| CVE-2026-19426 |
FitSoft|POS Sytstem - Missing Authentication |
12.08.2026 |
8.2 |
| CVE-2026-12976 |
LearnPress < 4.4.4 - Subscriber+ Sensitive Information Exposure via AI Assistant |
12.08.2026 |
|
| CVE-2026-13168 |
Eventin < 4.1.20 - Contributor+ Customer PII Disclosure via REST API |
12.08.2026 |
|
| CVE-2026-13171 |
Eventin < 4.1.20 - Unauthenticated Account Creation via Waiting List Endpoint |
12.08.2026 |
|
| CVE-2026-13177 |
Eventin < 4.1.20 - Contributor+ Order Information Disclosure via IDOR |
12.08.2026 |
|
| CVE-2026-13612 |
KiviCare < 4.5.2 - Patient+ Cross-Patient Bill, Invoice and Appointment Disclosure via IDOR |
12.08.2026 |
|
| CVE-2026-13613 |
KiviCare < 4.5.2 - Doctor/Receptionist+ SQL Injection via settings/listing REST Endpoint |
12.08.2026 |
|
| CVE-2026-14857 |
WP Crowdfunding < 2.2.1 - Subscriber+ Campaign Update Modification via IDOR |
12.08.2026 |
|
| CVE-2026-14858 |
WP Crowdfunding < 2.2.1 - Subscriber+ Order Data Disclosure via IDOR |
12.08.2026 |
|
| CVE-2026-14859 |
WP Crowdfunding < 2.2.1 - Subscriber+ Campaign Creation via Missing Authorization |
12.08.2026 |
|
| CVE-2026-14925 |
Import WP < 2.14.23 - Unauthenticated Sensitive Information Exposure via Export File Download |
12.08.2026 |
|
| CVE-2026-15039 |
Gift Cards For WooCommerce Pro < 4.2.10 - Unauthenticated Arbitrary File Upload |
12.08.2026 |
|
| CVE-2026-15249 |
Patterns Kit <= 1.0.3 - Contributor+ Stored XSS via YouTube Popup Link |
12.08.2026 |
|
| CVE-2026-15388 |
Cookie Consent < 0.0.10 - Subscriber+ Consent Settings Update and Consent Log Disclosure |
12.08.2026 |
|
| CVE-2026-16051 |
WPMU DEV Dashboard < 5.0.1 - Remote Code Execution via Hub Install Action |
12.08.2026 |
|
| CVE-2026-16066 |
Welcart e-Commerce < 2.11.34 - Author+ Stored XSS via Product Name |
12.08.2026 |
|
| CVE-2026-16253 |
Total Upkeep (BoldGrid Backup) < 1.17.3 - Unauthenticated Sensitive Data Disclosure and Forced Site Restore via Predictable cron_secret (regression of CVE-2020-36848) |
12.08.2026 |
|
| CVE-2026-16294 |
Blubrry PowerPress < 11.17.1 - Contributor+ Server-Side Request Forgery via Podcast Episode Chapters URL |
12.08.2026 |
|
| CVE-2026-16538 |
TeraWallet - Wallet for WooCommerce < 1.6.10 - Subscriber+ Wallet Balance Inflation via Discounted Top-Up |
12.08.2026 |
|
| CVE-2026-16737 |
WP Travel Engine < 6.8.5 - Unauthenticated Booking Details Disclosure and Modification via wte_add_trip_to_cart |
12.08.2026 |
|
| CVE-2026-16977 |
Form Maker by 10Web < 1.15.45 - Subscriber+ SQL Injection via display_name |
12.08.2026 |
|
| CVE-2026-17013 |
WP Photo Album Plus < 9.2.07.002 - Reflected XSS via lbstart |
12.08.2026 |
|
| CVE-2026-18035 |
User Access Manager < 2.3.15 - Unauthenticated Restricted Content Disclosure via REST API |
12.08.2026 |
|
| CVE-2026-18046 |
Cookie Consent < 0.0.10 - Subscriber+ MaxMind License Key Update |
12.08.2026 |
|
| CVE-2026-18048 |
WP Photo Album Plus < 9.2.07.002 - Unauthenticated Arbitrary ZIP File Deletion via delmyzip Path Traversal |
12.08.2026 |
|
| CVE-2026-18049 |
WP Photo Album Plus < 9.2.07.002 - Unauthenticated Option Disclosure via gettogo |
12.08.2026 |
|
| CVE-2026-18057 |
Events Manager < 7.4.1 - Subscriber+ Booking Consent Record Tampering via SQL Injection |
12.08.2026 |
|
| CVE-2026-18230 |
WP Directory Kit < 1.5.6 - Subscriber+ SQL Injection via section Parameter |
12.08.2026 |
|
| CVE-2026-18366 |
Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator |
12.08.2026 |
|
| CVE-2026-18391 |
WooCommerce Subscriptions < 9.1.0 - Unauthenticated RCE via PHP Object Injection |
12.08.2026 |
|
| CVE-2026-18474 |
WP Directory Kit < 1.5.6 - Unauthenticated SQL Injection via search_location and search_category |
12.08.2026 |
|
| CVE-2026-18789 |
Ezoic < 2.23.1 - Unauthenticated Database Export via Content Export REST Routes |
12.08.2026 |
|
| CVE-2026-18943 |
WPC Admin Columns < 2.3.4 - Subscriber+ Arbitrary User/Post/Term Meta Disclosure |
12.08.2026 |
|
| CVE-2026-18962 |
WP Photo Album Plus < 9.2.09.002 - Subscriber+ Cross-Album File Upload via Missing Authorization |
12.08.2026 |
|
| CVE-2026-19050 |
ProSolution WP Client < 2.0.9 - Subscriber+ SSRF via proSol_url_validate |
12.08.2026 |
|
| CVE-2026-19052 |
ProSolution WP Client < 2.0.9 - Subscriber+ proSol_ajaxTablesync and proSol_ajaxClearlog Calls |
12.08.2026 |
|
| CVE-2026-19073 |
Order Sync with Zendesk for WooCommerce < 2.2.3 - Unauthenticated Customer Order Data Disclosure |
12.08.2026 |
|
| CVE-2026-19217 |
Royal Elementor Addons < 1.7.1065 - Contributor+ Stored XSS via Icon Box Widget |
12.08.2026 |
|
| CVE-2026-66659 |
WordPress Tablesome Table plugin <= 1.2.9 - SQL Injection vulnerability |
12.08.2026 |
9.3 |
| CVE-2026-19594 |
Path Traversal and HTTP Parameter Pollution in Snowflake Python API (snowflake.core) Allow Confused-Deputy Privilege Escalation |
12.08.2026 |
8.1 |
| CVE-2026-12234 |
TOCTOU double-fetch in `zsock_sendmsg`/`recvmsg` userspace verifiers allows kernel-heap out-of-bounds write |
12.08.2026 |
7.8 |
| CVE-2026-12235 |
Out-of-bounds write in Xtensa llext PLT relocation from malformed ELF (CWE-787) |
12.08.2026 |
6.3 |
| CVE-2026-64954 |
Velociraptor collect_client() Permissions Bypass |
12.08.2026 |
8.2 |
| CVE-2026-12232 |
Out-of-bounds read via unvalidated stream_id in Intel ALH DAI get_properties |
12.08.2026 |
6.1 |
| CVE-2026-12233 |
Uninitialized mutex in TLS trusted-credential backend causes kernel NULL-deref DoS under contention |
12.08.2026 |
5.9 |
| CVE-2025-15687 |
Open5GS SMF Diameter Gx Credit-Control-Answer smf_gx_cca_cb denial of service |
12.08.2026 |
|
| CVE-2025-15684 |
Open5GS CER init.c diam_log_func assertion |
12.08.2026 |
|
| CVE-2025-15685 |
Open5GS freeDiameter memory corruption |
12.08.2026 |
|
| CVE-2025-15686 |
Open5GS HSS Service fd_msg_sess_get denial of service |
12.08.2026 |
|
| CVE-2026-18961 |
Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect <= 1.4.3 - Unauthenticated Authentication Bypass via Spotify OAuth Callback |
12.08.2026 |
8.1 |
| CVE-2026-19587 |
|
12.08.2026 |
6.5 |
| CVE-2026-19588 |
|
12.08.2026 |
6.5 |
| CVE-2026-9318 |
tablib versions prior to 3.10.0 Stored XSS via HTML Export Dataset Title |
12.08.2026 |
|
| CVE-2026-64927 |
Multicloud-operators-channel: multicloud-operators-channel: cross-namespace secret and configmap mutation via spec.secretref.namespace confused deputy |
12.08.2026 |
|
| CVE-2026-66878 |
Multicloud-operators-subscription: multicloud-operators-subscription: fetchchannelreferences honours channel.spec.secretref.namespace enabling cross-namespace secret exfiltration |
12.08.2026 |
|
| CVE-2026-70398 |
Multicloud-integrations: multicloud-integrations: gitopscluster.spec.argoserver.argonamespace writes spoke bearer tokens to attacker-chosen namespace |
12.08.2026 |
|
| CVE-2026-72526 |
Multicloud-integrations: multicloud-integrations: pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-cluster annotation |
12.08.2026 |
|
| CVE-2026-73122 |
Multicloud-operators-channel: multicloud-operators-channel: auto-generated role grants every managed-cluster agent secrets:get,list,watch in channel namespaces |
12.08.2026 |
|
| CVE-2024-14044 |
Open5GS Diameter Rx pcrf-rx-path.c pcrf_rx_aar_cb buffer overflow |
12.08.2026 |
|
| CVE-2026-68447 |
drm/amdkfd: clamp v9 CRIU control stack checkpoint copy to BO size |
12.08.2026 |
|
| CVE-2026-68448 |
ovl: check access to copy_file_range source with src mounter creds |
12.08.2026 |
|
| CVE-2026-68449 |
ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning |
12.08.2026 |
|
| CVE-2026-68450 |
btrfs: free mapping node on duplicate reloc root insert |
12.08.2026 |
|
| CVE-2026-6484 |
Lack of verified boot to certain FV may cause arbitrary code execution |
12.08.2026 |
8.2 |
| CVE-2026-68429 |
drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe() |
12.08.2026 |
|
| CVE-2026-68430 |
drm/amdgpu/gfx8: drop unecessary BUG_ON() |
12.08.2026 |
|
| CVE-2026-68431 |
ksmbd: validate minimum PDU size for transform requests |
12.08.2026 |
|
| CVE-2026-68432 |
vxlan: require CAP_NET_ADMIN in the device netns for changelink |
12.08.2026 |
|
| CVE-2026-68433 |
libceph: bound get_version reply decode to front len |
12.08.2026 |
|
| CVE-2026-68434 |
serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms |
12.08.2026 |
|
| CVE-2026-68435 |
LoongArch: Fix address space mismatch in kexec command line lookup |
12.08.2026 |
|
| CVE-2026-68436 |
drm/amd/display: use kvzalloc to allocate struct dc |
12.08.2026 |
|
| CVE-2026-68437 |
drm/imagination: Fit paired fragment job in the correct CCCB |
12.08.2026 |
|
| CVE-2026-68438 |
smp: Make CSD lock acquisition atomic for debug mode |
12.08.2026 |
|
| CVE-2026-68439 |
wifi: mt76: mt7925: fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv() |
12.08.2026 |
|
| CVE-2026-68440 |
net: txgbe: fix heap overflow when reading module EEPROM |
12.08.2026 |
|
| CVE-2026-68441 |
net/sched: Handle TC_ACT_REDIRECT from qdisc filter chains |
12.08.2026 |
|
| CVE-2026-68442 |
btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps |
12.08.2026 |
|
| CVE-2026-68443 |
hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop |
12.08.2026 |
|
| CVE-2026-68444 |
firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get() |
12.08.2026 |
|
| CVE-2026-68445 |
drm/vc4: Prevent shader BO mappings from becoming writable |
12.08.2026 |
|
| CVE-2026-68446 |
drm/vmwgfx: Validate vmw_surface_metadata::array_size |
12.08.2026 |
|
| CVE-2024-14043 |
Open5GS Diameter S6a mme-fd-path.c mme_s6a_subscription_data_from_avp heap-based overflow |
11.08.2026 |
|
| CVE-2026-73250 |
Notepad++: Install-time PowerShell command injection through installation path |
11.08.2026 |
|
| CVE-2026-18710 |
Cleartext Storage of Sensitive Information in MongoDB Driver Logging During Client Initialization |
11.08.2026 |
|
| CVE-2026-73246 |
Kestra: Unauthenticated management `/worker` endpoint exposes live task configuration and plaintext credentials |
11.08.2026 |
7.5 |
| CVE-2026-73247 |
Kestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata |
11.08.2026 |
8.6 |
| CVE-2026-73248 |
calibre: Bypass of Python template restrictions via nested `template()` leading to RCE |
11.08.2026 |
|
| CVE-2026-73249 |
calibre Content Server `/book-update-annotations` Missing Write Authorization Check Allows Unauthorized Annotation Modification |
11.08.2026 |
7.5 |
| CVE-2026-29036 |
cJSON 1.7.19 Wrong-Key Modification via JSON Pointer Escape Decoding |
11.08.2026 |
|
| CVE-2026-5917 |
libgit2 v0.27.0-v1.9.0 Shell Command Injection via ssh_libssh2 Backend |
11.08.2026 |
|
| CVE-2026-66098 |
Mira Hormone Monitor, Mira Android App Missing authentication for critical function |
11.08.2026 |
|
| CVE-2026-66875 |
Mira Hormone Monitor, Mira Android App Missing authentication for critical function |
11.08.2026 |
|
| CVE-2026-67558 |
Mira Hormone Monitor, Mira Android App Authentication bypass by spoofing |
11.08.2026 |
|
| CVE-2026-67568 |
Mira Hormone Monitor, Mira Android App Use of Hard-coded Credentials |
11.08.2026 |
|
| CVE-2026-73245 |
Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-auth |
11.08.2026 |
6.5 |
| CVE-2026-19556 |
|
11.08.2026 |
|
| CVE-2026-19557 |
|
11.08.2026 |
|
| CVE-2026-19558 |
|
11.08.2026 |
|
| CVE-2026-19559 |
|
11.08.2026 |
|
| CVE-2026-19560 |
|
11.08.2026 |
|
| CVE-2026-64934 |
Mira Hormone Monitor, Mira Android App Reliance on untrusted inputs in a security decision |
11.08.2026 |
|
| CVE-2026-66340 |
Mira Hormone Monitor, Mira Android App Improper restriction of excessive authentication attempts |
11.08.2026 |
|
| CVE-2026-68067 |
Mira Hormone Monitor, Mira Android App Weak Authentication |
11.08.2026 |
|
| CVE-2026-19550 |
Freeipa: ipa: freeipa: trust-fetch-domains uses trust-read aci to gate a privileged ad trust refresh, allowing unauthorized ldap writes |
11.08.2026 |
|
| CVE-2026-48763 |
TypeBot has Arbitrary S3 Object Write in deprecated public upload endpoint via attacker-controlled filePath |
11.08.2026 |
8.2 |
| CVE-2026-66832 |
Mira Hormone Monitor, Mira Android App Use of GET request method with sensitive query strings |
11.08.2026 |
|
| CVE-2026-14863 |
FileRun 2026.2.0 RCE via Thumbnail Generation Command Injection |
11.08.2026 |
|
| CVE-2026-15606 |
Frontend Admin by DynamiApps <= 3.29.9 - Authenticated (Subscriber+) Arbitrary Password Reset via Encrypted Object Token |
11.08.2026 |
8.8 |
| CVE-2026-48762 |
TypeBot Vulnerable to Server-Side Request Forgery (SSRF) in OpenAI Transcription Handler |
11.08.2026 |
5.4 |
| CVE-2026-48765 |
TypeBot vulnerable to cross-workspace OAuth credential takeover in updateOAuthCredentials via missing object binding |
11.08.2026 |
9.9 |
| CVE-2026-63133 |
Malcolm has Uncontrolled Resource Consumption in Archive Extraction (Inode-Exhaustion DoS) |
11.08.2026 |
6.5 |
| CVE-2026-63134 |
Malcolm's Path Traversal in Archive Extraction Allows Arbitrary Directory Creation |
11.08.2026 |
5.4 |
| CVE-2026-63177 |
Malcolm Vulnerable to Authorization Bypass via URI Normalization Differential in Nginx Lua RBAC |
11.08.2026 |
7.1 |
| CVE-2026-71290 |
Apache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM) |
11.08.2026 |
|
| CVE-2026-18634 |
|
12.08.2026 |
|
| CVE-2026-19579 |
Snipe-IT Checkout Request Cancellation IDOR |
11.08.2026 |
|
| CVE-2026-29035 |
CivetWeb Heap/Stack Buffer Overflow via WebSocket permessage-deflate Decompression |
11.08.2026 |
|
| CVE-2026-55676 |
Malcolm vulnerable to RCE via unrestricted .php upload to the file-upload component |
11.08.2026 |
8.8 |
| CVE-2026-66147 |
|
12.08.2026 |
|
| CVE-2026-66148 |
|
11.08.2026 |
|
| CVE-2026-66149 |
|
12.08.2026 |
|
| CVE-2026-66150 |
|
12.08.2026 |
|
| CVE-2026-66154 |
|
12.08.2026 |
|
| CVE-2026-18844 |
Pulsetto Vagus Nerve Stimulator Hidden Functionality |
11.08.2026 |
|
| CVE-2026-66145 |
|
12.08.2026 |
|
| CVE-2026-66146 |
|
11.08.2026 |
|
| CVE-2026-73243 |
kkFileView: Unauthenticated SSRF via /addTask with fullfilename type-confusion bypass |
11.08.2026 |
5.8 |
| CVE-2026-73244 |
kkFileView: Unauthenticated path traversal in POST /listFiles allows arbitrary directory listing |
11.08.2026 |
5.3 |
| CVE-2026-13457 |
InstaWP Connect <= 0.1.3.6 - Unauthenticated Cryptographic Key Disclosure |
11.08.2026 |
7.5 |
| CVE-2026-16230 |
Formidable Digital Signatures <= 3.0.6 - Unauthenticated Arbitrary File Deletion via Signature Field |
11.08.2026 |
9.8 |
| CVE-2026-19091 |
GeoDirectory <= 2.8.169 - Authenticated (Subscriber+) Arbitrary File Deletion via 'post_type' Parameter via Query-String Bypass in geodir_save_post + geodir_delete_revision |
11.08.2026 |
8.1 |
| CVE-2026-45618 |
LiquidJS is Vulnerable to Remote Code Execution |
11.08.2026 |
10 |
| CVE-2026-65655 |
Temporal UI Server may set OAuth credential cookies without Secure behind a TLS-terminating reverse proxy |
11.08.2026 |
|
| CVE-2026-73034 |
DB-GPT v0.8.1 Path Traversal Arbitrary File Write via user_id Header |
11.08.2026 |
|
| CVE-2026-73036 |
Bash-it barbuk Theme 3.2.0 Terminal Escape Sequence Injection via pyproject.toml |
11.08.2026 |
|
| CVE-2026-73231 |
Faker: helpers.fake exploitable into arbritary code execution |
11.08.2026 |
7.8 |
| CVE-2026-73232 |
ffuf denial of service (OOM) via HTTP response decompression bomb |
11.08.2026 |
7.5 |
| CVE-2026-73233 |
FreeCAD: FEM formula incomplete escape |
11.08.2026 |
|
| CVE-2026-73234 |
FreeCAD: FCStd path traversal allows arbitrary file write via unsanitized file attribute in PropertyFileIncluded::Restore() |
11.08.2026 |
7.8 |
| CVE-2026-73235 |
FreeCAD: XXE file read and SSRF via external entity injection in Document.xml SAX parser |
11.08.2026 |
6.1 |
| CVE-2026-73241 |
FreeRDP: RDSTLS server authentication bypass: a credential-less Capabilities PDU is accepted at the auth step (fail-open `resultCode`) |
11.08.2026 |
|
| CVE-2026-73242 |
FreeRDP: Kerberos GSS Wrap-token `EC` field is unbounded, causing an out-of-bounds decrypt in `kerberos_DecryptMessage` |
11.08.2026 |
|
| CVE-2024-14042 |
Open5GS Diameter S6a hss-s6a-path.c hss_ogs_diam_s6a_ulr_cb stack-based overflow |
11.08.2026 |
|
| CVE-2026-48804 |
python-socketio: Binary attachment accumulation can cause denial of service |
11.08.2026 |
7.5 |
| CVE-2026-48813 |
Flawfinder output manipulation via untrusted filenames and source text |
11.08.2026 |
|
| CVE-2026-70339 |
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
12.08.2026 |
5.4 |
| CVE-2026-71467 |
Acm-search-v2-api-rhel9: search-v2-api: authentication bypass on /federated via upgrade: websocket header spoofing |
11.08.2026 |
|
| CVE-2026-71468 |
Acm-search-v2-api-rhel9: search-v2-api: cross-user bearer-token reuse via global federation-config cache |
11.08.2026 |
|
| CVE-2026-71474 |
Insights-client-rhel9: insights-client: pull-secret bearer token written to logs on non-200 ccx response |
11.08.2026 |
|
| CVE-2026-71475 |
Insights-client-rhel9: insights-client: spoke-controlled clusterid injected unencoded into insights api url path |
11.08.2026 |
|
| CVE-2026-71845 |
Insights-client: insights-client: ccx_token bearer credential logged in clear text at startup via setdefault() |
11.08.2026 |
|
| CVE-2026-73031 |
telegram-search Stored XSS via v-html in MessageList.vue |
11.08.2026 |
|
| CVE-2026-73032 |
PapersGPT for Zotero 0.6.1 RCE via Unsanitized LLM Response eval() |
11.08.2026 |
|
| CVE-2026-73229 |
Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests |
11.08.2026 |
4.3 |
| CVE-2026-73230 |
Ente: 2of3 cards v1 contain a checksum that enables offline guessing of low-entropy secrets |
11.08.2026 |
|
| CVE-2026-73281 |
|
11.08.2026 |
3.5 |
| CVE-2026-73282 |
|
11.08.2026 |
4.8 |
| CVE-2026-73283 |
|
11.08.2026 |
2.5 |
| CVE-2026-18688 |
Out-of-Bounds Read in MongoDB Aggregation Framework Leads to Denial of Service and Potential Memory Disclosure |
11.08.2026 |
|
| CVE-2026-18690 |
Improper Authorization in MongoDB Server Allows Unauthorized Actions on System Collections |
11.08.2026 |
|
| CVE-2026-18691 |
Improper Authentication in MongoDB Intra-Cluster Connections Allows Credential Exposure |
11.08.2026 |
|
| CVE-2026-18692 |
Use-After-Free in MongoDB Timeseries Bucket Handling Leads to Denial of Service and Potential Remote Code Execution |
11.08.2026 |
|
| CVE-2026-18693 |
Out-of-Bounds Read/Write in MongoDB Timeseries Bucket Handling Leads to Denial of Service and Potential Memory Disclosure |
11.08.2026 |
|
| CVE-2026-18694 |
Out-of-Bounds Read in MongoDB Geospatial Query Processing Leads to Denial of Service and Potential Memory Disclosure |
11.08.2026 |
|
| CVE-2026-18696 |
Improper Authorization in MongoDB applyOps Command Handling Allows Unauthorized DDL Operations on Collections |
11.08.2026 |
|
| CVE-2026-18697 |
Improper Input Validation in MongoDB Aggregation Framework Allows Unauthenticated Denial of Service on mongos |
11.08.2026 |
|
| CVE-2026-18698 |
Improper Authorization in MongoDB Server Allows Unauthorized Actions on System Collections via the validate Command |
11.08.2026 |
|
| CVE-2026-18699 |
Improper Input Validation in MongoDB Query Planner Leads to Denial of Service |
11.08.2026 |
|
| CVE-2026-18700 |
Use-After-Free in MongoDB Geospatial Validation Leads to Denial of Service |
11.08.2026 |
|
| CVE-2026-18701 |
Type Confusion in MongoDB Query Subsystem Leads to Denial of Service |
11.08.2026 |
|
| CVE-2026-18702 |
Improper Authorization in MongoDB profile Command Allows Unauthorized Modification of Server-Wide Diagnostic Settings |
11.08.2026 |
|
| CVE-2026-18704 |
Improper Authorization in MongoDB Aggregation Framework Allows Read-Only User to Perform Unauthorized Write Operations |
11.08.2026 |
|
| CVE-2026-18705 |
Improper Authorization in MongoDB Atlas Vector Search Allows Unauthorized Access to Protected View Data |
11.08.2026 |
|
| CVE-2026-18708 |
Improper Neutralization of Input in MongoDB Server's JavaScript Scripting Engine Leads to Unauthorized Code Execution Within Query Scopes |
11.08.2026 |
|
| CVE-2026-18709 |
Missing Authorization in MongoDB Sharded Transaction Commit/Abort Handling Leads to Cross-Shard Data Inconsistency |
11.08.2026 |
|
| CVE-2026-18711 |
Use-After-Free in MongoDB Query Execution Engine Leads to Denial of Service and Potential Memory Disclosure |
11.08.2026 |
|
| CVE-2026-18712 |
Improper Authorization in MongoDB Queryable Encryption Maintenance Operations Allows Unauthorized Modification of Other Collections |
11.08.2026 |
|
| CVE-2026-69119 |
Taubyte Tau v1.1.10 Missing Authorization via POST /projects/{id} |
11.08.2026 |
|
| CVE-2026-72742 |
DSPy 3.3.0b1 Local File Read via Image/Audio Output Field Parsing |
11.08.2026 |
|
| CVE-2026-73223 |
electerm: Path traversal in editWithSystemEditor temp file path via unsanitized SFTP filename |
11.08.2026 |
8.1 |
| CVE-2026-73224 |
Electerm check folder size function may get attacked by unsafe folder name |
11.08.2026 |
8.8 |
| CVE-2026-73225 |
electerm: Path traversal in FTP/SFTP recursive folder download via unsanitized server filename |
11.08.2026 |
8.1 |
| CVE-2026-73226 |
Electerm WebSocket `upgrade-func` and `fs` handlers allow arbitrary method/function invocation due to missing method-name allowlist |
11.08.2026 |
8.8 |
| CVE-2026-73227 |
electerm's RDP clipboard file download may parse unsafe file name |
11.08.2026 |
8.1 |
| CVE-2026-73228 |
Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data` |
11.08.2026 |
5.3 |
| CVE-2026-15426 |
AcyMailing <= 10.11.1 - Authenticated (Subscriber+) Missing Authorization to Account Takeover via Notification Template Update |
11.08.2026 |
8.8 |
| CVE-2026-18687 |
Improper Validation in MongoDB Queryable Encryption Maintenance Operation Leads to Denial of Service and Index Corruption |
11.08.2026 |
|
| CVE-2026-18695 |
Improper Input Validation in MongoDB Timeseries Query Processing Leads to Denial of Service |
11.08.2026 |
|
| CVE-2026-18703 |
Improper Enforcement of Authentication Mechanism Restrictions in MongoDB Server Allows Use of Disabled Authentication Method |
11.08.2026 |
|
| CVE-2026-18706 |
Use-After-Free in MongoDB $graphLookup Aggregation Stage Leads to Denial of Service and Potential Remote Code Execution |
11.08.2026 |
|
| CVE-2026-18707 |
Improper Input Validation in MongoDB Aggregation Command Handling Leads to Denial of Service |
11.08.2026 |
|
| CVE-2026-48802 |
python-engineio has unbound thread allocation that can cause denial of service |
11.08.2026 |
7.5 |
| CVE-2026-48809 |
python-engineio has possible denial of service due to maximum payload size sometimes not being enforced |
11.08.2026 |
7.5 |
| CVE-2026-69115 |
OpenIM Server v3.8.3 Missing Authorization on User and Group Enumeration Endpoints |
11.08.2026 |
|
| CVE-2026-69117 |
NetBox 4.5.8 ORM Injection via WritableNestedSerializer |
11.08.2026 |
|
| CVE-2026-73221 |
CVAT: Flawed authorization logic in endpoints related to lambda requests |
11.08.2026 |
|
| CVE-2026-73222 |
Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio) |
11.08.2026 |
8.8 |
| CVE-2026-69102 |
MaxKey Hard-coded JWT Secret Unauthorized Access via /login/jwt/trust |
11.08.2026 |
|
| CVE-2026-69113 |
Cap v0.3.1 Broken Access Control via video comment endpoint |
11.08.2026 |
|
| CVE-2026-20712 |
|
11.08.2026 |
|
| CVE-2026-20917 |
|
11.08.2026 |
|
| CVE-2026-27302 |
Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) |
11.08.2026 |
10 |
| CVE-2026-47940 |
Lightroom Classic | Integer Overflow or Wraparound (CWE-190) |
12.08.2026 |
7.8 |
| CVE-2026-48381 |
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) |
11.08.2026 |
9 |
| CVE-2026-48397 |
Lightroom Classic | Deserialization of Untrusted Data (CWE-502) |
12.08.2026 |
8.6 |
| CVE-2026-48404 |
Lightroom Classic | Out-of-bounds Write (CWE-787) |
12.08.2026 |
7.8 |
| CVE-2026-48405 |
Lightroom Classic | Out-of-bounds Write (CWE-787) |
12.08.2026 |
7.8 |
| CVE-2026-48406 |
Lightroom Classic | Out-of-bounds Write (CWE-787) |
12.08.2026 |
7.8 |
| CVE-2026-48407 |
Lightroom Classic | Out-of-bounds Write (CWE-787) |
12.08.2026 |
7.8 |
| CVE-2026-48408 |
Lightroom Classic | Out-of-bounds Write (CWE-787) |
12.08.2026 |
7.8 |
| CVE-2026-48409 |
Lightroom Classic | Out-of-bounds Write (CWE-787) |
12.08.2026 |
7.8 |
| CVE-2026-48410 |
Lightroom Classic | Out-of-bounds Write (CWE-787) |
12.08.2026 |
7.8 |
| CVE-2026-48411 |
Adobe Commerce | Incorrect Authorization (CWE-863) |
11.08.2026 |
6.5 |
| CVE-2026-48412 |
Adobe Commerce | Incorrect Authorization (CWE-863) |
12.08.2026 |
2.7 |
| CVE-2026-48413 |
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) |
11.08.2026 |
8.7 |
| CVE-2026-48414 |
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79) |
11.08.2026 |
7.7 |
| CVE-2026-48415 |
Adobe Commerce | Incorrect Authorization (CWE-863) |
11.08.2026 |
7.6 |
| CVE-2026-48416 |
Adobe Commerce | Incorrect Authorization (CWE-863) |
11.08.2026 |
7.5 |
| CVE-2026-48441 |
Lightroom Classic | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) |
12.08.2026 |
8.6 |
| CVE-2026-48447 |
Lightroom Classic | Incorrect Authorization (CWE-863) |
12.08.2026 |
7.7 |
| CVE-2026-65680 |
Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability |
12.08.2026 |
6.7 |
| CVE-2026-71362 |
Adobe Commerce | Incorrect Authorization (CWE-863) |
12.08.2026 |
9.1 |
| CVE-2026-71398 |
Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863) |
11.08.2026 |
10 |
| CVE-2026-72712 |
Nmap 7.99 Denial of Service via Zero-Length TCP Option Packet |
11.08.2026 |
|
| CVE-2026-72713 |
XAgent Path Traversal Arbitrary File Read via /workspace/file |
11.08.2026 |
|
| CVE-2026-73213 |
Coturn: `addr_less_eq()` does a component-wise IPv6 comparison instead of a lexicographic one, letting an authenticated TURN client bypass `denied-peer-ip`/`allowed-peer-ip` IPv6 ranges (TURN-specific SSRF) |
11.08.2026 |
|
| CVE-2026-73214 |
coturn allocates a full per-peer SSL/session before verifying the DTLS cookie, enabling source-spoofing/botnet state-exhaustion DoS |
11.08.2026 |
|
| CVE-2026-73215 |
The coturn server can end in a state where it does not accept more requests with "even-port" enabled. |
11.08.2026 |
|
| CVE-2026-73216 |
coturn: mobility disconnects bypass allocation quotas and exhaust relay capacity |
11.08.2026 |
6.5 |
| CVE-2026-73217 |
Cursor: Sandbox escape via tampered Python virtual environments |
11.08.2026 |
|
| CVE-2026-73218 |
Cursor: Sandbox escape via launching privileged containers |
11.08.2026 |
|
| CVE-2026-73219 |
CVAT: Denial of service with regards to automatic annotation |
11.08.2026 |
|
| CVE-2016-20097 |
Weaver E-cology 8.0 SQL Injection File Read via SignatureDownLoad |
11.08.2026 |
|
| CVE-2022-50997 |
Weaver E-cology 8.0 / 9.0 SQL Injection via HrmCareerApplyPerView.jsp |
11.08.2026 |
|
| CVE-2025-0046 |
|
11.08.2026 |
|
| CVE-2025-54512 |
|
11.08.2026 |
|
| CVE-2026-0465 |
|
11.08.2026 |
|
| CVE-2026-20901 |
|
12.08.2026 |
|
| CVE-2026-47705 |
TypeBot vulnerable to CSV injection in result export |
11.08.2026 |
9.6 |
| CVE-2026-48494 |
TypeBot vulnerable to cross-typebot WhatsApp preview webhook resume via global `wa-preview-{phone}` session ids |
11.08.2026 |
|
| CVE-2026-48767 |
Google Sheets OAuth access token disclosure to guest members via getAccessToken |
11.08.2026 |
7.6 |
| CVE-2026-48771 |
ishankportfolio: Stored Contact Form Submission Exposure via Public Client-Side Database Configuration |
11.08.2026 |
8.2 |
| CVE-2026-48790 |
turso-cli persists Turso platform JWT with world-readable (0o644) file permissions |
11.08.2026 |
5.5 |
| CVE-2026-73090 |
PeerTube: Cross-origin remote video takeover via Update activity |
11.08.2026 |
9.3 |
| CVE-2026-73211 |
PeerTube: Unauthenticated remote SQL injection in ActorFollowModel.updateScore() |
11.08.2026 |
9.8 |
| CVE-2026-73212 |
coturn peer-IP ACL canonicalization & scope bypass on the RFC 6062 TCP CONNECT relay path → internal-network SSRF and proven internal root RCE |
11.08.2026 |
|
| CVE-2025-0041 |
|
11.08.2026 |
|
| CVE-2025-48505 |
|
11.08.2026 |
|
| CVE-2025-48506 |
|
11.08.2026 |
|
| CVE-2025-61970 |
|
11.08.2026 |
|
| CVE-2025-8087 |
|
11.08.2026 |
|
| CVE-2026-12571 |
Authentication Bypass Leading to Account Takeover |
12.08.2026 |
9.8 |
| CVE-2026-20349 |
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability |
12.08.2026 |
8.6 |
| CVE-2026-40375 |
Microsoft Dynamics Business Central Information Disclosure Vulnerability |
11.08.2026 |
6.5 |
| CVE-2026-42976 |
Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-43606 |
|
11.08.2026 |
|
| CVE-2026-47285 |
Visual Studio Code Information Disclosure Vulnerability |
11.08.2026 |
6.5 |
| CVE-2026-47299 |
Azure Monitor Agent Elevation of Privilege Vulnerability |
11.08.2026 |
7.2 |
| CVE-2026-47922 |
CAI Content Credentials | Server-Side Request Forgery (SSRF) (CWE-918) |
11.08.2026 |
4.7 |
| CVE-2026-48387 |
CAI Content Credentials | Integer Overflow or Wraparound (CWE-190) |
11.08.2026 |
6.2 |
| CVE-2026-48434 |
CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) |
11.08.2026 |
6.2 |
| CVE-2026-48435 |
CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191) |
11.08.2026 |
6.2 |
| CVE-2026-48436 |
CAI Content Credentials | Improper Input Validation (CWE-20) |
11.08.2026 |
6.5 |
| CVE-2026-48437 |
CAI Content Credentials | Improper Certificate Validation (CWE-295) |
11.08.2026 |
5.5 |
| CVE-2026-48438 |
CAI Content Credentials | NULL Pointer Dereference (CWE-476) |
11.08.2026 |
7.5 |
| CVE-2026-48439 |
CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) |
11.08.2026 |
7.5 |
| CVE-2026-48442 |
CAI Content Credentials | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) |
11.08.2026 |
7.1 |
| CVE-2026-48443 |
CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400) |
11.08.2026 |
6.2 |
| CVE-2026-48444 |
CAI Content Credentials | Integer Overflow or Wraparound (CWE-190) |
11.08.2026 |
6.2 |
| CVE-2026-48445 |
CAI Content Credentials | Integer Overflow or Wraparound (CWE-190) |
11.08.2026 |
6.2 |
| CVE-2026-48446 |
CAI Content Credentials | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) |
11.08.2026 |
5.5 |
| CVE-2026-49179 |
Windows Active Directory Domain Services Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-50472 |
Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-50516 |
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability |
12.08.2026 |
9.4 |
| CVE-2026-54113 |
Remote Procedure Call Denial of Service Vulnerability |
11.08.2026 |
7.5 |
| CVE-2026-54123 |
Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-54981 |
Visual Studio Code Python Extension Security Feature Bypass Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-54984 |
Windows Imaging Component Remote Code Execution Vulnerability |
11.08.2026 |
7.8 |
| CVE-2026-56174 |
Windows Narrator Braille Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-56179 |
Windows Network Address Translation (NAT) Spoofing Vulnerability |
12.08.2026 |
8.3 |
| CVE-2026-57104 |
Azure Storage Explorer Elevation of Privilege Vulnerability |
11.08.2026 |
8.8 |
| CVE-2026-57105 |
Microsoft Office SharePoint Spoofing Vulnerability |
12.08.2026 |
8 |
| CVE-2026-58612 |
PowerShell Information Disclosure Vulnerability |
11.08.2026 |
7.4 |
| CVE-2026-58639 |
Microsoft SharePoint Server Spoofing Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-58641 |
.NET Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-58650 |
Visual Studio Code Security Feature Bypass Vulnerability |
11.08.2026 |
7.8 |
| CVE-2026-58651 |
Microsoft Word Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-59113 |
Visual Studio Code Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-59119 |
PowerShell Elevation of Privilege Vulnerability |
12.08.2026 |
7.3 |
| CVE-2026-59122 |
Windows Telephony Service Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-59124 |
Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability |
12.08.2026 |
9.8 |
| CVE-2026-59125 |
Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability |
11.08.2026 |
7 |
| CVE-2026-59126 |
Windows Event Logging Service Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-59127 |
Windows Installer Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-59128 |
Windows Encrypting File System (EFS) Information Disclosure Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-59130 |
AMD Zen Information Disclosure Vulnerability |
11.08.2026 |
5.6 |
| CVE-2026-59131 |
AMD Zen Information Disclosure Vulnerability |
11.08.2026 |
5.6 |
| CVE-2026-59132 |
Windows TCP/IP Denial of Service Vulnerability |
11.08.2026 |
7.5 |
| CVE-2026-59133 |
Microsoft High Performance Computing (HPC) Pack Elevation of Privilege Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-59134 |
Remote Desktop Client Remote Code Execution Vulnerability |
12.08.2026 |
7.5 |
| CVE-2026-59135 |
Microsoft Windows Search Component Information Disclosure Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-59136 |
Microsoft COM for Windows Information Disclosure Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-59137 |
Windows Event Logging Service Information Disclosure Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-59138 |
Microsoft Remote Registry Service Denial of Service Vulnerability |
11.08.2026 |
6.5 |
| CVE-2026-61345 |
Microsoft Remote Registry Service Denial of Service Vulnerability |
11.08.2026 |
6.5 |
| CVE-2026-61346 |
Windows Graphics Kernel Elevation of Privilege Vulnerability |
11.08.2026 |
7 |
| CVE-2026-61347 |
Windows Event Logging Service Information Disclosure Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-61348 |
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-61349 |
Windows Work Folder Service Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-61350 |
Windows NTFS Information Disclosure Vulnerability |
11.08.2026 |
4.6 |
| CVE-2026-61352 |
Remote Desktop Client Remote Code Execution Vulnerability |
11.08.2026 |
7.5 |
| CVE-2026-61353 |
Windows Telephony Service Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-61355 |
Windows Sensor Data Service Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-61356 |
Windows Remote Desktop Services Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-61357 |
Application Information Services Elevation of Privilege Vulnerability |
11.08.2026 |
7.8 |
| CVE-2026-61358 |
Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability |
11.08.2026 |
7.8 |
| CVE-2026-61359 |
Windows Storage Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-61360 |
Windows GDI Information Disclosure Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-61361 |
Windows DHCP Client Remote Code Execution Vulnerability |
12.08.2026 |
7 |
| CVE-2026-61363 |
Remote Desktop Client Remote Code Execution Vulnerability |
12.08.2026 |
7.5 |
| CVE-2026-61364 |
Windows Remote Desktop Services Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-61365 |
Windows Remote Desktop Services Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-61366 |
Windows Network Connection Broker Elevation of Privilege Vulnerability |
11.08.2026 |
7 |
| CVE-2026-61367 |
Windows Remote Desktop Services Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-61368 |
Windows Hyper-V Information Disclosure Vulnerability |
11.08.2026 |
5 |
| CVE-2026-61918 |
Windows Remote Desktop Client Information Disclosure Vulnerability |
11.08.2026 |
6.5 |
| CVE-2026-61920 |
Windows DNS Server Remote Code Execution Vulnerability |
12.08.2026 |
6.6 |
| CVE-2026-61921 |
Windows Remote Desktop Client Information Disclosure Vulnerability |
11.08.2026 |
6.5 |
| CVE-2026-61923 |
Windows Display Enhancement Service Elevation of Privilege Vulnerability |
11.08.2026 |
7.8 |
| CVE-2026-61924 |
Windows Remote Desktop Client Information Disclosure Vulnerability |
11.08.2026 |
6.5 |
| CVE-2026-61925 |
Windows Installer Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-61926 |
Windows USB Driver Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-61927 |
Windows Bind Filter Driver Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-61928 |
Windows Hello Tampering Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-61929 |
Windows Kernel Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-61930 |
Windows Kernel Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-61932 |
Windows DWM Core Library Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-61933 |
Windows DWM Core Library Information Disclosure Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-61934 |
Windows Bind Filter Driver Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-61936 |
Windows Defender Firewall Service Security Feature Bypass Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-61937 |
Windows HTTP.sys Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-61938 |
Windows Installer Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-61939 |
Winlogon Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62688 |
Windows MIDI Service Module Elevation of Privileges Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62690 |
Windows Push Notifications Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62692 |
Windows Remote Desktop Services Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62693 |
Windows MIDI Service Module Elevation of Privileges Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62695 |
Windows Storage Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62696 |
Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62698 |
Microsoft Digest Authentication Elevation of Privilege Vulnerability |
11.08.2026 |
7.8 |
| CVE-2026-62699 |
Windows Universal Disk Format File System Driver (UDFS) Remote Code Execution Vulnerability |
11.08.2026 |
6.8 |
| CVE-2026-62700 |
Windows NTFS Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62701 |
Windows Telephony Service Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62702 |
Windows Graphics Kernel Denial of Service Vulnerability |
11.08.2026 |
6.8 |
| CVE-2026-62703 |
Windows DWM Core Library Information Disclosure Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-62705 |
Windows Bind Filter Driver Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62707 |
Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability |
11.08.2026 |
7.8 |
| CVE-2026-62708 |
Windows Kernel Elevation of Privilege Vulnerability |
12.08.2026 |
6.4 |
| CVE-2026-62709 |
Windows GDI+ Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-62710 |
Windows Device Association Service Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62711 |
Windows Win32k Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62712 |
Windows Win32k Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62713 |
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62714 |
Windows DHCP Server Information Disclosure Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-62715 |
Windows DHCP Server Information Disclosure Vulnerability |
11.08.2026 |
6.5 |
| CVE-2026-62716 |
Windows DHCP Server Information Disclosure Vulnerability |
11.08.2026 |
6.5 |
| CVE-2026-62717 |
Windows Message Queuing Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62718 |
Windows DHCP Server Information Disclosure Vulnerability |
11.08.2026 |
6.5 |
| CVE-2026-62719 |
Windows Message Queuing Elevation of Privilege Vulnerability |
11.08.2026 |
7.8 |
| CVE-2026-62720 |
Windows DHCP Server Information Disclosure Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-62721 |
Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62722 |
Windows Bind Filter Driver Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62723 |
Windows Telephony Service Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62724 |
Windows Telephony Service Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62725 |
Windows Telephony Service Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62726 |
Windows Telephony Service Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62728 |
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62729 |
Windows Telephony Service Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62730 |
Windows Wired AutoConfig Service Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-62732 |
Windows Telephony Service Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62733 |
Windows Win32k Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62734 |
Windows Telephony Service Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62735 |
Windows HTTP.sys Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62736 |
Windows DHCP Client Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62737 |
Windows Kernel Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62738 |
Windows Management Instrumentation Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-62739 |
Windows HTTP.sys Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62740 |
Windows Imaging Component Information Disclosure Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-62741 |
Windows HTTP.sys Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62742 |
Windows DHCP Server Information Disclosure Vulnerability |
11.08.2026 |
6.5 |
| CVE-2026-62743 |
Win32k Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-62745 |
Windows DHCP Server Information Disclosure Vulnerability |
11.08.2026 |
6.5 |
| CVE-2026-62746 |
Win32k Information Disclosure Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-62747 |
Windows Device Association Service Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62748 |
Windows Telephony Service Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62749 |
Windows Kernel Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62750 |
Windows HTTP Protocol Stack Tampering Vulnerability |
11.08.2026 |
6.5 |
| CVE-2026-62751 |
Windows Projected File System Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62752 |
Windows Kerberos Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62753 |
Windows HTTP.sys Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62754 |
Windows Kerberos Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62755 |
Windows DHCP Client Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62757 |
Windows Schannel Security Feature Bypass Vulnerability |
12.08.2026 |
5.3 |
| CVE-2026-62758 |
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62761 |
Windows DHCP Server Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62766 |
Windows Kerberos Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62768 |
Windows Installer Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62769 |
Windows DNS Elevation of Privilege Vulnerability |
12.08.2026 |
6.7 |
| CVE-2026-62770 |
Windows Shell Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62771 |
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62772 |
Windows Container Isolation FS Filter Driver (unionfs.sys) Elevation of Privilege Vulnerability |
11.08.2026 |
7.8 |
| CVE-2026-62773 |
Windows Kerberos Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62774 |
Windows Graphics Kernel Elevation of Privilege Vulnerability |
11.08.2026 |
7 |
| CVE-2026-62775 |
Windows Container Isolation FS Filter Driver (unionfs.sys) Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-62776 |
Windows DHCP Server Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62777 |
Windows License Manager Elevation of Privilege Vulnerability |
11.08.2026 |
7.8 |
| CVE-2026-62778 |
Windows DNS Elevation of Privilege Vulnerability |
12.08.2026 |
8.1 |
| CVE-2026-62779 |
Windows Schannel Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62780 |
Windows Kernel Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62781 |
RPC Runtime Library Remote Code Execution Vulnerability |
12.08.2026 |
8.1 |
| CVE-2026-62782 |
Windows SMB Client Information Disclosure Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-62783 |
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62784 |
Microsoft Local Security Authority Server (lsasrv) Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-62785 |
Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-62786 |
Win32k Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-62787 |
Windows DNS Server Remote Code Execution Vulnerability |
12.08.2026 |
7.5 |
| CVE-2026-62788 |
Windows Kernel Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62790 |
Windows SMBv3 Server Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-62792 |
Windows TCP/IP Remote Code Execution Vulnerability |
12.08.2026 |
8.1 |
| CVE-2026-62793 |
Windows NTFS Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-62795 |
Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-62796 |
Windows NTFS Information Disclosure Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-62797 |
Windows NTFS Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62798 |
Win32k Information Disclosure Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-62799 |
Windows SMB Client Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62800 |
Windows SMBv3 Server Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-62803 |
Windows DHCP Server Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62807 |
Windows DHCP Server Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62811 |
Windows HTTP.sys Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62812 |
Windows DHCP Server Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62814 |
Windows DHCP Server Information Disclosure Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-62815 |
Microsoft QUIC Remote Code Execution Vulnerability |
12.08.2026 |
9.8 |
| CVE-2026-62816 |
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-62817 |
Windows DNS Server Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-62818 |
Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-62819 |
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
12.08.2026 |
8.1 |
| CVE-2026-62820 |
Windows DNS Server Remote Code Execution Vulnerability |
12.08.2026 |
8.1 |
| CVE-2026-62822 |
Windows GDI+ Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-62823 |
Windows DHCP Server Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-62824 |
Remote Desktop Client Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-62827 |
Microsoft SharePoint Server Elevation of Privilege Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-62829 |
Microsoft SharePoint Server Spoofing Vulnerability |
11.08.2026 |
4.6 |
| CVE-2026-62832 |
Windows User Profile Service Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62837 |
Microsoft SharePoint Server Information Disclosure Vulnerability |
11.08.2026 |
6.5 |
| CVE-2026-62839 |
Microsoft SharePoint Server Spoofing Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-62842 |
Microsoft Office Graphics Component Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-62869 |
Azure Entra ID Spoofing Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-62871 |
.NET Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62872 |
.NET Framework Elevation of Privilege Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-62876 |
Windows Win32k Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62877 |
Windows Win32k Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62878 |
Windows DNS Server Remote Code Execution Vulnerability |
12.08.2026 |
9.8 |
| CVE-2026-62880 |
Windows NTFS Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62881 |
Windows DNS Elevation of Privilege Vulnerability |
12.08.2026 |
6.7 |
| CVE-2026-62882 |
Microsoft Outlook Spoofing Vulnerability |
12.08.2026 |
4.3 |
| CVE-2026-62883 |
Windows DNS Elevation of Privilege Vulnerability |
12.08.2026 |
6.7 |
| CVE-2026-62885 |
Windows Win32k Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62886 |
.NET Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62887 |
Windows NTFS Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-62888 |
Windows DWM Core Library Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62889 |
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability |
12.08.2026 |
8.1 |
| CVE-2026-62890 |
Windows GDI+ Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62892 |
Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62893 |
Windows Deployment Services TFTP Server Remote Code Execution Vulnerability |
12.08.2026 |
9.8 |
| CVE-2026-62894 |
Windows DWM Core Library Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62897 |
.NET Framework Remote Code Execution Vulnerability |
12.08.2026 |
7 |
| CVE-2026-62898 |
Microsoft QUIC Information Disclosure Vulnerability |
12.08.2026 |
7.5 |
| CVE-2026-62899 |
.NET Security Feature Bypass Vulnerability |
11.08.2026 |
5.9 |
| CVE-2026-62900 |
.NET Information Disclosure Vulnerability |
11.08.2026 |
5.9 |
| CVE-2026-62901 |
.NET Denial of Service Vulnerability |
11.08.2026 |
7.5 |
| CVE-2026-62902 |
.NET Information Disclosure Vulnerability |
11.08.2026 |
6.5 |
| CVE-2026-62908 |
Windows Backup Engine Elevation of Privilege Vulnerability |
11.08.2026 |
7 |
| CVE-2026-62909 |
.NET Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-62910 |
Microsoft Exchange Server Elevation of Privilege Vulnerability |
12.08.2026 |
7.2 |
| CVE-2026-62911 |
Microsoft Exchange Server Elevation of Privilege Vulnerability |
12.08.2026 |
8 |
| CVE-2026-62912 |
Microsoft Exchange Server Denial of Service Vulnerability |
11.08.2026 |
6.5 |
| CVE-2026-62913 |
Microsoft Exchange Server Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-62914 |
Microsoft Exchange Server Spoofing Vulnerability |
11.08.2026 |
7.3 |
| CVE-2026-62915 |
Microsoft Exchange Server Security Feature Bypass Vulnerability |
11.08.2026 |
6.5 |
| CVE-2026-62917 |
Microsoft SharePoint Server Spoofing Vulnerability |
12.08.2026 |
4.6 |
| CVE-2026-63512 |
Microsoft SharePoint Server Tampering Vulnerability |
11.08.2026 |
6.5 |
| CVE-2026-63513 |
Microsoft Office Graphics Component Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-63514 |
Microsoft SharePoint Server Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-63515 |
Microsoft Office Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-63516 |
Microsoft SharePoint Server Spoofing Vulnerability |
11.08.2026 |
6.5 |
| CVE-2026-63517 |
Microsoft Office Graphics Component Information Disclosure Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-63518 |
Microsoft Office Word Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-63519 |
Microsoft Office Graphics Component Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-63520 |
Microsoft SharePoint Server Remote Code Execution Vulnerability |
12.08.2026 |
8.1 |
| CVE-2026-63521 |
Microsoft Office Word Information Disclosure Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-63522 |
Azure SQL Database Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-63524 |
Microsoft Office Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-63525 |
Microsoft Office Word Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-63526 |
Microsoft Office Graphics Component Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-63527 |
Microsoft Office Word Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-63528 |
Microsoft Office Word Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-63529 |
Microsoft Office Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-63530 |
Microsoft Office Word Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-63531 |
Microsoft Office Word Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-63532 |
Microsoft Office Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-63533 |
Microsoft Office Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-64897 |
Microsoft SharePoint Server Spoofing Vulnerability |
12.08.2026 |
4.6 |
| CVE-2026-64898 |
Microsoft Office Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-64899 |
Microsoft Office Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-64900 |
Microsoft SharePoint Server Spoofing Vulnerability |
12.08.2026 |
7.3 |
| CVE-2026-64901 |
Microsoft SharePoint Server Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-64902 |
Microsoft SharePoint Server Spoofing Vulnerability |
12.08.2026 |
4.6 |
| CVE-2026-64903 |
Microsoft Office Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-64904 |
Microsoft Office Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-64905 |
Microsoft Office Word Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-64906 |
Microsoft Access Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-64907 |
Microsoft Office Word Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-64908 |
Microsoft Access Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-64909 |
Microsoft Office Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-64910 |
Microsoft Office Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-64911 |
Microsoft Office Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-64912 |
Microsoft Access Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-64914 |
Microsoft Access Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-64915 |
Microsoft Office Word Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-64916 |
Microsoft SharePoint Server Spoofing Vulnerability |
12.08.2026 |
4.6 |
| CVE-2026-64917 |
Microsoft Office Word Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-64919 |
Microsoft Access Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-64920 |
Microsoft Access Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-64921 |
Microsoft SharePoint Server Elevation of Privilege Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-64922 |
Microsoft SharePoint Server Spoofing Vulnerability |
11.08.2026 |
4.6 |
| CVE-2026-65656 |
Microsoft Office Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-65657 |
Microsoft Office Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-65658 |
Microsoft SharePoint Server Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-65660 |
Microsoft SharePoint Server Spoofing Vulnerability |
11.08.2026 |
6.5 |
| CVE-2026-65661 |
Microsoft Office Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-65662 |
Windows GDI Information Disclosure Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-65663 |
Microsoft SharePoint Server Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-65664 |
Microsoft Office Graphics Component Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-65665 |
Microsoft SharePoint Server Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-65671 |
Remote Access API Elevation of Privilege Vulnerability |
11.08.2026 |
7.8 |
| CVE-2026-65672 |
Remote Access API Elevation of Privilege Vulnerability |
11.08.2026 |
7.8 |
| CVE-2026-65673 |
Microsoft Entra Connect Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-65675 |
CoPilot Chat Security Feature Bypass Vulnerability |
11.08.2026 |
7.1 |
| CVE-2026-65678 |
Windows Win32k Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-65679 |
Windows iSCSI Target Service Remote Code Execution Vulnerability |
12.08.2026 |
8.1 |
| CVE-2026-65681 |
Windows iSCSI Target Service Denial of Service Vulnerability |
12.08.2026 |
7.5 |
| CVE-2026-65767 |
Microsoft Teams for Android and iOS Spoofing Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-65768 |
Microsoft Teams Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-65769 |
Microsoft Teams iOS Information Disclosure Vulnerability |
11.08.2026 |
6.5 |
| CVE-2026-65773 |
Windows Kernel Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-65774 |
Windows Installer Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-65775 |
Windows Win32k Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-65776 |
Windows Win32k Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-65777 |
Active Directory Security Feature Bypass Vulnerability |
12.08.2026 |
5.3 |
| CVE-2026-65778 |
Windows Autopilot Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-65779 |
Windows Autopilot Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-65780 |
Windows Autopilot Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-65781 |
Windows Autopilot Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-65782 |
Windows Autopilot Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-65783 |
Windows Autopilot Elevation of Privilege Vulnerability |
11.08.2026 |
7 |
| CVE-2026-65784 |
Windows NTFS Information Disclosure Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-65785 |
Windows DHCP Client Denial of Service Vulnerability |
11.08.2026 |
6.5 |
| CVE-2026-65786 |
Desktop Window Manager Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-65787 |
Desktop Window Manager Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-65788 |
Desktop Window Manager Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-65789 |
Windows DNS Server Remote Code Execution Vulnerability |
12.08.2026 |
8.1 |
| CVE-2026-65790 |
Windows Message Queuing Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-65791 |
Windows iSCSI Target Service Remote Code Execution Vulnerability |
12.08.2026 |
9.8 |
| CVE-2026-65794 |
Windows SMB Client Information Disclosure Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-65795 |
Windows DNS Elevation of Privilege Vulnerability |
12.08.2026 |
6.7 |
| CVE-2026-65796 |
Windows iSCSI Target Service Denial of Service Vulnerability |
12.08.2026 |
5.9 |
| CVE-2026-65797 |
Windows DNS Elevation of Privilege Vulnerability |
12.08.2026 |
6.7 |
| CVE-2026-65798 |
Windows DNS Elevation of Privilege Vulnerability |
12.08.2026 |
6.7 |
| CVE-2026-65799 |
Windows DNS Elevation of Privilege Vulnerability |
12.08.2026 |
6.7 |
| CVE-2026-65806 |
Azure CycleCloud Information Disclosure Vulnerability |
11.08.2026 |
6.5 |
| CVE-2026-65807 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-65810 |
.NET Framework Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-65811 |
Power BI Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-65813 |
Microsoft Exchange Server Elevation of Privilege Vulnerability |
12.08.2026 |
6.5 |
| CVE-2026-65814 |
Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-65815 |
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-66301 |
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability |
11.08.2026 |
6.5 |
| CVE-2026-66799 |
Windows Key Guard Elevation of Privilege Vulnerability |
11.08.2026 |
7.8 |
| CVE-2026-66802 |
Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability |
12.08.2026 |
8.1 |
| CVE-2026-66804 |
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability |
11.08.2026 |
7.8 |
| CVE-2026-66805 |
Microsoft SharePoint Server Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-66806 |
Microsoft Office Word Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-66807 |
Microsoft Office Graphics Component Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-66808 |
Microsoft SharePoint Server Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-66809 |
Microsoft Office Graphics Component Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-66810 |
Microsoft Office Word Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-68792 |
Microsoft Office Elevation of Privilege Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68793 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68794 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68795 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68796 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68797 |
Microsoft Excel Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-68798 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68799 |
Microsoft Excel Information Disclosure Vulnerability |
12.08.2026 |
5.5 |
| CVE-2026-68800 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68801 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68802 |
Microsoft Excel Information Disclosure Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-68803 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68804 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68805 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68806 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68807 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68808 |
Microsoft Excel Information Disclosure Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-68809 |
Powerpoint Information Disclosure Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-68810 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68811 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68812 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68813 |
Microsoft Excel Information Disclosure Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-68814 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68815 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68816 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68817 |
Microsoft Excel Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-68819 |
Windows Network File System Denial of Service Vulnerability |
11.08.2026 |
5.9 |
| CVE-2026-68820 |
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-68821 |
Windows Package Manager Elevation of Privilege Vulnerability |
11.08.2026 |
7.3 |
| CVE-2026-69223 |
Apache Allura: Server-side request forgery |
11.08.2026 |
|
| CVE-2026-69278 |
Visual Studio Code Security Feature Bypass Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-69306 |
Visual Studio Code Security Feature Bypass Vulnerability |
11.08.2026 |
8.2 |
| CVE-2026-69320 |
Visual Studio Code Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-70130 |
Microsoft Office Remote Code Execution Vulnerability |
12.08.2026 |
8.4 |
| CVE-2026-70304 |
Windows DNS Elevation of Privilege Vulnerability |
11.08.2026 |
6.7 |
| CVE-2026-70306 |
Microsoft Office SharePoint Spoofing Vulnerability |
12.08.2026 |
9.3 |
| CVE-2026-70307 |
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
12.08.2026 |
7 |
| CVE-2026-70310 |
Microsoft Word Information Disclosure Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-70311 |
Microsoft Office Word Remote Code Execution Vulnerability |
11.08.2026 |
7.8 |
| CVE-2026-70312 |
Powerpoint Information Disclosure Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-70313 |
Microsoft PowerPoint Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-70314 |
Microsoft Office Information Disclosure Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-70315 |
Microsoft Office Information Disclosure Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-70316 |
Powerpoint Information Disclosure Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-70317 |
Microsoft Office Information Disclosure Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-70318 |
Microsoft Excel Information Disclosure Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-70319 |
Microsoft Office Word Information Disclosure Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-70320 |
Powerpoint Information Disclosure Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-70321 |
Microsoft SharePoint Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-70322 |
Powerpoint Information Disclosure Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-70323 |
Microsoft Office Information Disclosure Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-70324 |
Microsoft SharePoint Elevation of Privilege Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-70325 |
Powerpoint Information Disclosure Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-70326 |
Microsoft SharePoint Server Elevation of Privilege Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-70327 |
Microsoft Excel Information Disclosure Vulnerability |
11.08.2026 |
6.5 |
| CVE-2026-70328 |
Microsoft Excel Information Disclosure Vulnerability |
11.08.2026 |
6.5 |
| CVE-2026-70329 |
Microsoft Outlook Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-70330 |
Windows DNS Elevation of Privilege Vulnerability |
11.08.2026 |
6.7 |
| CVE-2026-70335 |
GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability |
11.08.2026 |
7.8 |
| CVE-2026-70336 |
Visual Studio Code Remote Code Execution Vulnerability |
11.08.2026 |
8.8 |
| CVE-2026-70337 |
Microsoft PowerShell Remote Code Execution Vulnerability |
12.08.2026 |
8.8 |
| CVE-2026-70338 |
Microsoft PowerShell Security Feature Bypass Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-70340 |
Azure CycleCloud Elevation of Privilege Vulnerability |
12.08.2026 |
8.1 |
| CVE-2026-70344 |
Windows Installer Elevation of Privilege Vulnerability |
11.08.2026 |
7.8 |
| CVE-2026-70345 |
Windows Installer Elevation of Privilege Vulnerability |
11.08.2026 |
7.8 |
| CVE-2026-70346 |
Windows Installer Elevation of Privilege Vulnerability |
11.08.2026 |
7.8 |
| CVE-2026-70347 |
Windows Installer Elevation of Privilege Vulnerability |
11.08.2026 |
7.8 |
| CVE-2026-70348 |
Windows Management Services Denial of Service Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-70354 |
.NET Core Remote Code Execution Vulnerability |
12.08.2026 |
7.8 |
| CVE-2026-70355 |
Microsoft SharePoint Server Elevation of Privilege Vulnerability |
12.08.2026 |
7.3 |
| CVE-2026-71331 |
Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability |
12.08.2026 |
8.1 |
| CVE-2026-71389 |
CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191) |
11.08.2026 |
6.2 |
| CVE-2026-71390 |
CAI Content Credentials | Improper Input Validation (CWE-20) |
11.08.2026 |
4 |
| CVE-2026-72971 |
Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability |
11.08.2026 |
5.5 |
| CVE-2026-73086 |
nanoid: Integer Overflow or Wraparound |
11.08.2026 |
7.4 |
| CVE-2026-73087 |
Dozzle: SSRF guard bypass via IPv6 transition addresses (6to4/NAT64/Teredo) in webhook notification dispatcher |
11.08.2026 |
|
| CVE-2026-73088 |
Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.json custom stats (normalizeStats) |
11.08.2026 |
7.5 |
| CVE-2026-73089 |
Browserslist: Unbounded memory growth (no cache eviction) via distinct query results, leading to eventual OOM |
11.08.2026 |
7.5 |
| CVE-2025-31356 |
|
11.08.2026 |
|
| CVE-2025-31936 |
|
12.08.2026 |
|
| CVE-2025-31938 |
|
11.08.2026 |
|
| CVE-2025-35973 |
|
11.08.2026 |
|
| CVE-2025-35987 |
|
11.08.2026 |
|
| CVE-2026-20702 |
|
11.08.2026 |
|
| CVE-2026-20705 |
|
11.08.2026 |
|
| CVE-2026-20707 |
|
11.08.2026 |
|
| CVE-2026-20708 |
|
11.08.2026 |
|
| CVE-2026-20713 |
|
11.08.2026 |
|
| CVE-2026-20715 |
|
11.08.2026 |
|
| CVE-2026-20716 |
|
11.08.2026 |
|
| CVE-2026-20727 |
|
11.08.2026 |
|
| CVE-2026-20728 |
|
11.08.2026 |
|
| CVE-2026-20731 |
|
11.08.2026 |
|
| CVE-2026-20734 |
|
11.08.2026 |
|
| CVE-2026-20737 |
|
11.08.2026 |
|
| CVE-2026-20739 |
|
11.08.2026 |
|
| CVE-2026-20741 |
|
11.08.2026 |
|
| CVE-2026-20745 |
|
11.08.2026 |
|
| CVE-2026-20747 |
|
11.08.2026 |
|
| CVE-2026-20749 |
|
11.08.2026 |
|
| CVE-2026-20752 |
|
11.08.2026 |
|
| CVE-2026-20755 |
|
11.08.2026 |
|
| CVE-2026-20760 |
|
11.08.2026 |
|
| CVE-2026-20763 |
|
11.08.2026 |
|
| CVE-2026-20765 |
|
11.08.2026 |
|
| CVE-2026-20769 |
|
11.08.2026 |
|
| CVE-2026-20770 |
|
11.08.2026 |
|
| CVE-2026-20775 |
|
11.08.2026 |
|
| CVE-2026-20776 |
|
11.08.2026 |
|
| CVE-2026-20778 |
|
11.08.2026 |
|
| CVE-2026-20780 |
|
11.08.2026 |
|
| CVE-2026-20783 |
|
11.08.2026 |
|
| CVE-2026-20786 |
|
11.08.2026 |
|
| CVE-2026-20787 |
|
11.08.2026 |
|
| CVE-2026-20789 |
|
11.08.2026 |
|
| CVE-2026-20795 |
|
11.08.2026 |
|
| CVE-2026-20799 |
|
11.08.2026 |
|
| CVE-2026-20878 |
|
11.08.2026 |
|
| CVE-2026-20885 |
|
11.08.2026 |
|
| CVE-2026-20886 |
|
11.08.2026 |
|
| CVE-2026-20890 |
|
11.08.2026 |
|
| CVE-2026-20891 |
|
11.08.2026 |
|
| CVE-2026-20898 |
|
12.08.2026 |
|
| CVE-2026-20903 |
|
11.08.2026 |
|
| CVE-2026-20906 |
|
11.08.2026 |
|
| CVE-2026-20908 |
|
11.08.2026 |
|
| CVE-2026-20913 |
|
11.08.2026 |
|
| CVE-2026-21269 |
ColdFusion | Cross-site Scripting (Stored XSS) (CWE-79) |
11.08.2026 |
4.6 |
| CVE-2026-21273 |
ColdFusion | Improper Input Validation (CWE-20) |
11.08.2026 |
8.7 |
| CVE-2026-21279 |
ColdFusion | Improper Input Validation (CWE-20) |
11.08.2026 |
8.2 |
| CVE-2026-21387 |
|
11.08.2026 |
|
| CVE-2026-21399 |
|
11.08.2026 |
|
| CVE-2026-21400 |
|
11.08.2026 |
|
| CVE-2026-22887 |
|
11.08.2026 |
|
| CVE-2026-24099 |
|
11.08.2026 |
|
| CVE-2026-24693 |
|
11.08.2026 |
|
| CVE-2026-24911 |
|
11.08.2026 |
|
| CVE-2026-25194 |
|
11.08.2026 |
|
| CVE-2026-25652 |
ColdFusion | Incorrect Authorization (CWE-863) |
12.08.2026 |
7.8 |
| CVE-2026-27765 |
|
11.08.2026 |
|
| CVE-2026-28700 |
|
11.08.2026 |
|
| CVE-2026-28707 |
|
11.08.2026 |
|
| CVE-2026-28729 |
|
11.08.2026 |
|
| CVE-2026-28757 |
|
11.08.2026 |
|
| CVE-2026-32677 |
|
11.08.2026 |
|
| CVE-2026-32788 |
|
11.08.2026 |
|
| CVE-2026-32791 |
|
11.08.2026 |
|
| CVE-2026-34175 |
|
11.08.2026 |
|
| CVE-2026-34635 |
ColdFusion | Use of Hard-coded Cryptographic Key (CWE-321) |
11.08.2026 |
8.4 |
| CVE-2026-35502 |
|
11.08.2026 |
|
| CVE-2026-39452 |
|
11.08.2026 |
|
| CVE-2026-48362 |
ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) |
12.08.2026 |
10 |
| CVE-2026-48375 |
ColdFusion | Incorrect Authorization (CWE-863) |
11.08.2026 |
6.5 |
| CVE-2026-48376 |
ColdFusion | Improper Encoding or Escaping of Output (CWE-116) |
11.08.2026 |
5.4 |
| CVE-2026-48384 |
ColdFusion | Improper Input Validation (CWE-20) |
11.08.2026 |
4.9 |
| CVE-2026-48385 |
ColdFusion | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78) |
11.08.2026 |
7.7 |
| CVE-2026-48386 |
ColdFusion | Use of a Broken or Risky Cryptographic Algorithm (CWE-327) |
11.08.2026 |
7.5 |
| CVE-2026-48440 |
ColdFusion | Heap-based Buffer Overflow (CWE-122) |
12.08.2026 |
8.1 |
| CVE-2026-71383 |
ColdFusion | Incorrect Authorization (CWE-863) |
11.08.2026 |
7.3 |
| CVE-2026-71384 |
ColdFusion | Incorrect Authorization (CWE-863) |
11.08.2026 |
9.6 |
| CVE-2026-71386 |
ColdFusion | Cross-site Scripting (XSS) (CWE-79) |
12.08.2026 |
8.8 |
| CVE-2026-71387 |
ColdFusion | Incorrect Authorization (CWE-863) |
12.08.2026 |
8.8 |
| CVE-2026-73081 |
Activepieces: Remote Code Execution via Command Injection in Code Step Name |
11.08.2026 |
|
| CVE-2026-73082 |
Activepieces: Server-side request forgery in MCP tool validation endpoint |
11.08.2026 |
|
| CVE-2026-73083 |
Activepieces: V8 Isolate Sandbox Bypass via importFresh Module Loading |
11.08.2026 |
|
| CVE-2026-73084 |
Activepieces: Reflected Cross-Site Scripting in OAuth Redirect Endpoint |
11.08.2026 |
6.1 |
| CVE-2026-73085 |
Audiobookshelf: Refresh Token Accepted on Resource Endpoints |
11.08.2026 |
|
| CVE-2026-18247 |
DOM-Based Cross-Site Scripting in BlackBerry AtHoc Web Portals |
11.08.2026 |
|
| CVE-2026-47704 |
TypeBot vulnerable to cross-typebot webhook resume via unchecked `resultId` lineage allows unauthorized control of another bot's waiting session |
11.08.2026 |
|
| CVE-2026-48483 |
TypeBot's WhatsApp status forwarding uses unvalidated user-controlled URLs, allowing SSRF from the Typebot server |
11.08.2026 |
5.4 |
| CVE-2026-42142 |
TypeBot has Authorization Bypass in Google Sheets `getSheets` Endpoint that Allows Cross-Workspace Credential Access |
11.08.2026 |
7.1 |
| CVE-2026-48495 |
TypeBot Google Sheets OAuth callback can create credentials in unauthorized workspaces and modify arbitrary typebots |
11.08.2026 |
7.1 |
| CVE-2026-48766 |
TypeBot vulnerable to OpenAI API key exfiltration in listModels via attacker-controlled baseUrl |
11.08.2026 |
7.6 |
| CVE-2026-53413 |
Zoom Clients - Buffer Over-write |
12.08.2026 |
8.3 |
| CVE-2026-53414 |
Zoom Clients - Buffer Over-read |
11.08.2026 |
6.5 |
| CVE-2026-53415 |
Zoom Clients - Use After Free |
11.08.2026 |
8.3 |
| CVE-2026-53416 |
Zoom VDI - Path Traversal |
11.08.2026 |
7.1 |
| CVE-2026-56720 |
CamaleonCMS 2.9.2 and earlier Missing Authorization via profile Action |
11.08.2026 |
|
| CVE-2026-56721 |
CamaleonCMS 2.9.2 Privilege Escalation via Parameter Confusion in UsersController |
11.08.2026 |
|
| CVE-2026-67179 |
Genkit improper host header validation |
11.08.2026 |
7.8 |
| CVE-2026-67180 |
Google Turbinia arbitrary command execution |
11.08.2026 |
8.4 |
| CVE-2026-73077 |
Vim: Arbitrary Code Execution via Shell Keyword Lookup |
11.08.2026 |
|
| CVE-2026-73078 |
Vim: Arbitrary Code Execution via Netrw Menu Construction |
11.08.2026 |
|
| CVE-2026-73079 |
Sub2API: Path traversal in the Responses subpath routes lets an authenticated tenant relay requests to arbitrary upstream endpoints using pooled account credentials |
11.08.2026 |
8.5 |
| CVE-2026-73080 |
SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle |
11.08.2026 |
9.3 |
| CVE-2025-31114 |
Fooocus webui vulnerable to Remote Code Execution |
11.08.2026 |
|
| CVE-2026-14180 |
Undertow-core: undertow:http request smuggling via oversized chunk-size bit overlap |
11.08.2026 |
|
| CVE-2026-19078 |
Ose-oauth-server: oauth-server: open redirect vulnerability enables phishing via unvalidated parameter. |
11.08.2026 |
|
| CVE-2026-6726 |
An information leakage vulnerability in the TCG TPM 2.0 reference code. |
11.08.2026 |
|
| CVE-2026-6727 |
CVE-2026-6727 |
11.08.2026 |
|
| CVE-2026-73069 |
Twenty: SQL Injection in the `searchVector` Field Settings Allows Arbitrary PostgreSQL Execution |
11.08.2026 |
9.1 |
| CVE-2026-73070 |
Vim: Stack Buffer Overflow in the Vim Socket Server |
11.08.2026 |
|
| CVE-2026-73071 |
Vim: Use-after-free in JSON Decoding |
11.08.2026 |
3.3 |
| CVE-2026-73072 |
Vim: Heap Buffer Overflow when Loading a Spell File |
11.08.2026 |
|
| CVE-2026-73074 |
Vim: Heap Buffer Overflow in Text Property Handling |
11.08.2026 |
|
| CVE-2026-73075 |
Vim: Out-of-bounds Access in Popup Opacity Handling |
11.08.2026 |
|
| CVE-2026-73076 |
Vim: Arbitrary Command Execution via Malicious `.VimballRecord` Entry Replay in `vimball.vim` |
11.08.2026 |
|
| CVE-2026-11733 |
Buffer overflow vulnerability in some NETGEAR Nighthawk routers |
12.08.2026 |
|
| CVE-2026-11734 |
Device administrator can interrupt the normal operation of some NETGEAR Nighthawk devices. |
12.08.2026 |
|
| CVE-2026-11735 |
Stack-based buffer overflow vulnerability in some NETGEAR Nighthawk models |
12.08.2026 |
|
| CVE-2026-11736 |
Stack-based buffer overflow vulnerability in some NETGEAR Nighthawk routers |
12.08.2026 |
|
| CVE-2026-11737 |
Some NETGEAR Nighthawk devices allow administrators to tamper with the device |
12.08.2026 |
|
| CVE-2026-11738 |
Insufficient input validation in certain NETGEAR Nighthawk routers allows administrators to tamper with the device. |
12.08.2026 |
|
| CVE-2026-11739 |
Command injection vulnerability in some NETGEAR Nighthawk devices |
12.08.2026 |
|
| CVE-2026-11814 |
Command injection vulnerability in certain NETGEAR Nighthawk and Orbi routers |
11.08.2026 |
|
| CVE-2026-18638 |
Velociraptor server crash via the SetPassword API |
11.08.2026 |
6.5 |
| CVE-2026-18639 |
Velociraptor OIDC Authenticator susceptible to email spoofing |
11.08.2026 |
7.3 |
| CVE-2026-18640 |
Velociraptor directory traversal via the NewNotebook API |
11.08.2026 |
7.1 |
| CVE-2026-19546 |
Dbi: incomplete fix for cve-2026-14380 dbi: arbitrary code execution via caller-influenced profile attribute |
12.08.2026 |
|
| CVE-2026-73068 |
ToolJet: Cross-tenant Broken Access Control in ToolJet Database (tooljet-db): any authenticated user can read and write another organization's tables |
11.08.2026 |
5.9 |
| CVE-2026-9214 |
Insufficient input validation in NETGEAR R7000 router allows administrators to tamper with the device. |
12.08.2026 |
|
| CVE-2020-37257 |
|
11.08.2026 |
|
| CVE-2020-37258 |
|
11.08.2026 |
|
| CVE-2020-37259 |
|
11.08.2026 |
|
| CVE-2020-37260 |
|
11.08.2026 |
|
| CVE-2020-37261 |
|
11.08.2026 |
|
| CVE-2020-37262 |
|
11.08.2026 |
|
| CVE-2020-37263 |
|
11.08.2026 |
|
| CVE-2020-37264 |
|
11.08.2026 |
|
| CVE-2020-37265 |
|
11.08.2026 |
|
| CVE-2021-47988 |
|
11.08.2026 |
|
| CVE-2021-47989 |
|
11.08.2026 |
|
| CVE-2021-47990 |
|
11.08.2026 |
|
| CVE-2021-47991 |
|
11.08.2026 |
|
| CVE-2021-47992 |
|
11.08.2026 |
|
| CVE-2021-47993 |
|
11.08.2026 |
|
| CVE-2021-47994 |
|
11.08.2026 |
|
| CVE-2021-47995 |
|
11.08.2026 |
|
| CVE-2022-50974 |
|
11.08.2026 |
|
| CVE-2023-54367 |
|
11.08.2026 |
|
| CVE-2023-54368 |
|
11.08.2026 |
|
| CVE-2023-54369 |
|
11.08.2026 |
|
| CVE-2023-54370 |
|
11.08.2026 |
|
| CVE-2023-54371 |
|
11.08.2026 |
|
| CVE-2023-54372 |
|
11.08.2026 |
|
| CVE-2023-54373 |
|
11.08.2026 |
|
| CVE-2023-54374 |
|
11.08.2026 |
|
| CVE-2026-17535 |
Velociraptor Multiple Crashes in NTFS Parser when applied to invalid NTFS Volumes |
11.08.2026 |
6.2 |
| CVE-2026-18636 |
Velociraptor VFSGetBuffer API path deny list bypass |
11.08.2026 |
6.8 |
| CVE-2026-18860 |
Velociraptor incorrect Org deletion permissions check |
11.08.2026 |
8.7 |
| CVE-2026-72922 |
AutoGPT: Webhook provider path confusion bypasses generic webhook secret verification |
11.08.2026 |
8.2 |
| CVE-2026-72925 |
SWC HTML minifier may allow script element breakout when minifying embedded JSON |
11.08.2026 |
6.1 |
| CVE-2026-73066 |
Tesseract: Heap out-of-bounds write in LSTM Convolve layer via crafted .traineddata |
11.08.2026 |
|
| CVE-2026-73067 |
Tesseract: Heap OOB read in the DAWG loader |
11.08.2026 |
|
| CVE-2026-17061 |
Deserialization of Untrusted Data Vulnerability in SIMULIA Execution Engine from Release 2023 through Release 2026 |
11.08.2026 |
10 |
| CVE-2026-18125 |
|
11.08.2026 |
7.5 |
| CVE-2026-18127 |
|
11.08.2026 |
7.7 |
| CVE-2026-18129 |
|
12.08.2026 |
8.1 |
| CVE-2026-18635 |
Velociraptor query plugin allows impersonation in other orgs |
11.08.2026 |
7.2 |
| CVE-2026-47702 |
TypeBot API tokens stored in plaintext |
11.08.2026 |
|
| CVE-2026-72920 |
SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control |
11.08.2026 |
9.8 |
| CVE-2026-72921 |
SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths |
11.08.2026 |
8.1 |
| CVE-2026-19434 |
Stored Cross-site Scripting in Pentestify finding severity field |
11.08.2026 |
|
| CVE-2026-19539 |
IDOR in Prospero Flow CRM allows cross-tenant ticket read, hijacking, and deletion |
11.08.2026 |
|
| CVE-2026-46670 |
YesWiki: Unauthenticated SQL Injection |
11.08.2026 |
9.8 |
| CVE-2026-48056 |
Streambert Vulnerable to Arbitrary Binary Execution via Downloader IPC Handler |
11.08.2026 |
10 |
| CVE-2026-51583 |
|
11.08.2026 |
|
| CVE-2026-51584 |
|
11.08.2026 |
|
| CVE-2026-73210 |
Server-Side Request Forgery via Favicon Retrieval in Lookyloo PlaywrightCapture |
11.08.2026 |
|
| CVE-2026-48046 |
Streambert Vulnerable to Remote Code Execution (RCE) via Unvalidated Auto-Updater IPC Handler |
11.08.2026 |
|
| CVE-2026-18972 |
Velociraptor authenticated identity-spoofing vulnerability |
11.08.2026 |
9.6 |
| CVE-2026-50058 |
|
11.08.2026 |
7.8 |
| CVE-2026-50059 |
|
11.08.2026 |
7.8 |
| CVE-2026-50060 |
|
11.08.2026 |
7.8 |
| CVE-2026-50061 |
|
11.08.2026 |
7.8 |
| CVE-2026-50062 |
|
11.08.2026 |
7.8 |
| CVE-2026-50063 |
|
11.08.2026 |
7.8 |
| CVE-2026-50064 |
|
11.08.2026 |
7.8 |
| CVE-2026-57262 |
|
11.08.2026 |
6.8 |
| CVE-2026-57263 |
|
11.08.2026 |
6.8 |
| CVE-2026-58115 |
|
11.08.2026 |
10 |
| CVE-2026-59086 |
|
11.08.2026 |
7.8 |
| CVE-2026-59693 |
|
11.08.2026 |
4.3 |
| CVE-2026-59700 |
|
11.08.2026 |
7.8 |
| CVE-2026-59701 |
|
11.08.2026 |
7.8 |
| CVE-2026-64629 |
|
11.08.2026 |
7.8 |
| CVE-2026-69108 |
|
11.08.2026 |
6 |
| CVE-2026-69109 |
|
11.08.2026 |
7.5 |
| CVE-2026-72779 |
Craft CMS 5.0.0-RC1 before 5.10.6 Arbitrary File Read via SplFileObject |
11.08.2026 |
|
| CVE-2026-72780 |
Craft CMS before 5.10.5 WebAuthn Assertion Replay via login-with-passkey |
11.08.2026 |
|
| CVE-2026-72781 |
Craft CMS 5.0.0-RC1 before 5.10.7 Remote Code Execution via Twig Sandbox Escape |
11.08.2026 |
|
| CVE-2026-72782 |
Craft CMS 5.0.0-RC1 before 5.10.6 Environment Variable Leak |
11.08.2026 |
|
| CVE-2026-72783 |
Craft CMS 5.0.0-RC1 before 5.10.6 Path Traversal via ensurePathIsContained |
11.08.2026 |
|
| CVE-2026-72784 |
Craft CMS 5.0.0-RC1 before 5.10.6 SSRF via GraphQL asset mutation |
11.08.2026 |
|
| CVE-2026-72785 |
Craft CMS before 5.10.6 Authorization Bypass via structures/move-element |
11.08.2026 |
|
| CVE-2026-72744 |
Nuxt before 4.5.1 Information Disclosure via Chrome DevTools |
11.08.2026 |
|
| CVE-2026-72745 |
FreeRDP before 3.30.0 Out-of-Bounds Read via Kerberos GSS Wrap-token EC |
11.08.2026 |
|
| CVE-2026-72746 |
FreeRDP before 3.30.0 RDSTLS Server Authentication Bypass via PDU-type Confusion |
11.08.2026 |
|
| CVE-2026-72747 |
AVideo Stored Cross-Site Scripting via Unauthenticated Registration |
11.08.2026 |
|
| CVE-2026-72748 |
AVideo Unauthenticated Arbitrary File Write via aVideoEncoderChunk.json.php |
11.08.2026 |
|
| CVE-2026-72749 |
n8n before 1.123.67 Prototype Pollution via Edit Fields |
11.08.2026 |
|
| CVE-2026-72750 |
n8n before 1.123.67 SQL Injection via executeQuery Operation |
11.08.2026 |
|
| CVE-2026-72762 |
n8n before 1.123.67 Arbitrary File Write via Edit Image Node |
11.08.2026 |
|
| CVE-2026-72763 |
n8n before 1.123.67 Credential Exfiltration via Sub-Workflow |
11.08.2026 |
|
| CVE-2026-72764 |
n8n before 1.123.67 Module Cache Poisoning via Code Node |
11.08.2026 |
|
| CVE-2026-72765 |
n8n before 2.32.1 Remote Code Execution via Expression Sandbox Escape |
11.08.2026 |
|
| CVE-2026-72766 |
n8n before 1.123.67 Arbitrary File Read via Send Email Node |
11.08.2026 |
|
| CVE-2026-72767 |
n8n before 1.123.67 Remote Code Execution via Git node |
11.08.2026 |
|
| CVE-2026-72768 |
n8n before 2.32.1 SSRF Protection Bypass via MCP Client |
11.08.2026 |
|
| CVE-2026-72769 |
n8n before 1.123.67 Prototype Pollution via VM Expression Engine |
11.08.2026 |
|
| CVE-2026-72770 |
n8n before 1.123.67 Path Traversal via Git Node Operations |
11.08.2026 |
|
| CVE-2026-72771 |
n8n before 2.32.1 Credential Restriction Bypass via AI/LLM Nodes |
11.08.2026 |
|
| CVE-2026-72772 |
n8n before 2.32.1 Authentication Bypass via Token Exchange |
11.08.2026 |
|
| CVE-2026-72773 |
n8n before 2.32.1 Path Traversal via computer-use search_files |
11.08.2026 |
|
| CVE-2026-72774 |
n8n before 1.123.67 Authentication Bypass via HTTP Request Node |
11.08.2026 |
|
| CVE-2026-72775 |
n8n before 1.123.67 SQL Injection via PostgresTrigger Node |
11.08.2026 |
|
| CVE-2026-72778 |
Craft CMS 5.0.0-RC1 before 5.10.6 Authenticated RCE via condition.config |
11.08.2026 |
|
| CVE-2026-50236 |
Openshift/console: authenticated ssrf with full response reflection and path neutralization via dev console webhook helpers in openshift console |
11.08.2026 |
|
| CVE-2026-50237 |
Openshift/console: namespace tenant ssrf with egress bypass, catalog poisoning, and admin-mediated supply chain escalation via projecthelmchartrepository in openshift console |
11.08.2026 |
|
| CVE-2026-72607 |
Koha Community Koha - Stored SQL Injection via agefield in Automatic Item Modifications by Age |
11.08.2026 |
7.1 |
| CVE-2026-72608 |
Koha Community Koha - Stored SQL Injection via Patron Card Layout image_name |
11.08.2026 |
6.5 |
| CVE-2026-72609 |
Koha Community Koha - SQL Injection via ORDER BY Direction in acqui/parcels.pl |
11.08.2026 |
7.1 |
| CVE-2026-72610 |
Koha Community Koha - Stored SQL Injection via Patron lang Field in Issue Slip Generation |
11.08.2026 |
4.3 |
| CVE-2026-13737 |
Command Restriction Bypass |
11.08.2026 |
|
| CVE-2026-13738 |
Improper Authorization Validation |
11.08.2026 |
|
| CVE-2026-13739 |
Server-Side Request Forgery (SSRF) |
11.08.2026 |
|
| CVE-2026-72533 |
Portainer Portainer CE - Authentication Bypass |
11.08.2026 |
8.8 |
| CVE-2026-72534 |
Authentik Security authentik - Privilege Escalation |
11.08.2026 |
8.8 |
| CVE-2026-72535 |
Chaskiq Chaskiq - Missing Authentication |
11.08.2026 |
8.2 |
| CVE-2026-72536 |
Chaskiq Chaskiq - Missing Authentication |
11.08.2026 |
8.2 |
| CVE-2026-72537 |
Authentik Security authentik - Privilege Escalation |
11.08.2026 |
8.8 |
| CVE-2026-72538 |
PrefectHQ Prefect - Argument Injection |
11.08.2026 |
8.8 |
| CVE-2026-72539 |
Windmill Labs Windmill - Information Disclosure |
11.08.2026 |
6.5 |
| CVE-2026-72540 |
PhotoPrism PhotoPrism - Insecure Direct Object Reference |
11.08.2026 |
4.3 |
| CVE-2026-72541 |
Windmill Labs Windmill - Missing Authorization |
11.08.2026 |
6.5 |
| CVE-2026-72542 |
Windmill Labs Windmill - Missing Authorization |
11.08.2026 |
5.4 |
| CVE-2026-72543 |
OpenSignLabs OpenSign - Insecure Direct Object Reference |
11.08.2026 |
7.5 |
| CVE-2026-72544 |
OpenSignLabs OpenSign - Insufficient Verification of Data Authenticity |
11.08.2026 |
7.5 |
| CVE-2026-72545 |
OpenSignLabs OpenSign - Insecure Direct Object Reference |
11.08.2026 |
7.5 |
| CVE-2026-72546 |
Attendize Attendize - Insecure Direct Object Reference |
11.08.2026 |
7.1 |
| CVE-2026-72547 |
Attendize Attendize - Insecure Direct Object Reference |
11.08.2026 |
7.1 |
| CVE-2026-72548 |
OpenSignLabs OpenSign - Information Disclosure |
11.08.2026 |
7.5 |
| CVE-2026-72549 |
OpenSignLabs OpenSign - Information Disclosure |
11.08.2026 |
5.3 |
| CVE-2026-72550 |
Friendica Friendica - SQL Injection |
11.08.2026 |
9.8 |
| CVE-2026-72551 |
Apioo Fusio - Remote Code Execution |
11.08.2026 |
8.8 |
| CVE-2026-72552 |
Dub Dub - Server-Side Request Forgery |
11.08.2026 |
7.5 |
| CVE-2026-72553 |
ElkArte Forum ElkArte - Cross-Site Scripting |
11.08.2026 |
5.4 |
| CVE-2026-72554 |
Ladybird Web Solution Faveo Helpdesk - Broken Access Control |
11.08.2026 |
6.5 |
| CVE-2026-72555 |
Peppermint Lab Peppermint - Broken Access Control |
11.08.2026 |
8.1 |
| CVE-2026-72556 |
ZoneMinder ZoneMinder - Remote Code Execution |
11.08.2026 |
8.8 |
| CVE-2026-72557 |
Cockpit CMS Cockpit CMS - Unrestricted File Upload |
11.08.2026 |
8.8 |
| CVE-2026-72558 |
CiviCRM CiviCRM - SQL Injection |
11.08.2026 |
8.8 |
| CVE-2026-72559 |
Daniel Brendel HortusFox - Cross-Site Scripting |
11.08.2026 |
5.4 |
| CVE-2026-72560 |
HumanSignal Label Studio - Server-Side Request Forgery |
11.08.2026 |
6.5 |
| CVE-2026-72561 |
Peppermint Lab Peppermint - Broken Access Control |
11.08.2026 |
8.8 |
| CVE-2026-72562 |
Pimcore pimcore admin-ui-classic-bundle - SQL Injection |
11.08.2026 |
8.8 |
| CVE-2026-72563 |
BadChoice Handesk - Broken Access Control |
11.08.2026 |
8.1 |
| CVE-2026-72595 |
BadChoice Handesk - Broken Access Control |
11.08.2026 |
8.1 |
| CVE-2026-72596 |
Ghost Foundation Ghost - Broken Access Control |
11.08.2026 |
8.1 |
| CVE-2026-72597 |
Friendica Friendica - Server-Side Request Forgery |
11.08.2026 |
6.5 |
| CVE-2026-72598 |
Apioo Fusio - Server-Side Request Forgery |
11.08.2026 |
6.5 |
| CVE-2026-72599 |
e107 e107 - SQL Injection |
11.08.2026 |
9.8 |
| CVE-2026-72600 |
Idurar IDURAR ERP CRM - Broken Access Control |
11.08.2026 |
7.5 |
| CVE-2026-72601 |
CSZ CMS CSZ CMS - Broken Access Control |
11.08.2026 |
7.5 |
| CVE-2026-72602 |
AsyncFuncAI deepwiki-open - Path Traversal |
11.08.2026 |
7.5 |
| CVE-2026-72603 |
wg-easy wg-easy - OS Command Injection |
11.08.2026 |
9.9 |
| CVE-2026-72604 |
Intelliants Subrion CMS - Path Traversal |
11.08.2026 |
6.5 |
| CVE-2026-72605 |
Swing Music Swing Music - Missing Authentication |
11.08.2026 |
7.5 |
| CVE-2026-72606 |
Pinry Pinry - Server-Side Request Forgery |
11.08.2026 |
7.5 |
| CVE-2026-58231 |
Improper Authorization in SAP Commerce Cloud (Data Hub Adapter) |
12.08.2026 |
10 |