2026-68447 |
drm/amdkfd: clamp v9 CRIU control stack checkpoint copy to BO size |
12.08.2026 |
|
| CVE-2026-68448 |
ovl: check access to copy_file_range source with src mounter creds |
12.08.2026 |
|
| CVE-2026-68449 |
ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning |
12.08.2026 |
|
| CVE-2026-68450 |
btrfs: free mapping node on duplicate reloc root insert |
12.08.2026 |
|
| CVE-2026-6484 |
Lack of verified boot to certain FV may cause arbitrary code execution |
12.08.2026 |
8.2 |
| CVE-2026-68429 |
drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe() |
12.08.2026 |
|
| CVE-2026-68430 |
drm/amdgpu/gfx8: drop unecessary BUG_ON() |
12.08.2026 |
|
| CVE-2026-68431 |
ksmbd: validate minimum PDU size for transform requests |
12.08.2026 |
|
| CVE-2026-68432 |
vxlan: require CAP_NET_ADMIN in the device netns for changelink |
12.08.2026 |
|
| CVE-2026-68433 |
libceph: bound get_version reply decode to front len |
12.08.2026 |
|
| CVE-2026-68434 |
serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms |
12.08.2026 |
|
| CVE-2026-68435 |
LoongArch: Fix address space mismatch in kexec command line lookup |
12.08.2026 |
|
| CVE-2026-68436 |
drm/amd/display: use kvzalloc to allocate struct dc |
12.08.2026 |
|
| CVE-2026-68437 |
drm/imagination: Fit paired fragment job in the correct CCCB |
12.08.2026 |
|
| CVE-2026-68438 |
smp: Make CSD lock acquisition atomic for debug mode |
12.08.2026 |
|
| CVE-2026-68439 |
wifi: mt76: mt7925: fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv() |
12.08.2026 |
|
| CVE-2026-68440 |
net: txgbe: fix heap overflow when reading module EEPROM |
12.08.2026 |
|
| CVE-2026-68441 |
net/sched: Handle TC_ACT_REDIRECT from qdisc filter chains |
12.08.2026 |
|
| CVE-2026-68442 |
btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps |
12.08.2026 |
|
| CVE-2026-68443 |
hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop |
12.08.2026 |
|
| CVE-2026-68444 |
firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get() |
12.08.2026 |
|
| CVE-2026-68445 |
drm/vc4: Prevent shader BO mappings from becoming writable |
12.08.2026 |
|
| CVE-2026-68446 |
drm/vmwgfx: Validate vmw_surface_metadata::array_size |
12.08.2026 |
|
| CVE-2024-14043 |
Open5GS Diameter S6a mme-fd-path.c mme_s6a_subscription_data_from_avp heap-based overflow |
12.08.2026 |
|
| CVE-2026-73250 |
Notepad++: Install-time PowerShell command injection through installation path |
11.08.2026 |
|
| CVE-2026-18710 |
Cleartext Storage of Sensitive Information in MongoDB Driver Logging During Client Initialization |
12.08.2026 |
|
| CVE-2026-73246 |
Kestra: Unauthenticated management `/worker` endpoint exposes live task configuration and plaintext credentials |
11.08.2026 |
7.5 |
| CVE-2026-73247 |
Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata |
11.08.2026 |
8.6 |
| CVE-2026-73248 |
calibre: Bypass of Python template restrictions via nested `template()` leading to RCE |
12.08.2026 |
|
| CVE-2026-73249 |
calibre Content Server `/book-update-annotations` Missing Write Authorization Check Allows Unauthorized Annotation Modification |
12.08.2026 |
7.5 |
| CVE-2026-29036 |
cJSON 1.7.19 Wrong-Key Modification via JSON Pointer Escape Decoding |
11.08.2026 |
|
| CVE-2026-5917 |
libgit2 v0.27.0-v1.9.0 Shell Command Injection via ssh_libssh2 Backend |
12.08.2026 |
|
| CVE-2026-66098 |
Mira Hormone Monitor, Mira Android App Missing authentication for critical function |
12.08.2026 |
|
| CVE-2026-66875 |
Mira Hormone Monitor, Mira Android App Missing authentication for critical function |
12.08.2026 |
|
| CVE-2026-67558 |
Mira Hormone Monitor, Mira Android App Authentication bypass by spoofing |
12.08.2026 |
|
| CVE-2026-67568 |
Mira Hormone Monitor, Mira Android App Use of Hard-coded Credentials |
12.08.2026 |
|
| CVE-2026-73245 |
Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-auth |
12.08.2026 |
6.5 |
| CVE-2026-19556 |
|
12.08.2026 |
|
| CVE-2026-19557 |
|
12.08.2026 |
|
| CVE-2026-19558 |
|
12.08.2026 |
|
| CVE-2026-19559 |
|
11.08.2026 |
|
| CVE-2026-19560 |
|
12.08.2026 |
|
| CVE-2026-64934 |
Mira Hormone Monitor, Mira Android App Reliance on untrusted inputs in a security decision |
12.08.2026 |
|
| CVE-2026-66340 |
Mira Hormone Monitor, Mira Android App Improper restriction of excessive authentication attempts |
12.08.2026 |
|
| CVE-2026-68067 |
Mira Hormone Monitor, Mira Android App Weak Authentication |
12.08.2026 |
|
| CVE-2026-19550 |
Freeipa: ipa: freeipa: trust-fetch-domains uses trust-read aci to gate a privileged ad trust refresh, allowing unauthorized ldap writes |
12.08.2026 |
|
| CVE-2026-48763 |
TypeBot has Arbitrary S3 Object Write in deprecated public upload endpoint via attacker-controlled filePath |
12.08.2026 |
8.2 |
| CVE-2026-66832 |
Mira Hormone Monitor, Mira Android App Use of GET request method with sensitive query strings |
12.08.2026 |
|
| CVE-2026-14863 |
FileRun 2026.2.0 RCE via Thumbnail Generation Command Injection |
12.08.2026 |
|
| CVE-2026-15606 |
Frontend Admin by DynamiApps <= 3.29.9 - Authenticated (Subscriber+) Arbitrary Password Reset via Encrypted Object Token |
12.08.2026 |
8.8 |
| CVE-2026-48762 |
TypeBot Vulnerable to Server-Side Request Forgery (SSRF) in OpenAI Transcription Handler |
11.08.2026 |
5.4 |
| CVE-2026-48765 |
TypeBot vulnerable to cross-workspace OAuth credential takeover in updateOAuthCredentials via missing object binding |
12.08.2026 |
9.9 |
| CVE-2026-63133 |
Malcolm has Uncontrolled Resource Consumption in Archive Extraction (Inode-Exhaustion DoS) |
12.08.2026 |
6.5 |
| CVE-2026-63134 |
Malcolm's Path Traversal in Archive Extraction Allows Arbitrary Directory Creation |
11.08.2026 |
5.4 |
| CVE-2026-63177 |
Malcolm Vulnerable to Authorization Bypass via URI Normalization Differential in Nginx Lua RBAC |
11.08.2026 |
7.1 |
| CVE-2026-71290 |
Apache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM) |
11.08.2026 |
|
| CVE-2026-18634 |
|
12.08.2026 |
|
| CVE-2026-19579 |
Snipe-IT Checkout Request Cancellation IDOR |
11.08.2026 |
|
| CVE-2026-29035 |
CivetWeb Heap/Stack Buffer Overflow via WebSocket permessage-deflate Decompression |
11.08.2026 |
|
| CVE-2026-55676 |
Malcolm vulnerable to RCE via unrestricted .php upload to the file-upload component |
11.08.2026 |
8.8 |
| CVE-2026-66147 |
|
12.08.2026 |
|
| CVE-2026-66148 |
|
11.08.2026 |
|
| CVE-2026-66149 |
|
12.08.2026 |
|
| CVE-2026-66150 |
|
12.08.2026 |
|
| CVE-2026-66154 |
|
12.08.2026 |
|
| CVE-2026-18844 |
Pulsetto Vagus Nerve Stimulator Hidden Functionality |
11.08.2026 |
|
| CVE-2026-66145 |
|
12.08.2026 |
|
| CVE-2026-66146 |
|
11.08.2026 |
|
| CVE-2026-73243 |
kkFileView: Unauthenticated SSRF via /addTask with fullfilename type-confusion bypass |
11.08.2026 |
5.8 |
| CVE-2026-73244 |
kkFileView: Unauthenticated path traversal in POST /listFiles allows arbitrary directory listing |
11.08.2026 |
5.3 |
| CVE-2026-13457 |
InstaWP Connect <= 0.1.3.6 - Unauthenticated Cryptographic Key Disclosure |
12.08.2026 |
7.5 |
| CVE-2026-16230 |
Formidable Digital Signatures <= 3.0.6 - Unauthenticated Arbitrary File Deletion via Signature Field |
11.08.2026 |
9.8 |
| CVE-2026-19091 |
GeoDirectory <= 2.8.169 - Authenticated (Subscriber+) Arbitrary File Deletion via 'post_type' Parameter via Query-String Bypass in geodir_save_post + geodir_delete_revision |
11.08.2026 |
8.1 |
| CVE-2026-45618 |
LiquidJS is Vulnerable to Remote Code Execution |
11.08.2026 |
10 |
| CVE-2026-65655 |
Temporal UI Server may set OAuth credential cookies without Secure behind a TLS-terminating reverse proxy |
11.08.2026 |
|
| CVE-2026-73034 |
DB-GPT v0.8.1 Path Traversal Arbitrary File Write via user_id Header |
11.08.2026 |
|
| CVE-2026-73036 |
Bash-it barbuk Theme 3.2.0 Terminal Escape Sequence Injection via pyproject.toml |
12.08.2026 |
|
| CVE-2026-73231 |
Faker: helpers.fake exploitable into arbritary code execution |
11.08.2026 |
7.8 |
| CVE-2026-73232 |
ffuf denial of service (OOM) via HTTP response decompression bomb |
12.08.2026 |
7.5 |
| CVE-2026-73233 |
FreeCAD: FEM formula incomplete escape |
11.08.2026 |
|
| CVE-2026-73234 |
FreeCAD: FCStd path traversal allows arbitrary file write via unsanitized file attribute in PropertyFileIncluded::Restore() |
11.08.2026 |
7.8 |
| CVE-2026-73235 |
FreeCAD: XXE file read and SSRF via external entity injection in Document.xml SAX parser |
11.08.2026 |
6.1 |
| CVE-2026-73241 |
FreeRDP: RDSTLS server authentication bypass: a credential-less Capabilities PDU is accepted at the auth step (fail-open `resultCode`) |
11.08.2026 |
|
| CVE-2026-73242 |
FreeRDP: Kerberos GSS Wrap-token `EC` field is unbounded, causing an out-of-bounds decrypt in `kerberos_DecryptMessage` |
12.08.2026 |
|
| CVE-2024-14042 |
Open5GS Diameter S6a hss-s6a-path.c hss_ogs_diam_s6a_ulr_cb stack-based overflow |
11.08.2026 |
|
| CVE-2026-48804 |
python-socketio: Binary attachment accumulation can cause denial of service |
11.08.2026 |
7.5 |
| CVE-2026-48813 |
Flawfinder output manipulation via untrusted filenames and source text |
12.08.2026 |
|
| CVE-2026-70339 |
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
12.08.2026 |
5.4 |
| CVE-2026-71467 |
Acm-search-v2-api-rhel9: search-v2-api: authentication bypass on /federated via upgrade: websocket header spoofing |
11.08.2026 |
|
| CVE-2026-71468 |
Acm-search-v2-api-rhel9: search-v2-api: cross-user bearer-token reuse via global federation-config cache |
11.08.2026 |
|
| CVE-2026-71474 |
Insights-client-rhel9: insights-client: pull-secret bearer token written to logs on non-200 ccx response |
12.08.2026 |
|
| CVE-2026-71475 |
Insights-client-rhel9: insights-client: spoke-controlled clusterid injected unencoded into insights api url path |
11.08.2026 |
|
| CVE-2026-71845 |
Insights-client: insights-client: ccx_token bearer credential logged in clear text at startup via setdefault() |
12.08.2026 |
|
| CVE-2026-73031 |
telegram-search Stored XSS via v-html in MessageList.vue |
11.08.2026 |
|
| CVE-2026-73032 |
PapersGPT for Zotero 0.6.1 RCE via Unsanitized LLM Response eval() |
11.08.2026 |
|
| CVE-2026-73229 |
Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests |
11.08.2026 |
4.3 |
| CVE-2026-73230 |
Ente: 2of3 cards v1 contain a checksum that enables offline guessing of low-entropy secrets |
11.08.2026 |
|
| CVE-2026-73281 |
|
11.08.2026 |
3.5 |
| CVE-2026-73282 |
|
11.08.2026 |
4.8 |
| CVE-2026-73283 |
|
11.08.2026 |
2.5 |
| CVE-2026-18688 |
Out-of-Bounds Read in MongoDB Aggregation Framework Leads to Denial of Service and Potential Memory Disclosure |
11.08.2026 |
|
| CVE-2026-18690 |
Improper Authorization in MongoDB Server Allows Unauthorized Actions on System Collections |
11.08.2026 |
|
| CVE-2026-18691 |
Improper Authentication in MongoDB Intra-Cluster Connections Allows Credential Exposure |
11.08.2026 |
|
| CVE-2026-18692 |
Use-After-Free in MongoDB Timeseries Bucket Handling Leads to Denial of Service and Potential Remote Code Execution |
11.08.2026 |
|
| CVE-2026-18693 |
Out-of-Bounds Read/Write in MongoDB Timeseries Bucket Handling Leads to Denial of Service and Potential Memory Disclosure |
11.08.2026 |
|
| CVE-2026-18694 |
Out-of-Bounds Read in MongoDB Geospatial Query Processing Leads to Denial of Service and Potential Memory Disclosure |
11.08.2026 |
|
| CVE-2026-18696 |
Improper Authorization in MongoDB applyOps Command Handling Allows Unauthorized DDL Operations on Collections |
11.08.2026 |
|
| CVE-2026-18697 |
Improper Input Validation in MongoDB Aggregation Framework Allows Unauthenticated Denial of Service on mongos |
11.08.2026 |
|
| CVE-2026-18698 |
Improper Authorization in MongoDB Server Allows Unauthorized Actions on System Collections via the validate Command |
11.08.2026 |
|
| CVE-2026-18699 |
Improper Input Validation in MongoDB Query Planner Leads to Denial of Service |
11.08.2026 |
|
| CVE-2026-18700 |
Use-After-Free in MongoDB Geospatial Validation Leads to Denial of Service |
11.08.2026 |
|
| CVE-2026-18701 |
Type Confusion in MongoDB Query Subsystem Leads to Denial of Service |
11.08.2026 |
|
| CVE-2026-18702 |
Improper Authorization in MongoDB profile Command Allows Unauthorized Modification of Server-Wide Diagnostic Settings |
11.08.2026 |
|
| CVE-2026-18704 |
Improper Authorization in MongoDB Aggregation Framework Allows Read-Only User to Perform Unauthorized Write Operations |
11.08.2026 |
|
| CVE-2026-18705 |
Improper Authorization in MongoDB Atlas Vector Search Allows Unauthorized Access to Protected View Data |
11.08.2026 |
|
| CVE-2026-18708 |
Improper Neutralization of Input in MongoDB Server's JavaScript Scripting Engine Leads to Unauthorized Code Execution Within Query Scopes |
11.08.2026 |
|
| CVE-2026-18709 |
Missing Authorization in MongoDB Sharded Transaction Commit/Abort Handling Leads to Cross-Shard Data Inconsistency |
11.08.2026 |
|
| CVE-2026-18711 |
Use-After-Free in MongoDB Query Execution Engine Leads to Denial of Service and Potential Memory Disclosure |
11.08.2026 |
|
| CVE-2026-18712 |
Improper Authorization in MongoDB Queryable Encryption Maintenance Operations Allows Unauthorized Modification of Other Collections |
11.08.2026 |
|
| CVE-2026-69119 |
Taubyte Tau v1.1.10 Missing Authorization via POST /projects/{id} |
11.08.2026 |
|
| CVE-2026-72742 |
DSPy 3.3.0b1 Local File Read via Image/Audio Output Field Parsing |
11.08.2026 |
|
| CVE-2026-73223 |
electerm: Path traversal in editWithSystemEditor temp file path via unsanitized SFTP filename |
11.08.2026 |
8.1 |
| CVE-2026-73224 |
Electerm check folder size function may get attacked by unsafe folder name |
11.08.2026 |
8.8 |
| CVE-2026-73225 |
electerm: Path traversal in FTP/SFTP recursive folder download via unsanitized server filename |
11.08.2026 |
8.1 |
| CVE-2026-73226 |
Electerm WebSocket `upgrade-func` and `fs` handlers allow arbitrary method/function invocation due to missing method-name allowlist |
11.08.2026 |
8.8 |
| CVE-2026-73227 |
electerm's RDP clipboard file download may parse unsafe file name |
11.08.2026 |
8.1 |
| CVE-2026-73228 |
Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data` |
11.08.2026 |
5.3 |
| CVE-2026-15426 |
AcyMailing <= 10.11.1 - Authenticated (Subscriber+) Missing Authorization to Account Takeover via Notification Template Update |
11.08.2026 |
8.8 |
| CVE-2026-18687 |
Improper Validation in MongoDB Queryable Encryption Maintenance Operation Leads to Denial of Service and Index Corruption |
11.08.2026 |
|
| CVE-2026-18695 |
Improper Input Validation in MongoDB Timeseries Query Processing Leads to Denial of Service |
11.08.2026 |
|
| CVE-2026-18703 |
Improper Enforcement of Authentication Mechanism Restrictions in MongoDB Server Allows Use of Disabled Authentication Method |
11.08.2026 |
|
| CVE-2026-18706 |
Use-After-Free in MongoDB $graphLookup Aggregation Stage Leads to Denial of Service and Potential Remote Code Execution |
11.08.2026 |
|
| CVE-2026-18707 |
Improper Input Validation in MongoDB Aggregation Command Handling Leads to Denial of Service |
11.08.2026 |
|
| CVE-2026-48802 |
python-engineio has unbound thread allocation that can cause denial of service |
11.08.2026 |
7.5 |
| CVE-2026-48809 |
python-engineio has possible denial of service due to maximum payload size sometimes not being enforced |
11.08.2026 |
7.5 |
| CVE-2026-69115 |
OpenIM Server v3.8.3 Missing Authorization on User and Group Enumeration Endpoints |
11.08.2026 |
|
| CVE-2026-69117 |
NetBox 4.5.8 ORM Injection via WritableNestedSerializer |
11.08.2026 |
|
| CVE-2026-73221 |
CVAT: Flawed authorization logic in endpoints related to lambda requests |
11.08.2026 |
|
| CVE-2026-73222 |
Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio) |
11.08.2026 |
8.8 |
| CVE-2026-69102 |
MaxKey Hard-coded JWT Secret Unauthorized Access via /login/jwt/trust |
11.08.2026 |
|
| CVE-2026-69113 |
Cap v0.3.1 Broken Access Control via video comment endpoint |
11.08.2026 |
|
| CVE-2026-20712 |
|
12.08.2026 |
|
| CVE-2026-20917 |
|
12.08.2026 |
|
| CVE-2026-27302 |
Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) |
11.08.2026 |
10 |
| CVE-2026-47940 |
Lightroom Classic | Integer Overflow or Wraparound (CWE-190) |
12.08.2026 |
7.8 |
| CVE-2026-48381 |
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) |
11.08.2026 |
9 |
| CVE-2026-48397 |
Lightroom Classic | Deserialization of Untrusted Data (CWE-502) |
12.08.2026 |
8.6 |
| CVE-2026-48404 |
Lightroom Classic | Out-of-bounds Write (CWE-787) |
12.08.2026 |
7.8 |
| CVE-2026-48405 |
Lightroom Classic | Out-of-bounds Write (CWE-787) |
12.08.2026 |
7.8 |
| CVE-2026-48406 |
Lightroom Classic | Out-of-bounds Write (CWE-787) |
12.08.2026 |
7.8 |
| CVE-2026-48407 |
Lightroom Classic | Out-of-bounds Write (CWE-787) |
12.08.2026 |
7.8 |
| CVE-2026-48408 |
Lightroom Classic | Out-of-bounds Write (CWE-787) |
12.08.2026 |
7.8 |
| CVE-2026-48409 |
Lightroom Classic | Out-of-bounds Write (CWE-787) |
12.08.2026 |
7.8 |
| CVE-2026-48410 |
Lightroom Classic | Out-of-bounds Write (CWE-787) |
12.08.2026 |
7.8 |
| CVE-2026-48411 |
Adobe Commerce | Incorrect Authorization (CWE-863) |
11.08.2026 |
6.5 |
| CVE-2026-48412 |
Adobe Commerce | Incorrect Authorization (CWE-863) |
12.08.2026 |
2.7 |
| CVE-2026-48413 |
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) |
11.08.2026 |
8.7 |
| CVE-2026-48414 |
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) |
11.08.2026 |
7.7 |
| CVE-2026-48415 |
Adobe Commerce | Incorrect Authorization (CWE-863) |
11.08.2026 |
7.6 |
| CVE-2026-48416 |
Adobe Commerce | Incorrect Authorization (CWE-863) |
11.08.2026 |
7.5 |
| CVE-2026-48441 |
Lightroom Classic | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) |
12.08.2026 |
8.6 |
| CVE-2026-48447 |
Lightroom Classic | Incorrect Authorization (CWE-863) |
12.08.2026 |
7.7 |
| CVE-2026-65680 |
Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability |
12.08.2026 |
6.7 |
| CVE-2026-71362 |
Adobe Commerce | Incorrect Authorization (CWE-863) |
12.08.2026 |
9.1 |
| CVE-2026-71398 |
Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) |
11.08.2026 |
10 |
| CVE-2026-72712 |
Nmap 7.99 Denial of Service via Zero-Length TCP Option Packet |
11.08.2026 |
|
| CVE-2026-72713 |
XAgent Path Traversal Arbitrary File Read via /workspace/file |
11.08.2026 |
|
| CVE-2026-73213 |
Coturn: `addr_less_eq()` does a component-wise IPv6 comparison instead of a lexicographic one, letting an authenticated TURN client bypass `denied-peer-ip`/`allowed-peer-ip` IPv6 ranges (TURN-specific SSRF) |
11.08.2026 |
|
| CVE-2026-73214 |
coturn allocates a full per-peer SSL/session before verifying the DTLS cookie, enabling source-spoofing/botnet state-exhaustion DoS |
11.08.2026 |
|
| CVE-2026-73215 |
The coturn server can end in a state where it does not accept more requests with "even-port" enabled. |
11.08.2026 |
|
| CVE-2026-73216 |
coturn: mobility disconnects bypass allocation quotas and exhaust relay capacity |
11.08.2026 |
6.5 |
| CVE-2026-73217 |
Cursor: Sandbox escape via tampered Python virtual environments |
11.08.2026 |
|
| CVE-2026-73218 |
Cursor: Sandbox escape via launching privileged containers |
11.08.2026 |
|
| CVE-2026-73219 |
CVAT: Denial of service with regards to automatic annotation |
11.08.2026 |
|
| CVE-2016-20097 |
Weaver E-cology 8.0 SQL Injection File Read via SignatureDownLoad |
11.08.2026 |
|
| CVE-2022-50997 |
Weaver E-cology 8.0 / 9.0 SQL Injection via HrmCareerApplyPerView.jsp |
11.08.2026 |
|
| CVE-2025-0046 |
|
12.08.2026 |
|
| CVE-2025-54512 |
|
12.08.2026 |
|
| CVE-2026-0465 |
|
12.08.2026 |
|
| CVE-2026-20901 |
|
12.08.2026 |
|
| CVE-2026-47705 |
TypeBot vulnerable to CSV injection in result export |
11.08.2026 |
9.6 |
| CVE-2026-48494 |
TypeBot vulnerable to cross-typebot WhatsApp preview webhook resume via global `wa-preview-{phone}` session ids |
11.08.2026 |
|
| CVE-2026-48767 |
Google Sheets OAuth access token disclosure to guest members via getAccessToken |
11.08.2026 |
7.6 |
| CVE-2026-48771 |
ishankportfolio: Stored Contact Form Submission Exposure via Public Client-Side Database Configuration |
11.08.2026 |
8.2 |
| CVE-2026-48790 |
turso-cli persists Turso platform JWT with world-readable (0o644) file permissions |
11.08.2026 |
5.5 |
| CVE-2026-73090 |
PeerTube: Cross-origin remote video takeover via Update activity |
11.08.2026 |
9.3 |
| CVE-2026-73211 |
PeerTube: Unauthenticated remote SQL injection in ActorFollowModel.updateScore() |
11.08.2026 |
9.8 |
| CVE-2026-73212 |
coturn peer-IP ACL canonicalization & scope bypass on the RFC 6062 TCP CONNECT relay path → internal-network SSRF and proven internal root RCE |
11.08.2026 |
|
| CVE-2025-48505 |
|
12.08.2026 |
|
| CVE-2025-48506 |
|
12.08.2026 |
|
| CVE-2025-61970 |
|
12.08.2026 |
|
| CVE-2025-8087 |
|
12.08.2026 |
|
| CVE-2026-12571 |
Authentication Bypass Leading to Account Takeover |
12.08.2026 |
9.8 |
| CVE-2026-20349 |
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability |
12.08.2026 |
8.6 |
| CVE-2026-40375 |
Microsoft Dynamics Business Central Information Disclosure Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-42976 |
Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-47285 |
Visual Studio Code Information Disclosure Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-47299 |
Azure Monitor Agent Elevation of Privilege Vulnerability |
12.08.2026 |
7.2 |
| CVE-2026-47922 |
CAI Content Credentials | Server-Side Request Forgery (SSRF) (CWE-918) |
12.08.2026 |
4.7 |
| CVE-2026-48387 |
CAI Content Credentials | Integer Overflow or Wraparound (CWE-190) |
11.08.2026 |
6.2 |
| CVE-2026-48434 |
CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) |
12.08.2026 |
6.2 |
| CVE-2026-48435 |
CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191) |
11.08.2026 |
6.2 |
| CVE-2026-48436 |
CAI Content Credentials | Improper Input Validation (CWE-20) |
11.08.2026 |
6.5 |
| CVE-2026-48437 |
CAI Content Credentials | Improper Certificate Validation (CWE-295) |
12.08.2026 |
5.5 |
| CVE-2026-48438 |
CAI Content Credentials | NULL Pointer Dereference (CWE-476) |
11.08.2026 |
7.5 |
| CVE-2026-48439 |
CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) |
12.08.2026 |
7.5 |
| CVE-2026-48442 |
CAI Content Credentials | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) |
11.08.2026 |
7.1 |
| CVE-2026-48443 |
CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) |
11.08.2026 |
6.2 |
| CVE-2026-48444 |
CAI Content Credentials | Integer Overflow or Wraparound (CWE-190) |
12.08.2026 |
6.2 |
| CVE-2026-48445 |
CAI Content Credentials | Integer Overflow or Wraparound (CWE-190) |
11.08.2026 |
6.2 |
| CVE-2026-48446 |
CAI Content Credentials | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) |
12.08.2026 |
5.5 |
| CVE-2026-49179 |
Windows Active Directory Domain Services Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-50472 |
Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-50516 |
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability |
12.08.2026 |
9.4 |
| CVE-2026-54113 |
Remote Procedure Call Denial of Service Vulnerability |
12.08.2026 |
7.5 |
| CVE-2026-54123 |
Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-54981 |
Visual Studio Code Python Extension Security Feature Bypass Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-54984 |
Windows Imaging Component Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-56174 |
Windows Narrator Braille Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-56179 |
Windows Network Address Translation (NAT) Spoofing Vulnerability |
12.08.2026 |
8.3 |
| CVE-2026-57104 |
Azure Storage Explorer Elevation of Privilege Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-57105 |
Microsoft Office SharePoint Spoofing Vulnerability |
12.08.2026 |
8 |
| CVE-2026-58612 |
PowerShell Information Disclosure Vulnerability |
12.08.2026 |
7.4 |
| CVE-2026-58639 |
Microsoft SharePoint Server Spoofing Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-58641 |
.NET Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-58650 |
Visual Studio Code Security Feature Bypass Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-58651 |
Microsoft Word Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-59113 |
Visual Studio Code Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-59119 |
PowerShell Elevation of Privilege Vulnerability |
12.08.2026 |
7.3 |
| CVE-2026-59122 |
Windows Telephony Service Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-59124 |
Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability |
12.08.2026 |
9.8 |
| CVE-2026-59125 |
Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability |
12.08.2026 |
7 |
| CVE-2026-59126 |
Windows Event Logging Service Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-59127 |
Windows Installer Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-59128 |
Windows Encrypting File System (EFS) Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-59130 |
AMD Zen Information Disclosure Vulnerability |
12.08.2026 |
5.6 |
| CVE-2026-59131 |
AMD Zen Information Disclosure Vulnerability |
12.08.2026 |
5.6 |
| CVE-2026-59132 |
Windows TCP/IP Denial of Service Vulnerability |
12.08.2026 |
7.5 |
| CVE-2026-59133 |
Microsoft High Performance Computing (HPC) Pack Elevation of Privilege Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-59134 |
Remote Desktop Client Remote Code Execution Vulnerability |
12.08.2026 |
7.5 |
| CVE-2026-59135 |
Microsoft Windows Search Component Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-59136 |
Microsoft COM for Windows Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-59137 |
Windows Event Logging Service Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-59138 |
Microsoft Remote Registry Service Denial of Service Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-61345 |
Microsoft Remote Registry Service Denial of Service Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-61346 |
Windows Graphics Kernel Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-61347 |
Windows Event Logging Service Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-61348 |
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-61349 |
Windows Work Folder Service Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-61350 |
Windows NTFS Information Disclosure Vulnerability |
12.08.2026 |
4.6 |
| CVE-2026-61352 |
Remote Desktop Client Remote Code Execution Vulnerability |
12.08.2026 |
7.5 |
| CVE-2026-61353 |
Windows Telephony Service Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-61355 |
Windows Sensor Data Service Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-61356 |
Windows Remote Desktop Services Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-61357 |
Application Information Services Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-61358 |
Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-61359 |
Windows Storage Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-61360 |
Windows GDI Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-61361 |
Windows DHCP Client Remote Code Execution Vulnerability |
12.08.2026 |
7 |
| CVE-2026-61363 |
Remote Desktop Client Remote Code Execution Vulnerability |
12.08.2026 |
7.5 |
| CVE-2026-61364 |
Windows Remote Desktop Services Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-61365 |
Windows Remote Desktop Services Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-61366 |
Windows Network Connection Broker Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-61367 |
Windows Remote Desktop Services Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-61368 |
Windows Hyper-V Information Disclosure Vulnerability |
12.08.2026 |
5 |
| CVE-2026-61918 |
Windows Remote Desktop Client Information Disclosure Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-61920 |
Windows DNS Server Remote Code Execution Vulnerability |
12.08.2026 |
6.6 |
| CVE-2026-61921 |
Windows Remote Desktop Client Information Disclosure Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-61923 |
Windows Display Enhancement Service Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-61924 |
Windows Remote Desktop Client Information Disclosure Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-61925 |
Windows Installer Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-61926 |
Windows USB Driver Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-61927 |
Windows Bind Filter Driver Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-61928 |
Windows Hello Tampering Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-61929 |
Windows Kernel Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-61930 |
Windows Kernel Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-61932 |
Windows DWM Core Library Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-61933 |
Windows DWM Core Library Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-61934 |
Windows Bind Filter Driver Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-61936 |
Windows Defender Firewall Service Security Feature Bypass Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-61937 |
Windows HTTP.sys Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-61938 |
Windows Installer Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-61939 |
Winlogon Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62688 |
Windows MIDI Service Module Elevation of Privileges Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62690 |
Windows Push Notifications Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62692 |
Windows Remote Desktop Services Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62693 |
Windows MIDI Service Module Elevation of Privileges Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62695 |
Windows Storage Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62696 |
Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62698 |
Microsoft Digest Authentication Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62699 |
Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability |
12.08.2026 |
6.8 |
| CVE-2026-62700 |
Windows NTFS Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62701 |
Windows Telephony Service Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62702 |
Windows Graphics Kernel Denial of Service Vulnerability |
12.08.2026 |
6.8 |
| CVE-2026-62703 |
Windows DWM Core Library Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-62705 |
Windows Bind Filter Driver Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62707 |
Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62708 |
Windows Kernel Elevation of Privilege Vulnerability |
12.08.2026 |
6.4 |
| CVE-2026-62709 |
Windows GDI+ Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-62710 |
Windows Device Association Service Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62711 |
Windows Win32k Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62712 |
Windows Win32k Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62713 |
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62714 |
Windows DHCP Server Information Disclosure Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-62715 |
Windows DHCP Server Information Disclosure Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-62716 |
Windows DHCP Server Information Disclosure Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-62717 |
Windows Message Queuing Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62718 |
Windows DHCP Server Information Disclosure Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-62719 |
Windows Message Queuing Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62720 |
Windows DHCP Server Information Disclosure Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-62721 |
Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62722 |
Windows Bind Filter Driver Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62723 |
Windows Telephony Service Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62724 |
Windows Telephony Service Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62725 |
Windows Telephony Service Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62726 |
Windows Telephony Service Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62728 |
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62729 |
Windows Telephony Service Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62730 |
Windows Wired AutoConfig Service Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-62732 |
Windows Telephony Service Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62733 |
Windows Win32k Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62734 |
Windows Telephony Service Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62735 |
Windows HTTP.sys Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62736 |
Windows DHCP Client Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62737 |
Windows Kernel Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62738 |
Windows Management Instrumentation Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-62739 |
Windows HTTP.sys Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62740 |
Windows Imaging Component Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-62741 |
Windows HTTP.sys Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62742 |
Windows DHCP Server Information Disclosure Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-62743 |
Win32k Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-62745 |
Windows DHCP Server Information Disclosure Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-62746 |
Win32k Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-62747 |
Windows Device Association Service Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62748 |
Windows Telephony Service Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62749 |
Windows Kernel Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62750 |
Windows HTTP Protocol Stack Tampering Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-62751 |
Windows Projected File System Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62752 |
Windows Kerberos Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62753 |
Windows HTTP.sys Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62754 |
Windows Kerberos Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62755 |
Windows DHCP Client Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62757 |
Windows Schannel Security Feature Bypass Vulnerability |
12.08.2026 |
5.3 |
| CVE-2026-62758 |
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62761 |
Windows DHCP Server Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62766 |
Windows Kerberos Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62768 |
Windows Installer Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62769 |
Windows DNS Elevation of Privilege Vulnerability |
12.08.2026 |
6.7 |
| CVE-2026-62770 |
Windows Shell Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62771 |
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62772 |
Windows Container Isolation FS Filter Driver (unionfs.sys) Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62773 |
Windows Kerberos Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62774 |
Windows Graphics Kernel Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62775 |
Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-62776 |
Windows DHCP Server Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62777 |
Windows License Manager Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62778 |
Windows DNS Elevation of Privilege Vulnerability |
12.08.2026 |
8.1 |
| CVE-2026-62779 |
Windows Schannel Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62780 |
Windows Kernel Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62781 |
RPC Runtime Library Remote Code Execution Vulnerability |
12.08.2026 |
8.1 |
| CVE-2026-62782 |
Windows SMB Client Information Disclosure Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-62783 |
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62784 |
Microsoft Local Security Authority Server (lsasrv) Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-62785 |
Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-62786 |
Win32k Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-62787 |
Windows DNS Server Remote Code Execution Vulnerability |
12.08.2026 |
7.5 |
| CVE-2026-62788 |
Windows Kernel Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62790 |
Windows SMBv3 Server Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-62792 |
Windows TCP/IP Remote Code Execution Vulnerability |
12.08.2026 |
8.1 |
| CVE-2026-62793 |
Windows NTFS Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-62795 |
Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-62796 |
Windows NTFS Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-62797 |
Windows NTFS Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62798 |
Win32k Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-62799 |
Windows SMB Client Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62800 |
Windows SMBv3 Server Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-62803 |
Windows DHCP Server Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62807 |
Windows DHCP Server Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62811 |
Windows HTTP.sys Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62812 |
Windows DHCP Server Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62814 |
Windows DHCP Server Information Disclosure Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-62815 |
Microsoft QUIC Remote Code Execution Vulnerability |
12.08.2026 |
9.8 |
| CVE-2026-62816 |
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-62817 |
Windows DNS Server Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-62818 |
Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-62819 |
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
12.08.2026 |
8.1 |
| CVE-2026-62820 |
Windows DNS Server Remote Code Execution Vulnerability |
12.08.2026 |
8.1 |
| CVE-2026-62822 |
Windows GDI+ Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-62823 |
Windows DHCP Server Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-62824 |
Remote Desktop Client Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-62827 |
Microsoft SharePoint Server Elevation of Privilege Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-62829 |
Microsoft SharePoint Server Spoofing Vulnerability |
12.08.2026 |
4.6 |
| CVE-2026-62832 |
Windows User Profile Service Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62837 |
Microsoft SharePoint Server Information Disclosure Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-62839 |
Microsoft SharePoint Server Spoofing Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-62842 |
Microsoft Office Graphics Component Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-62869 |
Azure Entra ID Spoofing Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-62871 |
.NET Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62872 |
.NET Framework Elevation of Privilege Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-62876 |
Windows Win32k Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62877 |
Windows Win32k Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62878 |
Windows DNS Server Remote Code Execution Vulnerability |
12.08.2026 |
9.8 |
| CVE-2026-62880 |
Windows NTFS Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62881 |
Windows DNS Elevation of Privilege Vulnerability |
12.08.2026 |
6.7 |
| CVE-2026-62882 |
Microsoft Outlook Spoofing Vulnerability |
12.08.2026 |
4.3 |
| CVE-2026-62883 |
Windows DNS Elevation of Privilege Vulnerability |
12.08.2026 |
6.7 |
| CVE-2026-62885 |
Windows Win32k Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62886 |
.NET Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62887 |
Windows NTFS Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-62888 |
Windows DWM Core Library Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62889 |
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability |
12.08.2026 |
8.1 |
| CVE-2026-62890 |
Windows GDI+ Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62892 |
Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62893 |
Windows Deployment Services TFTP Server Remote Code Execution Vulnerability |
12.08.2026 |
9.8 |
| CVE-2026-62894 |
Windows DWM Core Library Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62897 |
.NET Framework Remote Code Execution Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62898 |
Microsoft QUIC Information Disclosure Vulnerability |
12.08.2026 |
7.5 |
| CVE-2026-62899 |
.NET Security Feature Bypass Vulnerability |
12.08.2026 |
5.9 |
| CVE-2026-62900 |
.NET Information Disclosure Vulnerability |
12.08.2026 |
5.9 |
| CVE-2026-62901 |
.NET Denial of Service Vulnerability |
12.08.2026 |
7.5 |
| CVE-2026-62902 |
.NET Information Disclosure Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-62908 |
Windows Backup Engine Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62909 |
.NET Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62910 |
Microsoft Exchange Server Elevation of Privilege Vulnerability |
12.08.2026 |
7.2 |
| CVE-2026-62911 |
Microsoft Exchange Server Elevation of Privilege Vulnerability |
12.08.2026 |
8 |
| CVE-2026-62912 |
Microsoft Exchange Server Denial of Service Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-62913 |
Microsoft Exchange Server Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-62914 |
Microsoft Exchange Server Spoofing Vulnerability |
12.08.2026 |
7.3 |
| CVE-2026-62915 |
Microsoft Exchange Server Security Feature Bypass Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-62917 |
Microsoft SharePoint Server Spoofing Vulnerability |
12.08.2026 |
4.6 |
| CVE-2026-63512 |
Microsoft SharePoint Server Tampering Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-63513 |
Microsoft Office Graphics Component Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-63514 |
Microsoft SharePoint Server Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-63515 |
Microsoft Office Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-63516 |
Microsoft SharePoint Server Spoofing Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-63517 |
Microsoft Office Graphics Component Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-63518 |
Microsoft Office Word Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-63519 |
Microsoft Office Graphics Component Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-63520 |
Microsoft SharePoint Server Remote Code Execution Vulnerability |
12.08.2026 |
8.1 |
| CVE-2026-63521 |
Microsoft Office Word Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-63522 |
Azure SQL Database Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-63524 |
Microsoft Office Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-63525 |
Microsoft Office Word Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-63526 |
Microsoft Office Graphics Component Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-63527 |
Microsoft Office Word Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-63528 |
Microsoft Office Word Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-63529 |
Microsoft Office Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-63530 |
Microsoft Office Word Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-63531 |
Microsoft Office Word Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-63532 |
Microsoft Office Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-63533 |
Microsoft Office Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-64897 |
Microsoft SharePoint Server Spoofing Vulnerability |
12.08.2026 |
4.6 |
| CVE-2026-64898 |
Microsoft Office Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-64899 |
Microsoft Office Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-64900 |
Microsoft SharePoint Server Spoofing Vulnerability |
12.08.2026 |
7.3 |
| CVE-2026-64901 |
Microsoft SharePoint Server Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-64902 |
Microsoft SharePoint Server Spoofing Vulnerability |
12.08.2026 |
4.6 |
| CVE-2026-64903 |
Microsoft Office Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-64904 |
Microsoft Office Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-64905 |
Microsoft Office Word Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-64906 |
Microsoft Access Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-64907 |
Microsoft Office Word Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-64908 |
Microsoft Access Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-64909 |
Microsoft Office Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-64910 |
Microsoft Office Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-64911 |
Microsoft Office Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-64912 |
Microsoft Access Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-64914 |
Microsoft Access Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-64915 |
Microsoft Office Word Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-64916 |
Microsoft SharePoint Server Spoofing Vulnerability |
12.08.2026 |
4.6 |
| CVE-2026-64917 |
Microsoft Office Word Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-64919 |
Microsoft Access Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-64920 |
Microsoft Access Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-64921 |
Microsoft SharePoint Server Elevation of Privilege Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-64922 |
Microsoft SharePoint Server Spoofing Vulnerability |
12.08.2026 |
4.6 |
| CVE-2026-65656 |
Microsoft Office Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-65657 |
Microsoft Office Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-65658 |
Microsoft SharePoint Server Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-65660 |
Microsoft SharePoint Server Spoofing Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-65661 |
Microsoft Office Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-65662 |
Windows GDI Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-65663 |
Microsoft SharePoint Server Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-65664 |
Microsoft Office Graphics Component Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-65665 |
Microsoft SharePoint Server Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-65671 |
Remote Access API Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-65672 |
Remote Access API Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-65673 |
Microsoft Entra Connect Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-65675 |
CoPilot Chat Security Feature Bypass Vulnerability |
12.08.2026 |
7.1 |
| CVE-2026-65678 |
Windows Win32k Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-65679 |
Windows iSCSI Target Service Remote Code Execution Vulnerability |
12.08.2026 |
8.1 |
| CVE-2026-65681 |
Windows iSCSI Target Service Denial of Service Vulnerability |
12.08.2026 |
7.5 |
| CVE-2026-65767 |
Microsoft Teams for Android and iOS Spoofing Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-65768 |
Microsoft Teams Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-65769 |
Microsoft Teams iOS Information Disclosure Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-65773 |
Windows Kernel Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-65774 |
Windows Installer Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-65775 |
Windows Win32k Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-65776 |
Windows Win32k Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-65777 |
Active Directory Security Feature Bypass Vulnerability |
12.08.2026 |
5.3 |
| CVE-2026-65778 |
Windows Autopilot Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-65779 |
Windows Autopilot Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-65780 |
Windows Autopilot Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-65781 |
Windows Autopilot Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-65782 |
Windows Autopilot Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-65783 |
Windows Autopilot Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-65784 |
Windows NTFS Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-65785 |
Windows DHCP Client Denial of Service Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-65786 |
Desktop Window Manager Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-65787 |
Desktop Window Manager Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-65788 |
Desktop Window Manager Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-65789 |
Windows DNS Server Remote Code Execution Vulnerability |
12.08.2026 |
8.1 |
| CVE-2026-65790 |
Windows Message Queuing Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-65791 |
Windows iSCSI Target Service Remote Code Execution Vulnerability |
12.08.2026 |
9.8 |
| CVE-2026-65794 |
Windows SMB Client Information Disclosure Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-65795 |
Windows DNS Elevation of Privilege Vulnerability |
12.08.2026 |
6.7 |
| CVE-2026-65796 |
Windows iSCSI Target Service Denial of Service Vulnerability |
12.08.2026 |
5.9 |
| CVE-2026-65797 |
Windows DNS Elevation of Privilege Vulnerability |
12.08.2026 |
6.7 |
| CVE-2026-65798 |
Windows DNS Elevation of Privilege Vulnerability |
12.08.2026 |
6.7 |
| CVE-2026-65799 |
Windows DNS Elevation of Privilege Vulnerability |
12.08.2026 |
6.7 |
| CVE-2026-65806 |
Azure CycleCloud Information Disclosure Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-65807 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-65810 |
.NET Framework Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-65811 |
Power BI Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-65813 |
Microsoft Exchange Server Elevation of Privilege Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-65814 |
Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-65815 |
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-66301 |
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-66799 |
Windows Key Guard Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-66802 |
Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability |
12.08.2026 |
8.1 |
| CVE-2026-66804 |
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-66805 |
Microsoft SharePoint Server Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-66806 |
Microsoft Office Word Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-66807 |
Microsoft Office Graphics Component Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-66808 |
Microsoft SharePoint Server Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-66809 |
Microsoft Office Graphics Component Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-66810 |
Microsoft Office Word Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-68792 |
Microsoft Office Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68793 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68794 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68795 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68796 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68797 |
Microsoft Excel Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-68798 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68799 |
Microsoft Excel Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-68800 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68801 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68802 |
Microsoft Excel Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-68803 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68804 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68805 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68806 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68807 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68808 |
Microsoft Excel Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-68809 |
Powerpoint Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-68810 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68811 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68812 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68813 |
Microsoft Excel Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-68814 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68815 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68816 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68817 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68819 |
Windows Network File System Denial of Service Vulnerability |
12.08.2026 |
5.9 |
| CVE-2026-68820 |
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-68821 |
Windows Package Manager Elevation of Privilege Vulnerability |
12.08.2026 |
7.3 |
| CVE-2026-69223 |
Apache Allura: Server-side request forgery |
11.08.2026 |
|
| CVE-2026-69278 |
Visual Studio Code Security Feature Bypass Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-69306 |
Visual Studio Code Security Feature Bypass Vulnerability |
12.08.2026 |
8.2 |
| CVE-2026-69320 |
Visual Studio Code Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-70130 |
Microsoft Office Remote Code Execution Vulnerability |
12.08.2026 |
8.4 |
| CVE-2026-70304 |
Windows DNS Elevation of Privilege Vulnerability |
12.08.2026 |
6.7 |
| CVE-2026-70306 |
Microsoft Office SharePoint Spoofing Vulnerability |
12.08.2026 |
9.3 |
| CVE-2026-70307 |
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-70310 |
Microsoft Word Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-70311 |
Microsoft Office Word Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-70312 |
Powerpoint Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-70313 |
Microsoft PowerPoint Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-70314 |
Microsoft Office Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-70315 |
Microsoft Office Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-70316 |
Powerpoint Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-70317 |
Microsoft Office Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-70318 |
Microsoft Excel Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-70319 |
Microsoft Office Word Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-70320 |
Powerpoint Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-70321 |
Microsoft SharePoint Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-70322 |
Powerpoint Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-70323 |
Microsoft Office Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-70324 |
Microsoft SharePoint Elevation of Privilege Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-70325 |
Powerpoint Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-70326 |
Microsoft SharePoint Server Elevation of Privilege Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-70327 |
Microsoft Excel Information Disclosure Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-70328 |
Microsoft Excel Information Disclosure Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-70329 |
Microsoft Outlook Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-70330 |
Windows DNS Elevation of Privilege Vulnerability |
12.08.2026 |
6.7 |
| CVE-2026-70335 |
GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-70336 |
Visual Studio Code Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-70337 |
Microsoft PowerShell Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-70338 |
Microsoft PowerShell Security Feature Bypass Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-70340 |
Azure CycleCloud Elevation of Privilege Vulnerability |
12.08.2026 |
8.1 |
| CVE-2026-70344 |
Windows Installer Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-70345 |
Windows Installer Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-70346 |
Windows Installer Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-70347 |
Windows Installer Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-70348 |
Windows Management Services Denial of Service Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-70354 |
.NET Core Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-70355 |
Microsoft SharePoint Server Elevation of Privilege Vulnerability |
12.08.2026 |
7.3 |
| CVE-2026-71331 |
Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability |
12.08.2026 |
8.1 |
| CVE-2026-71389 |
CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191) |
11.08.2026 |
6.2 |
| CVE-2026-71390 |
CAI Content Credentials | Improper Input Validation (CWE-20) |
11.08.2026 |
4 |
| CVE-2026-72971 |
Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-73087 |
Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher |
11.08.2026 |
|
| CVE-2026-73088 |
Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats) |
11.08.2026 |
7.5 |
| CVE-2026-73089 |
Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM |
11.08.2026 |
7.5 |