Recent CVE entries
Stay updated about the Latest Security Vulnerabilities
Showing 500 CVEs published in the last 12 hours.
| CVE ID & CVSS | Description |
|---|---|
|
CVE-2026-63521
5.5 (Medium)
Show References |
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Published: August 11, 2026; 5:18:48 PM UTC
6 hours ago
|
|
CVE-2026-63520
8.1 (High)
Show References |
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Published: August 11, 2026; 5:18:47 PM UTC
6 hours ago
|
|
CVE-2026-63519
7.8 (High)
Show References |
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Published: August 11, 2026; 5:18:47 PM UTC
6 hours ago
|
|
CVE-2026-63518
7.8 (High)
Show References |
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Published: August 11, 2026; 5:18:47 PM UTC
6 hours ago
|
|
CVE-2026-63517
5.5 (Medium)
Show References |
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Published: August 11, 2026; 5:18:46 PM UTC
6 hours ago
|
|
CVE-2026-63516
6.5 (Medium)
Show References |
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Published: August 11, 2026; 5:18:46 PM UTC
6 hours ago
|
|
CVE-2026-63515
7.8 (High)
Show References |
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
Published: August 11, 2026; 5:18:46 PM UTC
6 hours ago
|
|
CVE-2026-63514
8.8 (High)
Show References |
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Published: August 11, 2026; 5:18:46 PM UTC
6 hours ago
|
|
CVE-2026-63513
7.8 (High)
Show References |
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
Published: August 11, 2026; 5:18:46 PM UTC
6 hours ago
|
|
CVE-2026-63512
6.5 (Medium)
Show References |
Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.
Published: August 11, 2026; 5:18:45 PM UTC
6 hours ago
|
|
CVE-2026-62917
4.6 (Medium)
Show References |
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Published: August 11, 2026; 5:18:45 PM UTC
6 hours ago
|
|
CVE-2026-62915
6.5 (Medium)
Show References |
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.
Published: August 11, 2026; 5:18:45 PM UTC
6 hours ago
|
|
CVE-2026-62914
7.3 (High)
Show References |
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
Published: August 11, 2026; 5:18:45 PM UTC
6 hours ago
|
|
CVE-2026-62913
8.8 (High)
Show References |
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
Published: August 11, 2026; 5:18:45 PM UTC
6 hours ago
|
|
CVE-2026-62912
6.5 (Medium)
Show References |
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.
Published: August 11, 2026; 5:18:45 PM UTC
6 hours ago
|
|
CVE-2026-62911
8 (High)
Show References |
Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Published: August 11, 2026; 5:18:45 PM UTC
6 hours ago
|
|
CVE-2026-62910
7.2 (High)
Show References |
Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Published: August 11, 2026; 5:18:44 PM UTC
6 hours ago
|
|
CVE-2026-62909
7.8 (High)
Show References |
Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:44 PM UTC
6 hours ago
|
|
CVE-2026-62908
7 (High)
Show References |
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:44 PM UTC
6 hours ago
|
|
CVE-2026-62902
6.5 (Medium)
Show References |
Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.
Published: August 11, 2026; 5:18:44 PM UTC
6 hours ago
|
|
CVE-2026-62901
7.5 (High)
Show References |
Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.
Published: August 11, 2026; 5:18:44 PM UTC
6 hours ago
|
|
CVE-2026-62900
5.9 (Medium)
Show References |
Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.
Published: August 11, 2026; 5:18:44 PM UTC
6 hours ago
|
|
CVE-2026-62899
5.9 (Medium)
Show References |
Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network.
Published: August 11, 2026; 5:18:44 PM UTC
6 hours ago
|
|
CVE-2026-62898
7.5 (High)
Show References |
Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.
Published: August 11, 2026; 5:18:43 PM UTC
6 hours ago
|
|
CVE-2026-62897
7 (High)
Show References |
Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.
Published: August 11, 2026; 5:18:43 PM UTC
6 hours ago
|
|
CVE-2026-62894
7.8 (High)
Show References |
Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:43 PM UTC
6 hours ago
|
|
CVE-2026-62893
9.8 (Critical)
Show References |
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
Published: August 11, 2026; 5:18:43 PM UTC
6 hours ago
|
|
CVE-2026-62892
7 (High)
Show References |
Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:42 PM UTC
6 hours ago
|
|
CVE-2026-62890
7.8 (High)
Show References |
Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally.
Published: August 11, 2026; 5:18:40 PM UTC
6 hours ago
|
|
CVE-2026-62889
8.1 (High)
Show References |
Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
Published: August 11, 2026; 5:18:40 PM UTC
6 hours ago
|
|
CVE-2026-62888
7.8 (High)
Show References |
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:40 PM UTC
6 hours ago
|
|
CVE-2026-62887
5.5 (Medium)
Show References |
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
Published: August 11, 2026; 5:18:39 PM UTC
6 hours ago
|
|
CVE-2026-62886
7.8 (High)
Show References |
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:39 PM UTC
6 hours ago
|
|
CVE-2026-62885
7.8 (High)
Show References |
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:39 PM UTC
6 hours ago
|
|
CVE-2026-62883
6.7 (Medium)
Show References |
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:39 PM UTC
6 hours ago
|
|
CVE-2026-62882
4.3 (Medium)
Show References |
Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
Published: August 11, 2026; 5:18:39 PM UTC
6 hours ago
|
|
CVE-2026-62881
6.7 (Medium)
Show References |
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:39 PM UTC
6 hours ago
|
|
CVE-2026-62880
7.8 (High)
Show References |
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:38 PM UTC
6 hours ago
|
|
CVE-2026-62878
9.8 (Critical)
Show References |
Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
Published: August 11, 2026; 5:18:38 PM UTC
6 hours ago
|
|
CVE-2026-62877
7.8 (High)
Show References |
Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:38 PM UTC
6 hours ago
|
|
CVE-2026-62876
7.8 (High)
Show References |
Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:38 PM UTC
6 hours ago
|
|
CVE-2026-62872
8.8 (High)
Show References |
Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.
Published: August 11, 2026; 5:18:37 PM UTC
6 hours ago
|
|
CVE-2026-62871
7.8 (High)
Show References |
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
Published: August 11, 2026; 5:18:37 PM UTC
6 hours ago
|
|
CVE-2026-62869
8.8 (High)
Show References |
Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network.
Published: August 11, 2026; 5:18:37 PM UTC
6 hours ago
|
|
CVE-2026-62842
5.5 (Medium)
Show References |
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
Published: August 11, 2026; 5:18:37 PM UTC
6 hours ago
|
|
CVE-2026-62839
6.5 (Medium)
Show References |
Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Published: August 11, 2026; 5:18:37 PM UTC
6 hours ago
|
|
CVE-2026-62837
6.5 (Medium)
Show References |
Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
Published: August 11, 2026; 5:18:37 PM UTC
6 hours ago
|
|
CVE-2026-62832
7.8 (High)
Show References |
Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:37 PM UTC
6 hours ago
|
|
CVE-2026-62829
4.6 (Medium)
Show References |
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Published: August 11, 2026; 5:18:36 PM UTC
6 hours ago
|
|
CVE-2026-62827
8.8 (High)
Show References |
Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Published: August 11, 2026; 5:18:36 PM UTC
6 hours ago
|
|
CVE-2026-62824
8.8 (High)
Show References |
Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Published: August 11, 2026; 5:18:36 PM UTC
6 hours ago
|
|
CVE-2026-62823
8.8 (High)
Show References |
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.
Published: August 11, 2026; 5:18:36 PM UTC
6 hours ago
|
|
CVE-2026-62822
8.8 (High)
Show References |
Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.
Published: August 11, 2026; 5:18:36 PM UTC
6 hours ago
|
|
CVE-2026-62820
8.1 (High)
Show References |
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network.
Published: August 11, 2026; 5:18:36 PM UTC
6 hours ago
|
|
CVE-2026-62819
8.1 (High)
Show References |
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
Published: August 11, 2026; 5:18:35 PM UTC
6 hours ago
|
|
CVE-2026-62818
8.8 (High)
Show References |
Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network.
Published: August 11, 2026; 5:18:35 PM UTC
6 hours ago
|
|
CVE-2026-62817
8.8 (High)
Show References |
Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network.
Published: August 11, 2026; 5:18:35 PM UTC
6 hours ago
|
|
CVE-2026-62816
8.8 (High)
Show References |
Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.
Published: August 11, 2026; 5:18:35 PM UTC
6 hours ago
|
|
CVE-2026-62815
9.8 (Critical)
Show References |
Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.
Published: August 11, 2026; 5:18:35 PM UTC
6 hours ago
|
|
CVE-2026-62814
6.5 (Medium)
Show References |
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
Published: August 11, 2026; 5:18:35 PM UTC
6 hours ago
|
|
CVE-2026-62812
7.8 (High)
Show References |
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:35 PM UTC
6 hours ago
|
|
CVE-2026-62811
7.8 (High)
Show References |
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:34 PM UTC
6 hours ago
|
|
CVE-2026-62807
7.8 (High)
Show References |
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:34 PM UTC
6 hours ago
|
|
CVE-2026-62803
7.8 (High)
Show References |
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:34 PM UTC
6 hours ago
|
|
CVE-2026-62800
8.8 (High)
Show References |
Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.
Published: August 11, 2026; 5:18:34 PM UTC
6 hours ago
|
|
CVE-2026-62799
7.8 (High)
Show References |
Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:34 PM UTC
6 hours ago
|
|
CVE-2026-62798
5.5 (Medium)
Show References |
Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally.
Published: August 11, 2026; 5:18:34 PM UTC
6 hours ago
|
|
CVE-2026-62797
7.8 (High)
Show References |
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:33 PM UTC
6 hours ago
|
|
CVE-2026-62796
5.5 (Medium)
Show References |
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
Published: August 11, 2026; 5:18:33 PM UTC
6 hours ago
|
|
CVE-2026-62795
8.8 (High)
Show References |
Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
Published: August 11, 2026; 5:18:33 PM UTC
6 hours ago
|
|
CVE-2026-62793
5.5 (Medium)
Show References |
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
Published: August 11, 2026; 5:18:33 PM UTC
6 hours ago
|
|
CVE-2026-62792
8.1 (High)
Show References |
Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
Published: August 11, 2026; 5:18:32 PM UTC
6 hours ago
|
|
CVE-2026-62790
8.8 (High)
Show References |
Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.
Published: August 11, 2026; 5:18:32 PM UTC
6 hours ago
|
|
CVE-2026-62788
7 (High)
Show References |
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:32 PM UTC
6 hours ago
|
|
CVE-2026-62787
7.5 (High)
Show References |
Use after free in Windows DNS allows an authorized attacker to execute code over a network.
Published: August 11, 2026; 5:18:32 PM UTC
6 hours ago
|
|
CVE-2026-62786
5.5 (Medium)
Show References |
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
Published: August 11, 2026; 5:18:32 PM UTC
6 hours ago
|
|
CVE-2026-62785
8.8 (High)
Show References |
Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
Published: August 11, 2026; 5:18:32 PM UTC
6 hours ago
|
|
CVE-2026-62784
8.8 (High)
Show References |
Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network.
Published: August 11, 2026; 5:18:31 PM UTC
6 hours ago
|
|
CVE-2026-62783
7.8 (High)
Show References |
Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:31 PM UTC
6 hours ago
|
|
CVE-2026-62782
6.5 (Medium)
Show References |
Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.
Published: August 11, 2026; 5:18:31 PM UTC
6 hours ago
|
|
CVE-2026-62781
8.1 (High)
Show References |
Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network.
Published: August 11, 2026; 5:18:31 PM UTC
6 hours ago
|
|
CVE-2026-62780
7 (High)
Show References |
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:31 PM UTC
6 hours ago
|
|
CVE-2026-62779
7.8 (High)
Show References |
Use after free in Windows Schannel allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:31 PM UTC
6 hours ago
|
|
CVE-2026-62778
8.1 (High)
Show References |
Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network.
Published: August 11, 2026; 5:18:30 PM UTC
6 hours ago
|
|
CVE-2026-62777
7.8 (High)
Show References |
Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:30 PM UTC
6 hours ago
|
|
CVE-2026-62776
7.8 (High)
Show References |
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:30 PM UTC
6 hours ago
|
|
CVE-2026-62775
5.5 (Medium)
Show References |
Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally.
Published: August 11, 2026; 5:18:30 PM UTC
6 hours ago
|
|
CVE-2026-62774
7 (High)
Show References |
Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:30 PM UTC
6 hours ago
|
|
CVE-2026-62773
7 (High)
Show References |
Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:30 PM UTC
6 hours ago
|
|
CVE-2026-62772
7.8 (High)
Show References |
Heap-based buffer overflow in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:29 PM UTC
6 hours ago
|
|
CVE-2026-62771
7.8 (High)
Show References |
Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:29 PM UTC
6 hours ago
|
|
CVE-2026-62770
7.8 (High)
Show References |
Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:29 PM UTC
6 hours ago
|
|
CVE-2026-62769
6.7 (Medium)
Show References |
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:29 PM UTC
6 hours ago
|
|
CVE-2026-62768
7.8 (High)
Show References |
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:29 PM UTC
6 hours ago
|
|
CVE-2026-62766
7 (High)
Show References |
Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:29 PM UTC
6 hours ago
|
|
CVE-2026-62761
7.8 (High)
Show References |
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:28 PM UTC
6 hours ago
|
|
CVE-2026-62758
7.8 (High)
Show References |
Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:28 PM UTC
6 hours ago
|
|
CVE-2026-62757
5.3 (Medium)
Show References |
Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.
Published: August 11, 2026; 5:18:28 PM UTC
6 hours ago
|
|
CVE-2026-62755
7.8 (High)
Show References |
Stack-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:28 PM UTC
6 hours ago
|
|
CVE-2026-62754
7.8 (High)
Show References |
Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:28 PM UTC
6 hours ago
|
|
CVE-2026-62753
7 (High)
Show References |
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:27 PM UTC
6 hours ago
|
|
CVE-2026-62752
7.8 (High)
Show References |
Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:27 PM UTC
6 hours ago
|
|
CVE-2026-62751
7.8 (High)
Show References |
Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:27 PM UTC
6 hours ago
|
|
CVE-2026-62750
6.5 (Medium)
Show References |
Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network.
Published: August 11, 2026; 5:18:27 PM UTC
6 hours ago
|
|
CVE-2026-62749
7 (High)
Show References |
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:27 PM UTC
6 hours ago
|
|
CVE-2026-62748
7 (High)
Show References |
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:27 PM UTC
6 hours ago
|
|
CVE-2026-62747
7.8 (High)
Show References |
Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:26 PM UTC
6 hours ago
|
|
CVE-2026-62746
5.5 (Medium)
Show References |
Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.
Published: August 11, 2026; 5:18:26 PM UTC
6 hours ago
|
|
CVE-2026-62745
6.5 (Medium)
Show References |
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
Published: August 11, 2026; 5:18:26 PM UTC
6 hours ago
|
|
CVE-2026-62743
5.5 (Medium)
Show References |
Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
Published: August 11, 2026; 5:18:26 PM UTC
6 hours ago
|
|
CVE-2026-62742
6.5 (Medium)
Show References |
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
Published: August 11, 2026; 5:18:26 PM UTC
6 hours ago
|
|
CVE-2026-62741
7.8 (High)
Show References |
Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:26 PM UTC
6 hours ago
|
|
CVE-2026-62740
5.5 (Medium)
Show References |
Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.
Published: August 11, 2026; 5:18:25 PM UTC
6 hours ago
|
|
CVE-2026-62739
7.8 (High)
Show References |
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:25 PM UTC
6 hours ago
|
|
CVE-2026-62738
5.5 (Medium)
Show References |
Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.
Published: August 11, 2026; 5:18:25 PM UTC
6 hours ago
|
|
CVE-2026-62737
7.8 (High)
Show References |
Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:25 PM UTC
6 hours ago
|
|
CVE-2026-62736
7.8 (High)
Show References |
Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:25 PM UTC
6 hours ago
|
|
CVE-2026-62735
7.8 (High)
Show References |
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:25 PM UTC
6 hours ago
|
|
CVE-2026-62734
7 (High)
Show References |
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:24 PM UTC
6 hours ago
|
|
CVE-2026-62733
7.8 (High)
Show References |
Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:24 PM UTC
6 hours ago
|
|
CVE-2026-62732
7.8 (High)
Show References |
Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:24 PM UTC
6 hours ago
|
|
CVE-2026-62730
5.5 (Medium)
Show References |
Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.
Published: August 11, 2026; 5:18:24 PM UTC
6 hours ago
|
|
CVE-2026-62729
7 (High)
Show References |
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:24 PM UTC
6 hours ago
|
|
CVE-2026-62728
7 (High)
Show References |
Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:23 PM UTC
6 hours ago
|
|
CVE-2026-62726
7 (High)
Show References |
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:23 PM UTC
6 hours ago
|
|
CVE-2026-62725
7 (High)
Show References |
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:23 PM UTC
6 hours ago
|
|
CVE-2026-62724
7 (High)
Show References |
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:23 PM UTC
6 hours ago
|
|
CVE-2026-62723
7 (High)
Show References |
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:23 PM UTC
6 hours ago
|
|
CVE-2026-62722
7.8 (High)
Show References |
Heap-based buffer overflow in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:23 PM UTC
6 hours ago
|
|
CVE-2026-62721
7.8 (High)
Show References |
Insufficient granularity of access control in User-Mode Power Service (UMPS) allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:22 PM UTC
6 hours ago
|
|
CVE-2026-62720
6.5 (Medium)
Show References |
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
Published: August 11, 2026; 5:18:22 PM UTC
6 hours ago
|
|
CVE-2026-62719
7.8 (High)
Show References |
Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:22 PM UTC
6 hours ago
|
|
CVE-2026-62718
6.5 (Medium)
Show References |
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
Published: August 11, 2026; 5:18:22 PM UTC
6 hours ago
|
|
CVE-2026-62717
7.8 (High)
Show References |
Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:22 PM UTC
6 hours ago
|
|
CVE-2026-62716
6.5 (Medium)
Show References |
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
Published: August 11, 2026; 5:18:21 PM UTC
6 hours ago
|
|
CVE-2026-62715
6.5 (Medium)
Show References |
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
Published: August 11, 2026; 5:18:21 PM UTC
6 hours ago
|
|
CVE-2026-62714
6.5 (Medium)
Show References |
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
Published: August 11, 2026; 5:18:21 PM UTC
6 hours ago
|
|
CVE-2026-62713
7.8 (High)
Show References |
Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:21 PM UTC
6 hours ago
|
|
CVE-2026-62712
7.8 (High)
Show References |
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:21 PM UTC
6 hours ago
|
|
CVE-2026-62711
7.8 (High)
Show References |
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:21 PM UTC
6 hours ago
|
|
CVE-2026-62710
7.8 (High)
Show References |
Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:20 PM UTC
6 hours ago
|
|
CVE-2026-62709
5.5 (Medium)
Show References |
Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.
Published: August 11, 2026; 5:18:20 PM UTC
6 hours ago
|
|
CVE-2026-62708
6.4 (Medium)
Show References |
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges with a physical attack.
Published: August 11, 2026; 5:18:20 PM UTC
6 hours ago
|
|
CVE-2026-62707
7.8 (High)
Show References |
Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:20 PM UTC
6 hours ago
|
|
CVE-2026-62705
7 (High)
Show References |
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:20 PM UTC
6 hours ago
|
|
CVE-2026-62703
5.5 (Medium)
Show References |
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
Published: August 11, 2026; 5:18:20 PM UTC
6 hours ago
|
|
CVE-2026-62702
6.8 (Medium)
Show References |
Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.
Published: August 11, 2026; 5:18:20 PM UTC
6 hours ago
|
|
CVE-2026-62701
7.8 (High)
Show References |
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:19 PM UTC
6 hours ago
|
|
CVE-2026-62700
7.8 (High)
Show References |
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:19 PM UTC
6 hours ago
|
|
CVE-2026-62699
6.8 (Medium)
Show References |
Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to execute code with a physical attack.
Published: August 11, 2026; 5:18:19 PM UTC
6 hours ago
|
|
CVE-2026-62698
7.8 (High)
Show References |
Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:19 PM UTC
6 hours ago
|
|
CVE-2026-62696
7.8 (High)
Show References |
Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:19 PM UTC
6 hours ago
|
|
CVE-2026-62695
7.8 (High)
Show References |
Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:18 PM UTC
6 hours ago
|
|
CVE-2026-62693
7 (High)
Show References |
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:18 PM UTC
6 hours ago
|
|
CVE-2026-62692
7.8 (High)
Show References |
Heap-based buffer overflow in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:18 PM UTC
6 hours ago
|
|
CVE-2026-62690
7 (High)
Show References |
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:18 PM UTC
6 hours ago
|
|
CVE-2026-62688
7.8 (High)
Show References |
Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:18 PM UTC
6 hours ago
|
|
CVE-2026-61939
7 (High)
Show References |
Use after free in Winlogon allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:18 PM UTC
6 hours ago
|
|
CVE-2026-61938
7 (High)
Show References |
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:17 PM UTC
6 hours ago
|
|
CVE-2026-61937
7.8 (High)
Show References |
Integer overflow or wraparound in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:17 PM UTC
6 hours ago
|
|
CVE-2026-61936
5.5 (Medium)
Show References |
Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.
Published: August 11, 2026; 5:18:17 PM UTC
6 hours ago
|
|
CVE-2026-61934
7.8 (High)
Show References |
Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:16 PM UTC
6 hours ago
|
|
CVE-2026-61933
5.5 (Medium)
Show References |
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
Published: August 11, 2026; 5:18:16 PM UTC
6 hours ago
|
|
CVE-2026-61932
7.8 (High)
Show References |
Access of resource using incompatible type ('type confusion') in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:16 PM UTC
6 hours ago
|
|
CVE-2026-61930
7.8 (High)
Show References |
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:15 PM UTC
6 hours ago
|
|
CVE-2026-61929
7 (High)
Show References |
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:15 PM UTC
6 hours ago
|
|
CVE-2026-61928
5.5 (Medium)
Show References |
Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.
Published: August 11, 2026; 5:18:15 PM UTC
6 hours ago
|
|
CVE-2026-61927
7 (High)
Show References |
Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:15 PM UTC
6 hours ago
|
|
CVE-2026-61926
7.8 (High)
Show References |
Heap-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:15 PM UTC
6 hours ago
|
|
CVE-2026-61925
7.8 (High)
Show References |
Incorrect authorization in Windows Installer allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:15 PM UTC
6 hours ago
|
|
CVE-2026-61924
6.5 (Medium)
Show References |
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
Published: August 11, 2026; 5:18:14 PM UTC
6 hours ago
|
|
CVE-2026-61923
7.8 (High)
Show References |
Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:14 PM UTC
6 hours ago
|
|
CVE-2026-61921
6.5 (Medium)
Show References |
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
Published: August 11, 2026; 5:18:14 PM UTC
6 hours ago
|
|
CVE-2026-61920
6.6 (Medium)
Show References |
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network.
Published: August 11, 2026; 5:18:14 PM UTC
6 hours ago
|
|
CVE-2026-61918
6.5 (Medium)
Show References |
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
Published: August 11, 2026; 5:18:13 PM UTC
6 hours ago
|
|
CVE-2026-61368
5 (Medium)
Show References |
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.
Published: August 11, 2026; 5:18:13 PM UTC
6 hours ago
|
|
CVE-2026-61367
7.8 (High)
Show References |
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:13 PM UTC
6 hours ago
|
|
CVE-2026-61366
7 (High)
Show References |
Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:12 PM UTC
6 hours ago
|
|
CVE-2026-61365
7.8 (High)
Show References |
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:11 PM UTC
6 hours ago
|
|
CVE-2026-61364
7.8 (High)
Show References |
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:11 PM UTC
6 hours ago
|
|
CVE-2026-61363
7.5 (High)
Show References |
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Published: August 11, 2026; 5:18:11 PM UTC
6 hours ago
|
|
CVE-2026-61361
7 (High)
Show References |
Use after free in Windows DHCP Client allows an authorized attacker to execute code locally.
Published: August 11, 2026; 5:18:11 PM UTC
6 hours ago
|
|
CVE-2026-61360
5.5 (Medium)
Show References |
Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.
Published: August 11, 2026; 5:18:10 PM UTC
6 hours ago
|
|
CVE-2026-61359
7.8 (High)
Show References |
Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:10 PM UTC
6 hours ago
|
|
CVE-2026-61358
7.8 (High)
Show References |
Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:10 PM UTC
6 hours ago
|
|
CVE-2026-61357
7.8 (High)
Show References |
Use after free in Application Information Services allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:10 PM UTC
6 hours ago
|
|
CVE-2026-61356
7.8 (High)
Show References |
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:10 PM UTC
6 hours ago
|
|
CVE-2026-61355
7.8 (High)
Show References |
Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:10 PM UTC
6 hours ago
|
|
CVE-2026-61353
7.8 (High)
Show References |
Heap-based buffer overflow in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:09 PM UTC
6 hours ago
|
|
CVE-2026-61352
7.5 (High)
Show References |
Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Published: August 11, 2026; 5:18:09 PM UTC
6 hours ago
|
|
CVE-2026-61350
4.6 (Medium)
Show References |
Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
Published: August 11, 2026; 5:18:09 PM UTC
6 hours ago
|
|
CVE-2026-61349
7.8 (High)
Show References |
Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:09 PM UTC
6 hours ago
|
|
CVE-2026-61348
7 (High)
Show References |
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:09 PM UTC
6 hours ago
|
|
CVE-2026-61347
5.5 (Medium)
Show References |
Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.
Published: August 11, 2026; 5:18:09 PM UTC
6 hours ago
|
|
CVE-2026-61346
7 (High)
Show References |
Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:08 PM UTC
6 hours ago
|
|
CVE-2026-61345
6.5 (Medium)
Show References |
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.
Published: August 11, 2026; 5:18:08 PM UTC
6 hours ago
|
|
CVE-2026-59138
6.5 (Medium)
Show References |
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.
Published: August 11, 2026; 5:18:08 PM UTC
6 hours ago
|
|
CVE-2026-59137
5.5 (Medium)
Show References |
Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.
Published: August 11, 2026; 5:18:08 PM UTC
6 hours ago
|
|
CVE-2026-59136
5.5 (Medium)
Show References |
Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.
Published: August 11, 2026; 5:18:08 PM UTC
6 hours ago
|
|
CVE-2026-59135
5.5 (Medium)
Show References |
Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.
Published: August 11, 2026; 5:18:07 PM UTC
6 hours ago
|
|
CVE-2026-59134
7.5 (High)
Show References |
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Published: August 11, 2026; 5:18:07 PM UTC
6 hours ago
|
|
CVE-2026-59133
8.8 (High)
Show References |
Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network.
Published: August 11, 2026; 5:18:07 PM UTC
6 hours ago
|
|
CVE-2026-59132
7.5 (High)
Show References |
Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.
Published: August 11, 2026; 5:18:07 PM UTC
6 hours ago
|
|
CVE-2026-59131
5.6 (Medium)
Show References |
No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.
Published: August 11, 2026; 5:18:07 PM UTC
6 hours ago
|
|
CVE-2026-59130
5.6 (Medium)
Show References |
No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.
Published: August 11, 2026; 5:18:07 PM UTC
6 hours ago
|
|
CVE-2026-59128
5.5 (Medium)
Show References |
Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.
Published: August 11, 2026; 5:18:06 PM UTC
6 hours ago
|
|
CVE-2026-59127
7.8 (High)
Show References |
Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:06 PM UTC
6 hours ago
|
|
CVE-2026-59126
7 (High)
Show References |
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:06 PM UTC
6 hours ago
|
|
CVE-2026-59125
7 (High)
Show References |
Use after free in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:06 PM UTC
6 hours ago
|
|
CVE-2026-59124
9.8 (Critical)
Show References |
Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.
Published: August 11, 2026; 5:18:06 PM UTC
6 hours ago
|
|
CVE-2026-59122
7 (High)
Show References |
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:06 PM UTC
6 hours ago
|
|
CVE-2026-59119
7.3 (High)
Show References |
Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:05 PM UTC
6 hours ago
|
|
CVE-2026-59113
8.8 (High)
Show References |
Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.
Published: August 11, 2026; 5:18:05 PM UTC
6 hours ago
|
|
CVE-2026-58651
7.8 (High)
Show References |
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Published: August 11, 2026; 5:18:05 PM UTC
6 hours ago
|
|
CVE-2026-58650
7.8 (High)
Show References |
Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
Published: August 11, 2026; 5:18:05 PM UTC
6 hours ago
|
|
CVE-2026-58641
7.8 (High)
Show References |
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:05 PM UTC
6 hours ago
|
|
CVE-2026-58639
6.5 (Medium)
Show References |
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Published: August 11, 2026; 5:18:05 PM UTC
6 hours ago
|
|
CVE-2026-58612
7.4 (High)
Show References |
Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.
Published: August 11, 2026; 5:18:04 PM UTC
6 hours ago
|
|
CVE-2026-57105
8 (High)
Show References |
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Published: August 11, 2026; 5:18:04 PM UTC
6 hours ago
|
|
CVE-2026-57104
8.8 (High)
Show References |
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network.
Published: August 11, 2026; 5:18:04 PM UTC
6 hours ago
|
|
CVE-2026-56179
8.3 (High)
Show References |
Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.
Published: August 11, 2026; 5:18:04 PM UTC
6 hours ago
|
|
CVE-2026-56174
7.8 (High)
Show References |
Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:04 PM UTC
6 hours ago
|
|
CVE-2026-54984
7.8 (High)
Show References |
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.
Published: August 11, 2026; 5:18:03 PM UTC
6 hours ago
|
|
CVE-2026-54981
7.8 (High)
Show References |
Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally.
Published: August 11, 2026; 5:18:03 PM UTC
6 hours ago
|
|
CVE-2026-54123
5.5 (Medium)
Show References |
Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information locally.
Published: August 11, 2026; 5:18:03 PM UTC
6 hours ago
|
|
CVE-2026-54113
7.5 (High)
Show References |
Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.
Published: August 11, 2026; 5:18:03 PM UTC
6 hours ago
|
|
CVE-2026-50516
9.4 (Critical)
Show References |
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
Published: August 11, 2026; 5:18:02 PM UTC
6 hours ago
|
|
CVE-2026-50472
7 (High)
Show References |
Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:18:02 PM UTC
6 hours ago
|
|
CVE-2026-49179
8.8 (High)
Show References |
Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.
Published: August 11, 2026; 5:18:02 PM UTC
6 hours ago
|
|
CVE-2026-48483
5.4 (Medium)
Show References |
TypeBot is a chatbot builder tool. Prior to version 3.17.0, Typebot's WhatsApp status forwarding feature stores a workspace-configured webhook forwarding URL and later POSTs WhatsApp marketing/error status events to it from the server. The stored URL is only validated as a generic URL in settings, but the forwarding code uses the raw `ky` instance instead of the repository's SSRF-protected `safeKy` client. A workspace user who can configure WhatsApp settings can therefore make the Typebot server issue HTTP requests to internal services, private-network hosts, localhost, or metadata-style endpoints whenever the public WhatsApp production webhook receives a status payload that should be forwarded. Version 3.17.0 patches the issue.
Published: August 11, 2026; 5:18:02 PM UTC
6 hours ago
|
|
|
|
CVE-2026-48446
5.5 (Medium)
Show References |
CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.
Published: August 11, 2026; 5:18:01 PM UTC
6 hours ago
|
|
CVE-2026-48445
6.2 (Medium)
Show References |
CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Published: August 11, 2026; 5:18:01 PM UTC
6 hours ago
|
|
CVE-2026-48444
6.2 (Medium)
Show References |
CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Published: August 11, 2026; 5:18:01 PM UTC
6 hours ago
|
|
CVE-2026-48443
6.2 (Medium)
Show References |
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.
Published: August 11, 2026; 5:18:01 PM UTC
6 hours ago
|
|
CVE-2026-48442
7.1 (High)
Show References |
CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Arbitrary file system read. An attacker could leverage this vulnerability to gain unauthorized read access to files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction. Scope is changed.
Published: August 11, 2026; 5:18:01 PM UTC
6 hours ago
|
|
CVE-2026-48440
8.1 (High)
Show References |
ColdFusion is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.
Published: August 11, 2026; 5:18:01 PM UTC
6 hours ago
|
|
CVE-2026-48439
7.5 (High)
Show References |
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.
Published: August 11, 2026; 5:18:01 PM UTC
6 hours ago
|
|
CVE-2026-48438
7.5 (High)
Show References |
CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Published: August 11, 2026; 5:18:01 PM UTC
6 hours ago
|
|
CVE-2026-48437
5.5 (Medium)
Show References |
CAI Content Credentials is affected by an Improper Certificate Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.
Published: August 11, 2026; 5:18:00 PM UTC
6 hours ago
|
|
CVE-2026-48436
6.5 (Medium)
Show References |
CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.
Published: August 11, 2026; 5:18:00 PM UTC
6 hours ago
|
|
CVE-2026-48435
6.2 (Medium)
Show References |
CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Published: August 11, 2026; 5:18:00 PM UTC
6 hours ago
|
|
CVE-2026-48434
6.2 (Medium)
Show References |
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.
Published: August 11, 2026; 5:18:00 PM UTC
6 hours ago
|
|
CVE-2026-48387
6.2 (Medium)
Show References |
CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Published: August 11, 2026; 5:18:00 PM UTC
6 hours ago
|
|
CVE-2026-48386
7.5 (High)
Show References |
ColdFusion is affected by a Use of a Broken or Risky Cryptographic Algorithm vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue does not require user interaction.
Published: August 11, 2026; 5:18:00 PM UTC
6 hours ago
|
|
CVE-2026-48385
7.7 (High)
Show References |
ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction. Scope is changed.
Published: August 11, 2026; 5:18:00 PM UTC
6 hours ago
|
|
CVE-2026-48384
4.9 (Medium)
Show References |
ColdFusion is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker with high privileges could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Published: August 11, 2026; 5:18:00 PM UTC
6 hours ago
|
|
CVE-2026-48376
5.4 (Medium)
Show References |
is affected by an Improper Encoding or Escaping of Output vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction.
Published: August 11, 2026; 5:17:59 PM UTC
6 hours ago
|
|
CVE-2026-48375
6.5 (Medium)
Show References |
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in an application denial-of-service. A low-privileged attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.
Published: August 11, 2026; 5:17:59 PM UTC
6 hours ago
|
|
CVE-2026-48362
10 (Critical)
Show References |
ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Published: August 11, 2026; 5:17:59 PM UTC
6 hours ago
|
|
CVE-2026-47922
4.7 (Medium)
Show References |
CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
Published: August 11, 2026; 5:17:59 PM UTC
6 hours ago
|
|
CVE-2026-47704
7.1 (High)
Show References |
TypeBot is a chatbot builder tool. Prior to version 3.17.0, an authenticated user who has read access to any typebot can resume a waiting webhook session that belongs to a different typebot by mixing an authorized `typebotId` and `blockId` and a foreign live `resultId`. The webhook resume handler authorizes the parent typebot first, but then resolves the descendant `result` only by `resultId`. As a result, an attacker can inject arbitrary webhook JSON into another typebot's suspended session and advance its execution without any access to the victim typebot. Version 3.17.0 patches the issue.
Published: August 11, 2026; 5:17:59 PM UTC
6 hours ago
|
|
|
|
CVE-2026-47299
7.2 (High)
Show References |
Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network.
Published: August 11, 2026; 5:17:59 PM UTC
6 hours ago
|
|
CVE-2026-47285
6.5 (Medium)
Show References |
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose information over a network.
Published: August 11, 2026; 5:17:58 PM UTC
6 hours ago
|
|
CVE-2026-43606
8.5 (High)
Show References |
Observable Timing Discrepancy in the AMD Vitis Libraries ECDSA secp256k1 component could allow attackers with local access to potentially perform timing analysis or electromagnetic emanation attacks, resulting in high confidentiality and integrity impact due to the exposure of private cryptographic keys.
Published: August 11, 2026; 5:17:58 PM UTC
6 hours ago
|
|
CVE-2026-42976
7.8 (High)
Show References |
Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.
Published: August 11, 2026; 5:17:58 PM UTC
6 hours ago
|
|
CVE-2026-40375
6.5 (Medium)
Show References |
Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.
Published: August 11, 2026; 5:17:58 PM UTC
6 hours ago
|
|
CVE-2026-39452
6.3 (Medium)
Show References |
Protection mechanism failure for some Intel(R) Transfer Learning Tool before version v0.7 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via network access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:58 PM UTC
6 hours ago
|
|
CVE-2026-35502
4.6 (Medium)
Show References |
Deserialization of untrusted data for some Intel(R) Extension for PyTorch before version 2.8.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:58 PM UTC
6 hours ago
|
|
CVE-2026-34635
8.4 (High)
Show References |
is affected by a Use of Hard-coded Cryptographic Key vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction. Scope is changed.
Published: August 11, 2026; 5:17:57 PM UTC
6 hours ago
|
|
CVE-2026-34175
5.4 (Medium)
Show References |
Uncontrolled search path for some Hardware-Aware-Automated-MachineLearning NA before version 45cd723 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:57 PM UTC
6 hours ago
|
|
CVE-2026-32791
5.4 (Medium)
Show References |
Untrusted search path for some Intel(R) Performance Counter Monitor (Intel(R) PCM) before version tag 202604 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:57 PM UTC
6 hours ago
|
|
CVE-2026-32788
5.4 (Medium)
Show References |
Uncontrolled search path for some Approximate Bayesian Inference Framework before version on commit #484c949 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:57 PM UTC
6 hours ago
|
|
CVE-2026-32677
5.4 (Medium)
Show References |
Path traversal for some gaudi-container-runtime before version 1.24.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:57 PM UTC
6 hours ago
|
|
CVE-2026-28757
5.4 (Medium)
Show References |
Protection mechanism failure for some Intel(R) Workload Services Framework software within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:57 PM UTC
6 hours ago
|
|
CVE-2026-28729
2.4 (Low)
Show References |
Integer overflow in the UEFI firmware for the Intel(R) Slim Bootloader may allow an information disclosure. System software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the confidentiality (low), integrity (none) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (none) and availability (low) impacts.
Published: August 11, 2026; 5:17:57 PM UTC
6 hours ago
|
|
CVE-2026-28707
5.4 (Medium)
Show References |
Protection mechanism failure for some LLM-on-Ray before version 1.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:56 PM UTC
6 hours ago
|
|
CVE-2026-28700
5.4 (Medium)
Show References |
Uncontrolled search path for some EquiTriton before version f5ddbb5 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:56 PM UTC
6 hours ago
|
|
CVE-2026-27765
6.8 (Medium)
Show References |
Improper input validation for some vLLM Hardware Plugin for Intel(R) Gaudi(R) software before version 0.16.0 within Ring 3: User Applications may allow a denial of service. Authorized adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:56 PM UTC
6 hours ago
|
|
CVE-2026-25652
7.8 (High)
Show References |
is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain unauthorized read and write access. Exploitation of this issue does not require user interaction.
Published: August 11, 2026; 5:17:56 PM UTC
6 hours ago
|
|
CVE-2026-25194
1.8 (Low)
Show References |
Out-of-bounds write in the firmware for the Intel(R) Slim Bootloader may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:56 PM UTC
6 hours ago
|
|
CVE-2026-24911
8.3 (High)
Show References |
Stack-based buffer overflow for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0: Kernel may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (high) impacts.
Published: August 11, 2026; 5:17:56 PM UTC
6 hours ago
|
|
CVE-2026-24693
5.4 (Medium)
Show References |
Protection mechanism failure for some Intel(R) oneCCL Bindings for PyTorch before version v2.8.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:56 PM UTC
6 hours ago
|
|
CVE-2026-24099
5.9 (Medium)
Show References |
Use after free for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0: Kernel may allow a denial of service. System software adversary with an unauthenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:55 PM UTC
6 hours ago
|
|
CVE-2026-22887
8.3 (High)
Show References |
Improper buffer restrictions for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0: Kernel may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (high) impacts.
Published: August 11, 2026; 5:17:55 PM UTC
6 hours ago
|
|
CVE-2026-21400
5.4 (Medium)
Show References |
Protection mechanism failure for some Intel(R) AI Reference Models before version v3.4.1 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:55 PM UTC
6 hours ago
|
|
CVE-2026-21399
6.9 (Medium)
Show References |
Heap-based buffer overflow for the Intel(R) Open Volume Kernel Library (Intel(R) Open VKL) library maintained by intel(R) before version 2.0.2 within Ring 3: User Applications may allow a denial of service. System software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:55 PM UTC
6 hours ago
|
|
CVE-2026-21387
5.4 (Medium)
Show References |
Protection mechanism failure for some Intel(R) LLM Library for PyTorch within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:55 PM UTC
6 hours ago
|
|
CVE-2026-21279
8.2 (High)
Show References |
is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and limited write access. Exploitation of this issue does not require user interaction.
Published: August 11, 2026; 5:17:55 PM UTC
6 hours ago
|
|
CVE-2026-21273
8.7 (High)
Show References |
is affected by an Improper Input Validation vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain unauthorized read and write access. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Published: August 11, 2026; 5:17:55 PM UTC
6 hours ago
|
|
CVE-2026-21269
4.6 (Medium)
Show References |
is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.
Published: August 11, 2026; 5:17:55 PM UTC
6 hours ago
|
|
CVE-2026-20913
4.8 (Medium)
Show References |
Improper input validation for some Intel(R) Neural Compressor software before version v3.7 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:54 PM UTC
6 hours ago
|
|
CVE-2026-20908
5.8 (Medium)
Show References |
Time-of-check time-of-use race condition for the Intel(R) NPU Driver for Windows for all versions within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:54 PM UTC
6 hours ago
|
|
CVE-2026-20906
5.4 (Medium)
Show References |
Protection mechanism failure for some Intel(R) Neural Compressor software before version v3.6 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:54 PM UTC
6 hours ago
|
|
CVE-2026-20903
5.4 (Medium)
Show References |
Protection mechanism failure for some Intel(R) AI Containers before version v0.4.0 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:54 PM UTC
6 hours ago
|
|
CVE-2026-20898
8.5 (High)
Show References |
Improper access control in the firmware for some in Alias Checking Trusted Module for some Intel(R) Xeon(R) processors may allow an escalation of privilege. Startup code and SMM adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts.
Published: August 11, 2026; 5:17:54 PM UTC
6 hours ago
|
|
CVE-2026-20891
6.3 (Medium)
Show References |
Improper authentication for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable local code execution. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (low) and availability (low) impacts.
Published: August 11, 2026; 5:17:54 PM UTC
6 hours ago
|
|
CVE-2026-20890
7.1 (High)
Show References |
Improper privilege management for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Privileged Process may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (low) and availability (high) impacts.
Published: August 11, 2026; 5:17:54 PM UTC
6 hours ago
|
|
CVE-2026-20886
6.9 (Medium)
Show References |
Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (low) impacts.
Published: August 11, 2026; 5:17:53 PM UTC
6 hours ago
|
|
CVE-2026-20885
7 (High)
Show References |
Improper authentication in the Intel(R) TDX module for some Intel(R) platforms within Ring 0: Trust Domain may allow an information disclosure and escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (low) and availability (none) impacts.
Published: August 11, 2026; 5:17:53 PM UTC
6 hours ago
|
|
CVE-2026-20878
7.1 (High)
Show References |
Null pointer dereference for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (low) impacts.
Published: August 11, 2026; 5:17:53 PM UTC
6 hours ago
|
|
CVE-2026-20799
5.4 (Medium)
Show References |
Untrusted search path for some Battery Life Diagnostic Tool software before version 2.9.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present with special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:53 PM UTC
6 hours ago
|
|
CVE-2026-20795
7.1 (High)
Show References |
Improper buffer restrictions for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (low) impacts.
Published: August 11, 2026; 5:17:53 PM UTC
6 hours ago
|
|
CVE-2026-20789
8.4 (High)
Show References |
Improper access control for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable local code execution. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (low) and availability (low) impacts.
Published: August 11, 2026; 5:17:53 PM UTC
6 hours ago
|
|
CVE-2026-20787
7.1 (High)
Show References |
Null pointer dereference for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (low) impacts.
Published: August 11, 2026; 5:17:53 PM UTC
6 hours ago
|
|
CVE-2026-20786
6.9 (Medium)
Show References |
Out-of-bounds read for the Intel(R) NPU Driver for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:53 PM UTC
6 hours ago
|
|
CVE-2026-20783
6.9 (Medium)
Show References |
Improper conditions check in the firmware for the Intel(R) NPU Driver for all versions within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:52 PM UTC
6 hours ago
|
|
CVE-2026-20780
6.9 (Medium)
Show References |
Uncontrolled resource consumption for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (low) impacts.
Published: August 11, 2026; 5:17:52 PM UTC
6 hours ago
|
|
CVE-2026-20778
7 (High)
Show References |
Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0: Kernel may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur via adjacent access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (high) impacts.
Published: August 11, 2026; 5:17:52 PM UTC
6 hours ago
|
|
CVE-2026-20776
8.3 (High)
Show References |
Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (high) impacts.
Published: August 11, 2026; 5:17:52 PM UTC
6 hours ago
|
|
CVE-2026-20775
6.8 (Medium)
Show References |
Uncaught exception for some Intel(R) TDX modules within Ring 0: Trust Domain may allow a denial of service. System software adversary with a privileged user combined with a high complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (high) impacts.
Published: August 11, 2026; 5:17:52 PM UTC
6 hours ago
|
|
CVE-2026-20770
5.4 (Medium)
Show References |
Protection mechanism failure for some Cluster Management Toolkit for Kubernetes software before version v0.8.5 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:52 PM UTC
6 hours ago
|
|
CVE-2026-20769
6.9 (Medium)
Show References |
Improper conditions check for the Intel(R) NPU Driver for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:52 PM UTC
6 hours ago
|
|
CVE-2026-20765
4.6 (Medium)
Show References |
Incorrect comparison for some Intel(R) TDX Guest software before version 0.3.1 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:51 PM UTC
6 hours ago
|
|
CVE-2026-20763
4.6 (Medium)
Show References |
Incorrect calculation for some Intel(R) TDX Guest software before version 0.3.1 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:51 PM UTC
6 hours ago
|
|
CVE-2026-20760
6.8 (Medium)
Show References |
Improper handling of overlap between protected memory ranges in some microcode for some Intel(R) Processors within Ring 0: Hypervisor may allow an escalation of privilege. Authorized adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:51 PM UTC
6 hours ago
|
|
CVE-2026-20755
5.4 (Medium)
Show References |
Protection mechanism failure for some LLM Scaler software within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:51 PM UTC
6 hours ago
|
|
CVE-2026-20752
6.7 (Medium)
Show References |
Improper authentication for some Intel(R) PROSet/Wireless WiFi Software within Ring 0: Kernel may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:51 PM UTC
6 hours ago
|
|
CVE-2026-20749
7.2 (High)
Show References |
Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow an escalation of privilege. Network adversary with an unauthenticated user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (low) and availability (low) impacts.
Published: August 11, 2026; 5:17:51 PM UTC
6 hours ago
|
|
CVE-2026-20747
7.1 (High)
Show References |
Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:51 PM UTC
6 hours ago
|
|
CVE-2026-20745
7.1 (High)
Show References |
Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (low) impacts.
Published: August 11, 2026; 5:17:51 PM UTC
6 hours ago
|
|
CVE-2026-20741
8.3 (High)
Show References |
Improper access control for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (low) and availability (high) impacts.
Published: August 11, 2026; 5:17:50 PM UTC
6 hours ago
|
|
CVE-2026-20739
7.1 (High)
Show References |
Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (low) impacts.
Published: August 11, 2026; 5:17:50 PM UTC
6 hours ago
|
|
CVE-2026-20737
6.3 (Medium)
Show References |
Exposure of sensitive information to an unauthorized actor for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable local code execution. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (low) and availability (low) impacts.
Published: August 11, 2026; 5:17:50 PM UTC
6 hours ago
|
|
CVE-2026-20734
5.6 (Medium)
Show References |
Improper initialization in some firmware for some Intel(R) Active Management Technology (Intel(R) AMT), and some Intel(R) Standard Manageability may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:50 PM UTC
6 hours ago
|
|
CVE-2026-20731
6.9 (Medium)
Show References |
Improper buffer restrictions for the Intel(R) NPU Driver for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:50 PM UTC
6 hours ago
|
|
CVE-2026-20728
5.4 (Medium)
Show References |
Protection mechanism failure for some Intel Extension for TensorFlow software before version 2.15.0.3 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:50 PM UTC
6 hours ago
|
|
CVE-2026-20727
8.3 (High)
Show References |
Null pointer dereference for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0: Kernel may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (high) impacts.
Published: August 11, 2026; 5:17:50 PM UTC
6 hours ago
|
|
CVE-2026-20716
7.2 (High)
Show References |
Improper access control for some Intel(R) Processors within Ring 3: User Applications may allow an escalation of privilege. Simple hardware adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:49 PM UTC
6 hours ago
|
|
CVE-2026-20715
8.2 (High)
Show References |
Improper input validation in some firmware for some Intel(R) Active Management Technology (Intel(R) AMT) and some Intel(R) Standard Manageability may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via network access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:49 PM UTC
6 hours ago
|
|
CVE-2026-20713
4.5 (Medium)
Show References |
Always-incorrect control flow implementation in some firmware for some Intel(R) Xeon(R) processors may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts.
Published: August 11, 2026; 5:17:49 PM UTC
6 hours ago
|
|
CVE-2026-20708
5.9 (Medium)
Show References |
Insertion of sensitive information into log file in the subsystem for the Intel(R) AMT and Intel(R) Standard Manageability may allow an information disclosure. Network adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via network access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:49 PM UTC
6 hours ago
|
|
CVE-2026-20707
6.8 (Medium)
Show References |
Hardware logic contains race conditions for some 3rd Gen Intel(R) Xeon(R) Scalable Processors within Ring 3: unprivileged software may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (high) impacts.
Published: August 11, 2026; 5:17:49 PM UTC
6 hours ago
|
|
CVE-2026-20705
6.8 (Medium)
Show References |
Insecure storage of sensitive information in the Intel(R) TDX module for some Intel(R) platform within Ring 0: Trust Domain may allow information disclosure. System software adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:49 PM UTC
6 hours ago
|
|
CVE-2026-20702
8.9 (High)
Show References |
Protection mechanism failure for some Intel(R) Data Center Attestation Primitives (Intel(R) DCAP) may allow information disclosure. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable data exposure. This result may potentially occur via network access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:49 PM UTC
6 hours ago
|
|
CVE-2026-20349
8.6 (High)
Show References |
A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.
This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.
Published: August 11, 2026; 5:17:48 PM UTC
6 hours ago
|
|
CVE-2026-18247
5.3 (Medium)
Show References |
A Cross Site Scripting (XSS) vulnerability in the Web Portals of AtHoc IWS in versions earlier than 7.21 HF-734 could allow an attacker to potentially execute actions in the context of the victim's session.
Published: August 11, 2026; 5:17:48 PM UTC
6 hours ago
|
|
CVE-2026-12571
9.8 (Critical)
Show References |
An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.
Published: August 11, 2026; 5:17:46 PM UTC
6 hours ago
|
|
CVE-2025-8087
7 (High)
Show References |
A DLL hijacking vulnerability in AMD Power Design Manager could allow a malicious local attacker to escalate privileges during the uninstallation process, potentially resulting in arbitrary code execution.
Published: August 11, 2026; 5:17:44 PM UTC
6 hours ago
|
|
CVE-2025-61970
1 (Low)
Show References |
Weak permissions in the Vitisâ„¢ Unified installation path on local Windows machines could allow a low-privileged user to create arbitrary code, potentially resulting in binary hijacking.
Published: August 11, 2026; 5:17:44 PM UTC
6 hours ago
|
|
CVE-2025-48506
4.6 (Medium)
Show References |
Uncontrolled search paths in Vitisâ„¢ Unified installation path on local Windows machines could allow DLL injection into these install paths, potentially resulting in arbitrary code execution.
Published: August 11, 2026; 5:17:44 PM UTC
6 hours ago
|
|
CVE-2025-48505
1 (Low)
Show References |
Weak permissions in the Vitisâ„¢ Unified installation path on local Windows machines could allow a low-privileged user to achieve privileged escalation, potentially resulting in arbitrary code execution.
Published: August 11, 2026; 5:17:44 PM UTC
6 hours ago
|
|
CVE-2025-35987
4.3 (Medium)
Show References |
Omission of security-relevant information for some Intel(R) Software Guard Extensions Data Center Attestation Primitives within Ring 0: Kernel may allow a denial of service. Authorized adversary with a privileged user combined with a high complexity attack may enable data alteration. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (high) and availability (low) impacts.
Published: August 11, 2026; 5:17:43 PM UTC
6 hours ago
|
|
CVE-2025-35973
4.5 (Medium)
Show References |
Improper handling of values for some Intel(R) Processors within Ring 0: Kernel, Hypervisor and Bare Metal OS may allow an escalation of privilege. Authorized adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and require no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts.
Published: August 11, 2026; 5:17:43 PM UTC
6 hours ago
|
|
CVE-2025-31938
4.3 (Medium)
Show References |
Insufficient granularity of access control in some subsystem for some Intel(R) Xeon(R) 6 Scalable processors with Intel(R) TDX may allow an information disclosure. Authorized adversary with an authenticated user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:43 PM UTC
6 hours ago
|
|
CVE-2025-31936
7 (High)
Show References |
Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R) TDX within SMM may allow an escalation of privilege. SMM adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
Published: August 11, 2026; 5:17:43 PM UTC
6 hours ago
|
|
CVE-2025-31356
5.6 (Medium)
Show References |
Insufficient verification of data authenticity for some Intel(R) Trust Domain Extensions (Intel(R) TDX) within Ring 0: Hypervisor may allow an information disclosure. A system software adversary with a privileged user access combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without any user interaction. The potential vulnerability may impact the confidentiality (high), integrity (low) and no effect on availability. Subsequent system impacts include reduced confidentiality (low), integrity (low), and no effect on availability.
Published: August 11, 2026; 5:17:43 PM UTC
6 hours ago
|
|
CVE-2025-0041
4.6 (Medium)
Show References |
Uncontrolled search paths in the Vitisâ„¢ Embedded Single File Download (SFD) for local Windows installation could allow a low-privileged user to create arbitrary code execution.
Published: August 11, 2026; 5:17:42 PM UTC
6 hours ago
|
|
CVE-2026-9214
4.3 (Medium)
Show References |
Insufficient input validation vulnerability in the NETGEAR R7000 models
allows authenticated administrators connected to the local network to
make unauthorized modification to router software and functionality.
Published: August 11, 2026; 4:17:40 PM UTC
7 hours ago
|
|
CVE-2026-73080
9.3 (Critical)
Show References |
SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_remote.go fetches a caller-supplied remote endpoint through weed/remote_storage/s3/s3_storage_client.go and writes the response into a needle. The RPC performs no authentication and no target validation, allowing anyone who can reach a volume server's gRPC port to cause requests to arbitrary hosts, including loopback, link-local, RFC 1918, and cloud metadata endpoints such as 169.254.169.254, and read the response. On cloud deployments, this can disclose instance metadata and IAM credentials and reach otherwise unexposed internal services. The volume server gRPC plane is unauthenticated by default, and configuring documented JWT signing keys does not protect this RPC. This issue is fixed in version 4.24.
Published: August 11, 2026; 4:17:39 PM UTC
7 hours ago
|
|
|
|
CVE-2026-73079
8.5 (High)
Show References |
Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. From 0.1.135, to 0.1.168, platform API keys issued to tenants are exchanged for upstream requests made with shared provider accounts (ChatGPT/Codex OAuth, OpenAI platform keys, or an operator-configured base URL) that belong to the operator, not to the caller. The `POST /responses/*subpath` wildcard routes spliced the client-supplied subpath into the upstream URL with no validation. This lets an authenticated tenant relay requests to arbitrary upstream endpoints using pooled account credentials via a path traversal. This vulnerability is fixed in 0.1.169.
Published: August 11, 2026; 4:17:39 PM UTC
7 hours ago
|
|
|
|
CVE-2026-73078
8.6 (High)
Show References |
Vim is an open source, command line text editor. Prior to 9.2.0840, runtime/plugin/netrwPlugin.vim loads netrw and runtime/pack/dist/opt/netrw/autoload/netrw.vim constructs Bookmarks, History, and Targets menu entries by interpolating attacker-controlled directory paths into executed :menu commands. s:NetrwBookmarkMenu(), s:NetrwTgtMenu(), g:netrw_menu_escape, EX_TRLBAR, and netrw#MakeTgt() fail to neutralize the | command separator or single quotes at five construction sites, allowing a crafted path browsed or bookmarked in GUI Vim to execute arbitrary Ex and operating-system commands. This issue is fixed in version 9.2.0840.
Published: August 11, 2026; 4:17:39 PM UTC
7 hours ago
|
|
CVE-2026-73077
8.4 (High)
Show References |
Vim is an open source, command line text editor. Prior to 9.2.0839, the runtime/ftplugin/sh.vim, runtime/ftplugin/zsh.vim, and runtime/ftplugin/ps1.vim filetype plugins pass attacker-controlled Visual-mode selections from K through keywordprg commands without safely separating shell arguments. fnameescape() and PATH_ESC_CHARS do not neutralize shell metacharacters before ShKeywordPrg, ZshKeywordPrg, or GetHelp invokes bash, zsh, or PowerShell, allowing arbitrary operating-system commands to execute with the privileges of the user running Vim. This issue is fixed in version 9.2.0839.
Published: August 11, 2026; 4:17:39 PM UTC
7 hours ago
|
|
CVE-2026-73076
8.4 (High)
Show References |
Vim is an open source, command line text editor. Prior to 9.2.0847, runtime/autoload/vimball.vim allows a crafted vimball member named .VimballRecord to overwrite the installation record with attacker-chosen commands. When vimball#RmVimball() later processes the matching record entry, the stored Ex commands, including operating-system commands invoked through :!, execute with the privileges of the user running Vim. This issue is fixed in version 9.2.0847.
Published: August 11, 2026; 4:17:38 PM UTC
7 hours ago
|
|
CVE-2026-73075
4.6 (Medium)
Show References |
Vim is an open source, command line text editor. From 9.2.0469 until 9.2.0843, popup_mark_opacity_zindex() in src/popupwin.c can use a negative w_winrow for a text-property-anchored popup with clipwindow and opacity, indexing before the screen array instead of accounting for w_popup_topoff and causing an out-of-bounds read and conditional write. This issue is fixed in version 9.2.0843.
Published: August 11, 2026; 4:17:38 PM UTC
7 hours ago
|
|
|
|
CVE-2026-73074
7.1 (High)
Show References |
Vim is an open source, command line text editor. Prior to 9.2.0841, prop_add_one() in src/textprop.c uses the proplen value from get_text_props() to increment a uint16_t property count beyond 0xffff, wrapping the count to zero and copying existing text-property records into a heap allocation sized for none of them. This issue is fixed in version 9.2.0841.
Published: August 11, 2026; 4:17:38 PM UTC
7 hours ago
|
|
CVE-2026-73072
8.5 (High)
Show References |
Vim is an open source, command line text editor. Prior to 9.2.0846, set_sofo() in src/spellfile.c reuses sl_sal_first[] without resetting values left by set_sal_first(), so a crafted spell file containing an SN_SAL section before an SN_SOFO section causes under-counted mapping lists and attacker-influenced writes beyond a heap allocation. This issue is fixed in version 9.2.0846.
Published: August 11, 2026; 4:17:38 PM UTC
7 hours ago
|
|
CVE-2026-73071
3.3 (Low)
Show References |
Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can retain a stale pointer after json_decode_string() invokes channel_fill() to refill and free the current buffer, causing the error path to read freed memory instead of reader->js_buf + reader->js_used when an invalid JSON string spans buffers. This issue is fixed in version 9.2.0844.
Published: August 11, 2026; 4:17:38 PM UTC
7 hours ago
|
|
CVE-2026-73070
6.8 (Medium)
Show References |
Vim is an open source, command line text editor. Prior to 9.2.0842, the socket server backend in src/socketserver.c accepts unbounded client connections in socketserver_accept(), causing descriptors to overflow fd_set structures in src/channel.c and fixed-size struct pollfd arrays in src/os_unix.c, which allows a local process that can connect to the server socket to corrupt stack memory or terminate the Vim server. This issue is fixed in version 9.2.0842.
Published: August 11, 2026; 4:17:38 PM UTC
7 hours ago
|
|
CVE-2026-73069
9.1 (Critical)
Show References |
Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty allowed a workspace administrator with the DATA_MODEL permission to supply settings.asExpression for the system TS_VECTOR field searchVector through PATCH /rest/metadata/fields/:id or the updateOneField GraphQL mutation, causing buildSqlColumnDefinition in packages/twenty-server/src/engine/twenty-orm/workspace-schema-manager/utils/build-sql-column-definition.util.ts to concatenate unescaped input into GENERATED ALWAYS AS (...) and execute arbitrary PostgreSQL statements as the application database user. This issue is fixed in version 2.15.0.
Published: August 11, 2026; 4:17:38 PM UTC
7 hours ago
|
|
|
|
CVE-2026-73068
5.9 (Medium)
Show References |
ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.207, the ToolJet Database HTTP API in server/src/modules/tooljet-db/controller.ts authorizes operations against the :organizationId URL path value without verifying that the caller belongs to that organization. JwtAuthGuard validates the tj-workspace-id header against the caller's memberships, while server/src/modules/tooljet-db/ability/index.ts grants VIEW_TABLES, VIEW_TABLE, and JOIN_TABLES without binding them to the path organization. An authenticated user can set tj-workspace-id to the user's own workspace and target another workspace through GET /api/tooljet-db/organizations/:organizationId/tables, GET /api/tooljet-db/organizations/:organizationId/table/:tableName, POST /api/tooljet-db/organizations/:organizationId/join, and the related table-management routes, allowing disclosure of table names, schemas, and rows and allowing tables to be created, altered, bulk populated, or dropped across tenant boundaries. This issue is fixed in version 3.20.207-lts.
Published: August 11, 2026; 4:17:37 PM UTC
7 hours ago
|
|
|
|
CVE-2026-6727
N/A (Info)
Show References |
A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may be able to exploit timing differences to recover information that could allow decryption of ciphertexts encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), including import blobs, credential blobs, and session salts. Under certain conditions, this may also enable the forgery of TPM 2.0 attestations. Refer to TCGVRT0011.
Published: August 11, 2026; 4:17:34 PM UTC
7 hours ago
|
|
CVE-2026-6726
N/A (Info)
Show References |
An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. See also TCG VRT0010.
Published: August 11, 2026; 4:17:34 PM UTC
7 hours ago
|
|
|
|
CVE-2026-67180
7.5 (High)
Show References |
Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing request or influence an evidence path/name obtains code execution on the worker fleet. Fixed on 2026-07-10.
Published: August 11, 2026; 4:17:34 PM UTC
7 hours ago
|
|
CVE-2026-67179
7.8 (High)
Show References |
Genkit does not properly validate host request headers. Any host on the developer's network, and any website the developer visits (via DNS rebinding), can reach POST /api/runAction on the Dev UI server (default port 4000) and execute any registered Genkit action and read the result. Fixed on 2026-06-18.
Published: August 11, 2026; 4:17:34 PM UTC
7 hours ago
|
|
CVE-2026-56721
8.7 (High)
Show References |
CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure direct object reference (IDOR) that allows authenticated low-privileged attackers to overwrite any user's credentials by exploiting a parameter confusion flaw between the authorization filter and action body in the UsersController. Attackers can send a PATCH request to the updated_ajax endpoint setting params[:id] to their own user ID to pass the self-authorization check while simultaneously setting params[:user_id] to a victim's ID, causing the controller to load and mutate the victim's account, including overwriting administrator passwords to achieve full site takeover.
Published: August 11, 2026; 4:17:33 PM UTC
7 hours ago
|
|
|
|
CVE-2026-56720
5.3 (Medium)
Show References |
CamaleonCMS version 2.9.2 and earlier contains a missing authorization vulnerability in the admin users controller that allows any authenticated user to access any other user's profile data by supplying an arbitrary user ID parameter. Attackers can send a GET request to the admin profile endpoint with an enumerable sequential integer user ID to disclose profile information of any user, including administrators, due to the profile action being excluded from the role validation filter with no compensating ownership check.
Published: August 11, 2026; 4:17:33 PM UTC
7 hours ago
|
|
|
|
CVE-2026-53416
7.1 (High)
Show References |
Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure via local access.
Published: August 11, 2026; 4:17:32 PM UTC
7 hours ago
|
|
CVE-2026-53415
8.3 (High)
Show References |
Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another participant via network access.
Published: August 11, 2026; 4:17:32 PM UTC
7 hours ago
|
|
CVE-2026-53414
6.5 (Medium)
Show References |
Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access.
Published: August 11, 2026; 4:17:32 PM UTC
7 hours ago
|
|
CVE-2026-53413
8.3 (High)
Show References |
Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code execution of another participant via network access.
Published: August 11, 2026; 4:17:32 PM UTC
7 hours ago
|
|
CVE-2026-48766
7.6 (High)
Show References |
TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to exfiltrate stored OpenAI-compatible API keys by invoking the OpenAI model-listing helper with an attacker-controlled `baseUrl`. The vulnerable path decrypts the selected workspace credential, creates an OpenAI client with the secret in both `apiKey` and the explicit `api-key` header, and then sends the outbound request to the caller-supplied URL. Because the permission check accepts any readable workspace member and `listCredentials` reveals credential identifiers to guests, a guest can force the server to deliver the workspace secret to attacker infrastructure. Version 3.17.0 patches the issue.
Published: August 11, 2026; 4:17:32 PM UTC
7 hours ago
|
|
|
|
CVE-2026-48495
7.1 (High)
Show References |
TypeBot is a chatbot builder tool. Prior to version 3.17.0, the Google Sheets OAuth callback decodes a base64-encoded JSON `state` parameter and trusts the embedded `workspaceId`, `typebotId`, `blockId`, and `redirectUrl` without cryptographic integrity protection or authorization checks. The callback route is authenticated, but it does not verify that the authenticated user has write access to the target workspace or Typebot before creating credentials in the workspace or updating Typebot groups. An authenticated user who can obtain a valid Google OAuth `code` can alter the `state` value to create Google Sheets credentials in another workspace and, if target IDs are known, attach those credentials to a block in another Typebot. Version 3.17.0 patches the issue.
Published: August 11, 2026; 4:17:32 PM UTC
7 hours ago
|
|
|
|
CVE-2026-42142
7.1 (High)
Show References |
TypeBot is a chatbot builder tool. Prior to version 3.17.0, the `handleGetSheets` API handler (`POST /api/sheets/getSheets`) does not validate workspace membership, allowing any authenticated user to access and decrypt another workspace's Google Sheets OAuth credentials and retrieve spreadsheet data (sheet names, IDs, column headers). Version 3.17.0 fixes the issue.
Published: August 11, 2026; 4:17:31 PM UTC
7 hours ago
|
|
|
|
CVE-2026-19546
8.8 (High)
Show References |
A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z.
For a detailed Statement, Description and Mitigation please reffer to the original https://access.redhat.com/security/cve/cve-2026-19546.
Published: August 11, 2026; 4:17:31 PM UTC
7 hours ago
|
|
CVE-2026-19078
4.3 (Medium)
Show References |
A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the grant approval handler is not properly validated. A remote attacker can craft a malicious URL that, when approved or denied by an authenticated user, redirects them to an attacker-controlled website. This could enable phishing attacks, potentially tricking users into revealing sensitive information.
Published: August 11, 2026; 4:17:31 PM UTC
7 hours ago
|
|
CVE-2026-18640
7.1 (High)
Show References |
The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT permission to write the notebook record outside the org's data store directory. The file written must have an extension of ".json.db" but can otherwise overwrite other metadata files (such as ACL records, hunts etc). This can corrupt these files and cause data corruption.
Published: August 11, 2026; 4:17:30 PM UTC
7 hours ago
|
|
CVE-2026-18639
7.3 (High)
Show References |
When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, some IdP allow users to change the email claim without verification. Some IdPs do not set the "email_verified" claim and do not actually verify the email.
This allows a user to impersonate another user by setting their email address within the IdP, allowing account takeover.
Published: August 11, 2026; 4:17:30 PM UTC
7 hours ago
|
|
CVE-2026-18638
6.5 (Medium)
Show References |
Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server process with a single request, by calling SetPassword with a username that does not exist.
Published: August 11, 2026; 4:17:30 PM UTC
7 hours ago
|
|
CVE-2026-14180
5.3 (Medium)
Show References |
A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding. The issue occurs because the parser uses a single internal variable to store both the remaining chunk size and state flags. By sending a specially crafted request with an extremely large chunk size, an attacker can cause these values to overlap, tricking the parser into thinking a request has finished prematurely. This can allow a second, "smuggled" request to be processed out of sync, potentially bypassing security controls.
Published: August 11, 2026; 4:17:28 PM UTC
7 hours ago
|
|
CVE-2026-11814
4.9 (Medium)
Show References |
A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs.
Published: August 11, 2026; 4:17:28 PM UTC
7 hours ago
|
|
|
|
CVE-2026-11739
4.9 (Medium)
Show References |
A command injection vulnerability in certain affected NETGEAR Nighthawk
devices allows a network-adjacent attacker with the ability to intercept
and modify local network traffic (attacker in the middle) to compromise
the confidentiality and integrity of the affected device.
Published: August 11, 2026; 4:17:28 PM UTC
7 hours ago
|
|
|
|
CVE-2026-11738
4.3 (Medium)
Show References |
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.
Published: August 11, 2026; 4:17:28 PM UTC
7 hours ago
|
|
CVE-2026-11737
4.3 (Medium)
Show References |
Insufficient input validation vulnerability in the listed
NETGEAR models allows authenticated administrators connected to the
local network to make unauthorized modification to the device software and
functionality.
Published: August 11, 2026; 4:17:27 PM UTC
7 hours ago
|
|
|
|
CVE-2026-11736
1.9 (Low)
Show References |
A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality.
Published: August 11, 2026; 4:17:27 PM UTC
7 hours ago
|
|
|
|
CVE-2026-11735
1.9 (Low)
Show References |
A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality.
Published: August 11, 2026; 4:17:27 PM UTC
7 hours ago
|
|
|
|
CVE-2026-11734
1.1 (Low)
Show References |
A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable.
Published: August 11, 2026; 4:17:27 PM UTC
7 hours ago
|
|
|
|
CVE-2026-11733
1.1 (Low)
Show References |
A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the normal operation of the affected device.
Published: August 11, 2026; 4:17:26 PM UTC
7 hours ago
|
|
|
|
CVE-2025-31114
9.3 (Critical)
Show References |
Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remote code execution due to the unsafe use of eval when processing metadata JSON. An attacker with access to the Fooocus web UI may be able to execute arbitrary code on the instance. As of time of publication, no known patched versions are available, but a suggested fix pull request is available.
Published: August 11, 2026; 4:17:26 PM UTC
7 hours ago
|
|
CVE-2026-73067
6.7 (Medium)
Show References |
Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata model loaded through TessBaseAPI::Init can cause SquishedDawg::read_squished_dawg in src/dict/dawg.cpp to accept an unterminated forward-edge run, after which SquishedDawg::Load calls num_forward_edges(0) and last_edge in src/dict/dawg.h reads beyond edges_, causing a heap out-of-bounds read and process crash before image processing. This issue is fixed in version 5.5.3.
Published: August 11, 2026; 3:17:38 PM UTC
8 hours ago
|
|
|
|
CVE-2026-73066
6.8 (Medium)
Show References |
Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesseract's deserializer can cause an unchecked signed integer multiplication in Convolve::DeSerialize in src/lstm/convolve.cpp to wrap the convolution output-channel count, undersizing the forward-pass output buffer while writes use the unwrapped element count and causing a heap out-of-bounds write during OCR recognition. This issue is fixed in version 5.5.3.
Published: August 11, 2026; 3:17:38 PM UTC
8 hours ago
|
|
|
|
CVE-2026-72925
6.1 (Medium)
Show References |
SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_minifier 59.0.0, the minifyJson processing in crates/swc_html_minifier/src/lib.rs parsed and serialized attacker-controlled JSON in application/json and application/ld+json script elements without the escape_json_for_html_script behavior to re-escape less-than signs, allowing a closing script sequence to terminate the element early and execute script in the generated page's origin. This issue is fixed in @swc/html 1.15.47-nightly-20260729.1 and swc_html_minifier 59.0.0.
Published: August 11, 2026; 3:17:38 PM UTC
8 hours ago
|
|
|
|
CVE-2026-72922
8.2 (High)
Show References |
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.70, AutoGPT's autogpt_platform/backend/backend/api/features/integrations/router.py webhook_ingress_generic route selected get_webhook_manager(provider) from the untrusted provider URL segment without verifying webhook.provider, allowing a request to /compass/webhooks/{webhook_id}/ingress to use CompassWebhookManager's inherited no-op BaseWebhooksManager.verify_signature instead of GenericWebhooksManager.verify_signature, bypass X-Webhook-Secret for a configured secret_token, and execute a generic webhook graph as its owner. This issue is fixed in version 0.6.70.
Published: August 11, 2026; 3:17:38 PM UTC
8 hours ago
|
|
|
|
CVE-2026-72921
8.1 (High)
Show References |
SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes authorization check used strings.HasPrefix on raw path strings, so a filer JWT scoped to /tenant1 also authorized sibling paths such as /tenant1234, /tenant1-old, and /tenant1backup, enabling cross-tenant reads and writes with a valid scoped token. This issue is fixed in version 4.24.
Published: August 11, 2026; 3:17:38 PM UTC
8 hours ago
|
|
|
|
CVE-2026-72920
9.8 (Critical)
Show References |
SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset, allowing any client that can reach the filer gRPC port to invoke CreateUser, CreateAccessKey, PutPolicy, and related IAM RPCs to mint credentials and gain S3 administrative control. This issue is fixed in versions 4.24.
Published: August 11, 2026; 3:17:38 PM UTC
8 hours ago
|
|
|
|
CVE-2026-47702
9.1 (Critical)
Show References |
TypeBot is a chatbot builder tool. In version 3.16.1, API tokens (bearer credentials used to authenticate against the builder API) are stored in the database as cleartext strings. An attacker who gains read access to the database (e.g., via SQL injection, backup exposure, or insider access) can extract all API tokens and impersonate any user without requiring a password or multi-factor authentication. Version 3.17.0 fixes the issue.
Published: August 11, 2026; 3:17:30 PM UTC
8 hours ago
|
|
|
|
CVE-2026-18860
8.7 (High)
Show References |
Velociraptor allows multi-tenant deployments named "Orgs".
By default Velociraptor, uses the ROOT org, but users can create child orgs for other tenants within the same deployment.
Users can have different permissions in each org. To manage Orgs, Velociraptor usually examines the ORG_ADMIN permission on the ROOT org.
This issue results from the Velociraptor server allowing for the deletion of Orgs by incorrectly checking the ORG_ADMIN permission of callers within the calling ORG instead of the ROOT org. However, Org admins of child orgs were able to add this permission to their ACL token within their own org. This allows an administrator in a child org, which is not also an administrator in the ROOT org, to delete other orgs.
Published: August 11, 2026; 3:17:28 PM UTC
8 hours ago
|
|
CVE-2026-18636
6.8 (Medium)
Show References |
The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users from reading sensitive files or accessing other orgs, the requested path is prefix checked against a list of denied prefixes. This prefix check can be bypassed allowing a user to access usually denied files. If the user has read permission in the ROOT org, this allows access to other orgs, in which the user may not have permission.
Published: August 11, 2026; 3:17:28 PM UTC
8 hours ago
|
|
CVE-2026-18635
7.2 (High)
Show References |
Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able to run as a different user, the calling user needs to have the IMPERSONATE permission (usually only given to administrators). Velociraptor versions prior to 0.77.2 evaluate this permission against the caller's org instead of against the target org.
This allows an administrator in one org to impersonate another user in another org, in which they may not have the IMPERSONATE permission.
Published: August 11, 2026; 3:17:28 PM UTC
8 hours ago
|
|
CVE-2026-18129
8.1 (High)
Show References |
Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker in a MITM position to leak credentials for external SQL connections.
Published: August 11, 2026; 3:17:28 PM UTC
8 hours ago
|
|
CVE-2026-18127
7.7 (High)
Show References |
External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage.
Published: August 11, 2026; 3:17:28 PM UTC
8 hours ago
|
|
CVE-2026-18125
7.5 (High)
Show References |
An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker to crash an agent service.
Published: August 11, 2026; 3:17:28 PM UTC
8 hours ago
|
|
CVE-2026-17535
6.2 (Medium)
Show References |
Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by maliciously crafted NTFS images.
Typically Velociraptor's NTFS parser is used on live NTFS filesystems, limiting the opportunity of attackers corrupting the filesystem. However, in some applications (e.g. dead disk forensics https://docs.velociraptor.app/docs/forensic/deaddisk/ ) Velociraptor may be used on untrusted NTFS image files.Â
If an attacker is able to inject maliciously corrupted NTFS Volumes they can cause a crash and a Denial of Service.
Published: August 11, 2026; 3:17:27 PM UTC
8 hours ago
|
|
CVE-2026-17061
10 (Critical)
Show References |
A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthenticated remote code execution.
Published: August 11, 2026; 3:17:27 PM UTC
8 hours ago
|
|
CVE-2026-73210
5.1 (Medium)
Show References |
A Server-Side Request Forgery (SSRF) vulnerability existed in Lookyloo's PlaywrightCapture when the only_global_lookup option was enabled.
PlaywrightCapture implements this option to prevent captures from accessing local, loopback, or otherwise non-public network resources. However, favicon retrieval was performed separately from the browser request-routing protections. Favicon URLs extracted from rendered HTML were resolved and subsequently fetched directly using an aiohttp.ClientSession.
An attacker able to supply or control a web page processed by PlaywrightCapture could include a crafted favicon reference, for example pointing to a loopback address, private IP address, or another resource reachable only from the PlaywrightCapture host. When the page was processed, the favicon retrieval routine could issue an HTTP request to this destination despite only_global_lookup being enabled.
This bypass could therefore be used to make the PlaywrightCapture host interact with internal network services that should not be reachable through a capture. Depending on the targeted service and its response, this could enable internal service discovery, access to internal resources, or interaction with HTTP endpoints available only from the capture infrastructure.
The patch introduces a common URL validation routine and applies it to favicon retrieval. Direct non-global IP addresses, localhost, .local domains, malformed URLs, and other explicitly non-public destinations are rejected before the favicon request is performed.
This fix is a complementary fix to CVE-2026-44439 - GCVE-0-2026-44439 - GHSA-687H-XW6F-Q2QW
Published: August 11, 2026; 2:17:16 PM UTC
9 hours ago
|
|
CVE-2026-51584
N/A (Info)
Show References |
An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the SignIn handler in server/router/api/v1/auth_service.go, because SSO identity is matched only on an attacker-controllable identifier without binding to the IdP's stable subject claim.
Published: August 11, 2026; 2:17:14 PM UTC
9 hours ago
|
|
CVE-2026-51583
N/A (Info)
Show References |
An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side Request Forgery (SSRF) via the Webhook validation mechanism in internal/webhook/validate.go, by setting a webhook target to an internal address.
Published: August 11, 2026; 2:17:14 PM UTC
9 hours ago
|
|
CVE-2026-48056
10 (Critical)
Show References |
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 improperly validate executable paths supplied to the  run-download IPC handler, allowing a compromised renderer process to execute arbitrary local binaries with the application’s privileges. Version 2.5.0 contains a patch.
Published: August 11, 2026; 2:17:14 PM UTC
9 hours ago
|
|
CVE-2026-48046
9.3 (Critical)
Show References |
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contain an unvalidated auto-updater URL vulnerability that allows a compromised renderer process to make the main process download and execute an arbitrary binary, resulting in remote code execution. Version 2.5.0 contains a patch.
Published: August 11, 2026; 2:17:14 PM UTC
9 hours ago
|
|
CVE-2026-46670
9.8 (Critical)
Show References |
YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any unauthenticated visitor of a default YesWiki install to inject arbitrary SQL into an `INSERT` statement and read the full database, including `yeswiki_users.password` hashes. Version 4.6.4 fixes the issue.
Published: August 11, 2026; 2:17:13 PM UTC
9 hours ago
|
|
CVE-2026-19539
8.6 (High)
Show References |
Authorization Bypass Through User-Controlled Key in the ticket management component in Roskus Prospero Flow CRM before 5.4.9 allows authenticated users of any company to read the full content (title, description, and attachments) of tickets belonging to another company, to hijack another company's tickets by reassigning their company_id, and to delete another company's tickets without any authorization check, via the ticket's numeric identifier, because the read and save operations retrieve the record without constraining the query to the authenticated user's company, and the delete controller type-hints a generic Illuminate\Http\Request instead of the TicketDeleteRequest that would enforce the required permission.
Published: August 11, 2026; 2:17:13 PM UTC
9 hours ago
|
|
|
|
CVE-2026-19434
5.1 (Medium)
Show References |
Cross-site Scripting in the finding renderer in maalfer Pentestify before 2.3.1 allows authenticated users to execute arbitrary JavaScript in the application origin via HTML markup stored in a finding's severity field, which the frontend interpolates unescaped into class and style attributes when rendering the report.
Published: August 11, 2026; 2:17:13 PM UTC
9 hours ago
|
|
CVE-2026-72785
9.3 (Critical)
Show References |
Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability. A control-panel user holding only the viewCategories permission (without saveCategories) for a category group can permanently modify that group's category structure — reordering and re-parenting categories — via the structures/move-element action. The structureEditable flag is computed from the view permission rather than the save permission, and the StructuresController authorizes the mutating action on that read-time session grant without a save re-check. Because a category's URI is derived from its position in the structure, moving a category changes its URL and those of its descendants and can corrupt navigation menus built from the category taxonomy. The issue is fixed in 5.10.6.
Published: August 11, 2026; 1:19:09 PM UTC
10 hours ago
|
|
CVE-2026-72784
6.9 (Medium)
Show References |
Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a server-side request forgery vulnerability in the GraphQL save<Volume>Asset mutation, which fetches an attacker-supplied URL server-side. The anti-SSRF validation is incomplete: validateIp() does not cover CGNAT (100.64.0.0/10) or NAT64 (64:ff9b::/96) ranges, and the only IP check runs after the request has already been issued. An attacker holding a GraphQL token scoped only to asset-creation permissions can disclose internal HTTP content from CGNAT/NAT64 targets, force outbound GET requests to internal hosts (including RFC1918, loopback, and metadata endpoints), and enumerate internal services.
Published: August 11, 2026; 1:19:09 PM UTC
10 hours ago
|
|
CVE-2026-72783
6.9 (Medium)
Show References |
Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a theoretical path traversal weakness in the ensurePathIsContained function of the Local file system class. The order of operations validates the path before normalization, so normalization could invalidate prior validation assumptions (a desanitization-style issue) and potentially resolve to files outside the intended volume directory. The vendor notes the issue is not directly exploitable and no exploitable scenario has been discovered; the fix is recommended for hardening.
Published: August 11, 2026; 1:19:08 PM UTC
10 hours ago
|
|
CVE-2026-72782
7.1 (High)
Show References |
Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 interpolate environment variables and secrets (via ${ENV_VAR} strings in the elementId parameter) into Twig templates before rendering, even when the Twig sandbox is enabled. An authenticated attacker with control panel access can render a malicious sandboxed Twig template and, using a blind error-based technique across many requests, incrementally leak arbitrary environment variables and secrets. These can be abused to forge sessions (via CRAFT_SECURITY_KEY), escalate privileges, and steal database, SMTP, API, or blob storage credentials. Fixed in 5.10.6 and 4.18.2.
Published: August 11, 2026; 1:19:08 PM UTC
10 hours ago
|
|
CVE-2026-72781
8.7 (High)
Show References |
Craft CMS versions >= 5.0.0-RC1 before 5.10.7 and >= 4.0.0-RC1 before 4.18.3 contain a remote code execution vulnerability in the Twig sandbox mechanism. Because Craft marks the ElementInterface as safe (via the AllowedInSandbox attribute) and the sandbox allowlisting extends to the entire class hierarchy (craft\base\Component up to yii\base\Component), an authenticated attacker with permission to access the control panel can render a malicious Twig template that abuses the yii\base\Component arbitrary function-call gadget to execute arbitrary code, even when the Twig sandbox is enabled via enableTwigSandbox().
Published: August 11, 2026; 1:19:08 PM UTC
10 hours ago
|
|
CVE-2026-72780
7.1 (High)
Show References |
Craft CMS before 5.10.5 fails to persist updated credential counters after WebAuthn assertion validation in the passkey login endpoint. Attackers can replay captured login request bodies containing requestOptions and response to create additional authenticated sessions for victim accounts.
Published: August 11, 2026; 1:19:08 PM UTC
10 hours ago
|
|
CVE-2026-72779
8.7 (High)
Show References |
Craft CMS 5.0.0-RC1 before 5.10.6 and 4.0.0-RC1 before 4.18.2 contain an arbitrary file read vulnerability. The create() Twig function restricts class instantiation using a 5-entry blocklist that does not include SplFileObject, allowing an authenticated administrator (with allowAdminChanges=true) to configure a malicious entry type title or URI format that instantiates SplFileObject in a non-sandboxed template context. When a user subsequently creates an entry in the affected section, arbitrary files on the server (such as .env containing the security key and database credentials) are read and rendered as entry titles.
Published: August 11, 2026; 1:19:08 PM UTC
10 hours ago
|
|
CVE-2026-72778
8.7 (High)
Show References |
Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in the control panel element-search condition handling. Craft cleanses the outer request-controlled condition array via Component::cleanseConfig(), but Conditions::createCondition() later decodes and merges the JSON string in condition.config without re-running cleanseConfig() on the decoded configuration. Because condition.config is a JSON string during the first cleanse, Yii special config keys such as 'as ...' and 'on ...' can be hidden inside it and, after JSON decoding, are interpreted by Yii as behavior/event configuration during FieldLayout object creation. An attacker with an authenticated control panel session (and a valid CSRF token) can exploit this to execute operating system commands as the PHP/web user.
Published: August 11, 2026; 1:19:08 PM UTC
10 hours ago
|
|
CVE-2026-72775
5.8 (Medium)
Show References |
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the PostgresTrigger node, which interpolates user-supplied identifier parameters (channel, function, and trigger names) into SQL statements without proper escaping. An authenticated user can inject arbitrary SQL executed against the connected PostgreSQL database with the configured credential's privileges, allowing full read and write access.
Published: August 11, 2026; 1:19:08 PM UTC
10 hours ago
|
|
CVE-2026-72774
7.1 (High)
Show References |
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypass in the HTTP Request node. An authenticated member with edit access to a shared workflow can reference another user's credential while specifying the credential type via an expression. Because the pre-execution permission check compares the unresolved expression instead of the resolved credential type, the ownership check is skipped and the credential is loaded at execution time, allowing the member to use or exfiltrate a credential they were not granted. Exploitation requires knowing the target credential's identifier.
Published: August 11, 2026; 1:19:07 PM UTC
10 hours ago
|
|
CVE-2026-72773
4.9 (Medium)
Show References |
n8n before 2.31.5 and 2.32.x before 2.32.1 contain a path-confinement bypass in the @n8n/computer-use file-search (search_files) tool. A crafted search pattern can bypass the base-directory confinement check and expand to locations outside the configured directory, causing the tool to return the names and contents of arbitrary local files readable by the daemon's OS user. Any deployment where an actor can influence the tool's search input is affected.
Published: August 11, 2026; 1:19:07 PM UTC
10 hours ago
|
|
CVE-2026-72772
8.9 (High)
Show References |
n8n before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the Token Exchange Embed Login feature. When a validly-signed incoming token was matched to a local account by its email claim, the service did not verify that the email claim was verified, nor that the trusted key's permitted role ceiling covered that account. As a result, anyone able to obtain a token accepted by a configured trusted key (for example, a trusted issuer emitting unverified email addresses) could authenticate as any existing user and gain full account control. This issue only affects instances where the embed login feature is enabled and at least one trusted key source is configured.
Published: August 11, 2026; 1:19:07 PM UTC
10 hours ago
|
|
CVE-2026-72771
7.1 (High)
Show References |
n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when user-supplied base or endpoint URLs are configured. Low-privileged workflow editors with use-only access to shared credentials can redirect requests to attacker-controlled hosts and exfiltrate credential secrets for reuse against underlying services.
Published: August 11, 2026; 1:19:07 PM UTC
10 hours ago
|
|
CVE-2026-72770
7.1 (High)
Show References |
n8n versions before 1.123.67 contain a path traversal vulnerability in the Git node's fetch, pull, and push-tags operations that allows authenticated users to bypass repository-path containment checks. Attackers with workflow create/execute rights can point allowlisted remote configurations at local paths outside the sandbox to pull arbitrary git repositories and read their files and history.
Published: August 11, 2026; 1:19:07 PM UTC
10 hours ago
|
|
CVE-2026-72769
6.1 (Medium)
Show References |
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the VM expression engine. An authenticated user able to create or edit a workflow expression can abuse the engine's array-element access to obtain a reference to a host built-in and pollute its prototype in the main n8n process (a sandbox escape), leading to a denial of service. Both self-hosted and cloud instances running the VM expression engine are affected.
Published: August 11, 2026; 1:19:07 PM UTC
10 hours ago
|
|
CVE-2026-72768
6.4 (Medium)
Show References |
n8n versions before 2.32.1 contain a server-side request forgery protection bypass vulnerability in the MCP Client node that allows authenticated users to bypass SSRF protections. Attackers can craft workflows that send requests to internal or blocked hosts without routing through SSRF protection, exposing internal services and reading responses back through the workflow.
Published: August 11, 2026; 1:19:07 PM UTC
10 hours ago
|
|
CVE-2026-72767
8.7 (High)
Show References |
n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a remote code execution vulnerability in the Git node. Authenticated users with rights to create and execute workflows can stage a crafted local repository that causes git to run hooks under default git security settings, executing arbitrary commands as the n8n process user. Both self-hosted and cloud instances are affected.
Published: August 11, 2026; 1:19:06 PM UTC
10 hours ago
|
|
CVE-2026-72766
8.2 (High)
Show References |
n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a type confusion vulnerability in the Send Email node, which does not enforce that its message fields are strings. A crafted non-string value supplied from a workflow expression into the text or HTML body field can be interpreted by the underlying mail library (Nodemailer) as a file path or URL, allowing arbitrary local file disclosure and server-side request forgery (SSRF). Exploitation requires a pre-existing active workflow with an unauthenticated webhook, valid SMTP credentials configured on the node, and untrusted input mapped directly into the body field; this is not a default configuration.
Published: August 11, 2026; 1:19:06 PM UTC
10 hours ago
|
|
CVE-2026-72765
8.7 (High)
Show References |
n8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in expression evaluation. An authenticated user with permission to create or modify workflows can craft expressions using arrow-function bodies to bypass the expression sandbox, triggering system command execution on the host running n8n. The issue is fixed in versions 2.31.5 and 2.32.1.
Published: August 11, 2026; 1:19:06 PM UTC
10 hours ago
|
|
CVE-2026-72764
5.8 (Medium)
Show References |
n8n's JavaScript task runner shared a single module cache across all users' Code-node executions. In affected versions (before 1.123.67, 2.31.5, and 2.32.1), a user able to run a Code node could poison a cached module and thereby alter other users' Code-node executions on the same runner, affecting their confidentiality, integrity, or availability. This is a cross-user isolation break within a single n8n instance and does not constitute a sandbox escape or remote code execution. Only multi-user instances running the JS task runner with built-in or external modules enabled are affected.
Published: August 11, 2026; 1:19:06 PM UTC
10 hours ago
|
|
CVE-2026-72763
7.2 (High)
Show References |
n8n before 1.123.67, 2.31.5, and 2.32.1 validates credential-access only for a node's top-level credentials and not for credentials referenced inside an Execute Sub-workflow node's inline workflow JSON. A member with Editor access to a shared workflow (when workflow sharing is enabled) who knows a target credential's ID can reference that credential in the inline JSON; it passes save-time and runtime validation and resolves in the parent workflow's project context, allowing the attacker to use or exfiltrate credentials they are not permitted to access.
Published: August 11, 2026; 1:19:06 PM UTC
10 hours ago
|
|
CVE-2026-72762
7.7 (High)
Show References |
n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in the Edit Image node, which passes its output format parameter to the underlying image library without validation. An authenticated user able to run workflows can supply a crafted format value to write arbitrary files outside the node's working directory on the n8n instance.
Published: August 11, 2026; 1:19:06 PM UTC
10 hours ago
|
|
CVE-2026-72750
5.3 (Medium)
Show References |
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake node's Execute Query operation, which interpolates expression values directly into the SQL string. When a workflow author embeds untrusted, externally-controlled expression data directly in a raw SQL query, that data is not parameterized, allowing SQL injection. The fix adds an optional 'Query Parameters' field to bind values via positional placeholders.
Published: August 11, 2026; 1:19:06 PM UTC
10 hours ago
|
|
CVE-2026-72749
7.1 (High)
Show References |
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the Edit Fields (Set) node. The node assigns output fields via a dot-notation path setter without restricting the field name, allowing an authenticated user to name a field after an inherited built-in method path and corrupt a shared global in the main Node.js process. Because that global is used on the request-authentication path, the instance then fails every authenticated request, causing an instance-wide denial of service for all users until the process is restarted.
Published: August 11, 2026; 1:19:05 PM UTC
10 hours ago
|
|
CVE-2026-72748
6.9 (Medium)
Show References |
AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that allows remote attackers to write up to 4 GB of arbitrary content to the server filesystem via HTTP PUT requests without authentication. Attackers can exhaust disk space causing denial of service, poison the video encoding pipeline, or chain this with local file inclusion to achieve remote code execution.
Published: August 11, 2026; 1:19:05 PM UTC
10 hours ago
|
|
|
|
CVE-2026-72747
5.1 (Medium)
Show References |
AVideo fails to sanitize the phone field during user registration, allowing unauthenticated attackers to inject malicious JavaScript that persists in the database. When administrators visit the users management page, the unsanitized phone value is rendered via innerHTML, executing the injected script in the admin's browser session.
Published: August 11, 2026; 1:19:05 PM UTC
10 hours ago
|
|
|
|
CVE-2026-72746
8.7 (High)
Show References |
FreeRDP before 3.30.0 contains a server-side authentication bypass in the RDSTLS handshake. When a server is configured with RdstlsSecurity = TRUE, the handshake dispatches inbound PDUs based solely on the attacker-supplied wire pduType without verifying that the received PDU is the one required at the current step. Because the rdpRdstls object is calloc-zeroed, its resultCode defaults to 0 (RDSTLS_RESULT_SUCCESS). An unauthenticated remote client can send a Capabilities PDU instead of the required Authentication Request PDU; rdstls_process_capabilities() returns success without ever setting resultCode, so the server responds with an AUTHRSP carrying resultCode SUCCESS and treats the session as authenticated without evaluating any password, redirection GUID, or auto-reconnect cookie. This affects the released FreeRDP 3.x series (e.g., 3.27.1) and master HEAD; at the time of the advisory no patched version was available.
Published: August 11, 2026; 1:19:05 PM UTC
10 hours ago
|
|
|
|
CVE-2026-72745
8.7 (High)
Show References |
FreeRDP before 3.30.0 contains an out-of-bounds vulnerability in kerberos_DecryptMessage() (winpr/libwinpr/sspi/Kerberos/kerberos.c). The 16-bit EC (extra count) field of a peer-supplied GSS Wrap token (RFC 4121) is used directly in pointer arithmetic to locate the encrypted regions without being bounds-checked, while only RRC and the total buffer length are validated. A malicious peer (server or client) can supply a large EC value (up to 0xFFFF) during CredSSP/NLA authentication, moving the decrypt operation's base pointers past the end of the ~60-byte token buffer. Because the AES-CTS-HMAC enctypes decrypt in place before the HMAC integrity check, this results in an out-of-bounds read and in-place out-of-bounds write, potentially leading to information disclosure, memory corruption, or denial of service.
Published: August 11, 2026; 1:19:05 PM UTC
10 hours ago
|
|
CVE-2026-72744
6.9 (Medium)
Show References |
Nuxt versions >= 4.4.7 and < 4.5.1, and >= 3.21.7 and < 3.21.10, contain an information disclosure vulnerability in the development server's Chrome DevTools workspace endpoint (GET /.well-known/appspecific/com.chrome.devtools.json). The endpoint's local-request gate (isLocalDevRequest) is header-based and trusts the attacker-supplied Host header rather than the connected peer address. When the dev server is bound to a network-reachable interface (e.g. nuxt dev --host) and experimental.chromeDevtoolsProjectSettings is enabled (the default), an unauthenticated attacker on the LAN can send a request with a spoofed Host header and no browser-specific headers (Sec-Fetch-Site, Origin, Referer) to retrieve the project's absolute filesystem root path (rootDir) and a persistent per-project workspace UUID. Production builds are unaffected. Fixed in 4.5.1 and 3.21.10.
Published: August 11, 2026; 1:19:05 PM UTC
10 hours ago
|
|
CVE-2026-69109
8.7 (High)
Show References |
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.3). The affected application is vulnerable to a path traversal vulnerability due to lack of sanitization of user input. This could allow a remote attacker to access arbitrary files on the application.
Published: August 11, 2026; 1:19:02 PM UTC
10 hours ago
|
|
CVE-2026-69108
8.3 (High)
Show References |
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.1). The affected application is vulnerable to a local privilege escalation due to an insecure sudoers policy. This could allow an attacker to execute arbitrary commands and plant malicious files as root, leading to full system compromise.
Published: August 11, 2026; 1:19:01 PM UTC
10 hours ago
|
|
CVE-2026-64629
7.3 (High)
Show References |
A vulnerability has been identified in Parasolid V38.0 (All versions < V38.0.235), Parasolid V38.1 (All versions < V38.1.230). The affected applications contains an out of bounds read vulnerability while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process.
Published: August 11, 2026; 1:19:01 PM UTC
10 hours ago
|
|
CVE-2026-59701
7.3 (High)
Show References |
A vulnerability has been identified in Simcenter Femap (All versions < V2606.0001). The affected applications contains an out of bounds read vulnerability while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process.
Published: August 11, 2026; 1:19:00 PM UTC
10 hours ago
|
|
CVE-2026-59700
7.3 (High)
Show References |
A vulnerability has been identified in Simcenter Femap (All versions < V2606.0001). The affected applications contains an out of bounds read vulnerability while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process.
Published: August 11, 2026; 1:19:00 PM UTC
10 hours ago
|
|
CVE-2026-59693
5.3 (Medium)
Show References |
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.233.16-7862), Desigo PXC3 (All versions < V01.21.233.16-7862), Desigo PXC4 (All versions < V02.21.194.36-2715), Desigo PXC5.E003 (All versions < V02.21.194.36-2715), Desigo PXC5.E24 (All versions < V02.21.194.36-2715), Desigo PXC7 (All versions < V02.21.194.36-2715). The affected devices are vulnerable to a denial-of-service (DoS) vulnerability. An attacker can exploit this issue by sending a malformed BACnet packet, causing the device to stop responding to BACnet queries. Recovery requires a device reset or reboot to restore normal functionality.
Published: August 11, 2026; 1:19:00 PM UTC
10 hours ago
|
|
CVE-2026-59086
7.3 (High)
Show References |
A vulnerability has been identified in Simcenter Nastran (All versions < V2606). The affected applications contain a stack overflow vulnerability while parsing specially strings as argument for one of the application binaries. This could allow an attacker to execute code in the context of the current process.
Published: August 11, 2026; 1:19:00 PM UTC
10 hours ago
|
|
CVE-2026-58115
10 (Critical)
Show References |
A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server.
This could allow an unauthenticated remote attacker to create malicious flows through the HTTP interface in order to execute arbitrary code on the underlying server with maximum privileges.
Published: August 11, 2026; 1:19:00 PM UTC
10 hours ago
|
|
CVE-2026-57263
7 (High)
Show References |
A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). The project password feature in the affected products stores the password as an unsalted SHA-256 hash. This could allow an attacker who has obtained the project file to perform efficient offline dictionary or brute-force attacks against the unsalted hash.
Published: August 11, 2026; 1:18:59 PM UTC
10 hours ago
|
|
CVE-2026-57262
7 (High)
Show References |
A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). Affected products use a static, hardcoded AES master key to encrypt project files. This could allow a local attacker to extract the master key from the application files or memory and use it to decrypt project files or remove project passwords entirely without knowing the actual user-defined password.
Published: August 11, 2026; 1:18:59 PM UTC
10 hours ago
|
|
CVE-2026-50064
7.3 (High)
Show References |
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds write vulnerability while parsing specially crafted PSM files. This could allow an attacker to execute code in the context of the current process.
Published: August 11, 2026; 1:18:58 PM UTC
10 hours ago
|
|
CVE-2026-50063
7.3 (High)
Show References |
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds read vulnerability while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.
Published: August 11, 2026; 1:18:58 PM UTC
10 hours ago
|
|
CVE-2026-50062
7.3 (High)
Show References |
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds read vulnerability while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.
Published: August 11, 2026; 1:18:58 PM UTC
10 hours ago
|
|
CVE-2026-50061
7.3 (High)
Show References |
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.
Published: August 11, 2026; 1:18:58 PM UTC
10 hours ago
|
|
CVE-2026-50060
7.3 (High)
Show References |
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.
Published: August 11, 2026; 1:18:58 PM UTC
10 hours ago
|
|
CVE-2026-50059
7.3 (High)
Show References |
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds write vulnerability while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.
Published: August 11, 2026; 1:18:58 PM UTC
10 hours ago
|
|
CVE-2026-50058
7.3 (High)
Show References |
A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds read vulnerability while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.
Published: August 11, 2026; 1:18:58 PM UTC
10 hours ago
|
|
CVE-2026-18972
9.6 (Critical)
Show References |
An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account takeover attack from a user with low privileges to administrator.
Published: August 11, 2026; 1:17:56 PM UTC
10 hours ago
|
|
CVE-2026-72610
4.3 (Medium)
Show References |
A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the borrowers => edit_borrowers permission to cause a time-based denial of service by storing a SQL payload in a patron lang field. The value is concatenated raw into a subquery in Koha::AdditionalContents->search_for_display when an issue slip is printed for the affected patron. The 25-character column length limits exploitation to timing attacks; data extraction is not practical. The stored payload executes on each subsequent issue-slip print, scaling linearly with the SLEEP value and the number of slip-news rows.
Published: August 11, 2026; 12:17:44 PM UTC
11 hours ago
|
|
CVE-2026-72609
7.1 (High)
Show References |
An SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the acquisition => order_receive permission to read arbitrary database contents via the orderby request parameter in acqui/parcels.pl. The parameter is passed to C4::Acquisition::GetInvoices, which allow-lists the column name but concatenates the direction token raw into the SQL ORDER BY clause without validation. Exploitation is blind (time-based) in production and allows extraction of patron PII, staff bcrypt password hashes, and two-factor secrets.
Published: August 11, 2026; 12:17:44 PM UTC
11 hours ago
|
|
CVE-2026-72608
6.5 (Medium)
Show References |
A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the tools => label_creator permission to execute arbitrary SQL via the image_name field of a patron card layout. The image_name value is stored verbatim in the layout XML and later concatenated raw into a SQL query in patroncards/create-pdf.pl when a patron card batch is printed. An attacker can read the entire Koha database including patron PII and staff bcrypt password hashes via error-based or time-based blind injection.
Published: August 11, 2026; 12:17:43 PM UTC
11 hours ago
|
|
CVE-2026-72607
7.1 (High)
Show References |
A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the tools => items_batchmod permission to read arbitrary database contents by storing a SQL payload in the agefield value of an automatic item modification rule. The agefield value is stored verbatim to the system preference and later interpolated without parameterization into a SQL query in C4::Items::ToggleNewStatus (line 1228) when the scheduled cron job executes. The injection is SELECT-only under standard MariaDB/MySQL DBI single-statement execution; a time-based SLEEP payload is also achievable via the cron trigger. An attacker can read the entire Koha database including patron PII and staff bcrypt password hashes.
Published: August 11, 2026; 12:17:43 PM UTC
11 hours ago
|
|
CVE-2026-72606
7.5 (High)
Show References |
A server-side request forgery vulnerability in Pinry through 2.1.13 allows unauthenticated remote attackers to make the server issue HTTP requests to arbitrary internal or external hosts via the pin-from-URL feature. The feature passes the user-supplied URL directly to requests.get() without host or IP validation, and ALLOW_NEW_REGISTRATIONS defaults to true enabling anonymous triggering. An attacker can reach internal services or cloud metadata endpoints from the server.
Published: August 11, 2026; 12:17:43 PM UTC
11 hours ago
|
|
CVE-2026-72605
7.5 (High)
Show References |
A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers to create arbitrary user accounts via the POST /auth/profile/create endpoint. The endpoint is allowlisted from JWT verification, permitting unauthenticated account creation. An attacker can register an account and use it to access protected functionality on the server.
Published: August 11, 2026; 12:17:43 PM UTC
11 hours ago
|
|
CVE-2026-72604
6.5 (Medium)
Show References |
A path traversal vulnerability in Intelliants Subrion CMS through 4.2.1 allows authenticated administrators to delete arbitrary files on the server via the admin panel file deletion endpoint. The endpoint passes a user-supplied file path directly to unlink() without sanitization or path canonicalization. An authenticated administrator can delete sensitive system files outside the web root, potentially causing server instability or facilitating further attacks.
Published: August 11, 2026; 12:17:43 PM UTC
11 hours ago
|
|
CVE-2026-72603
9.9 (Critical)
Show References |
An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited WireGuard PostUp directives into the client name field. The client name is written to the WireGuard configuration file without neutralizing newline characters, allowing injection of arbitrary directives that are executed by wg-quick with root privileges. An attacker with clients.create permission achieves root code execution on the host.
Published: August 11, 2026; 12:17:43 PM UTC
11 hours ago
|
|
CVE-2026-72602
7.5 (High)
Show References |
A path traversal vulnerability in AsyncFuncAI deepwiki-open through commit 16f35a0 allows unauthenticated remote attackers to obtain directory listings for arbitrary filesystem paths via the local-repository structure endpoint. The endpoint accepts an absolute filesystem path parameter and returns a directory listing without authentication, as WIKI_AUTH_MODE defaults to false. An attacker can enumerate sensitive directory contents on the host system.
Published: August 11, 2026; 12:17:43 PM UTC
11 hours ago
|
|
CVE-2026-72601
7.5 (High)
Show References |
A broken access control vulnerability in CSZ CMS 1.3.2 allows unauthenticated remote attackers to read all form submissions including personally identifiable information via the admin form-submission viewer. The viewer endpoint lacks an authentication check and the framework authentication helper fails open. An unauthenticated attacker can access all contact form submissions without credentials.
Published: August 11, 2026; 12:17:43 PM UTC
11 hours ago
|
|
CVE-2026-72600
7.5 (High)
Show References |
A broken access control vulnerability in Idurar IDURAR ERP CRM 4.1.0 allows unauthenticated remote attackers to download invoice PDF files containing customer PII via the /download router. The router is mounted without authentication middleware, making it publicly accessible. An attacker can enumerate MongoDB ObjectIds to download any invoice in the system without credentials.
Published: August 11, 2026; 12:17:43 PM UTC
11 hours ago
|
|
CVE-2026-72599
9.8 (Critical)
Show References |
An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbitrary SQL via the news item page ID parameter. The parameter is concatenated without escaping into a SQL WHERE clause. An unauthenticated attacker can read, modify, or delete all database contents including administrator credentials.
Published: August 11, 2026; 12:17:42 PM UTC
11 hours ago
|
|
CVE-2026-72598
6.5 (Medium)
Show References |
A server-side request forgery vulnerability in Apioo Fusio 8.8.3 allows authenticated consumer-role users to make the server issue HTTP requests to internal network addresses by registering a webhook URL pointing to an internal host. The webhook registration endpoint validates URL syntax via FILTER_VALIDATE_URL but applies no IP or host denylist. When the registered event fires, the server issues an HTTP POST to the attacker-supplied internal URL.
Published: August 11, 2026; 12:17:42 PM UTC
11 hours ago
|
|
CVE-2026-72597
6.5 (Medium)
Show References |
A server-side request forgery vulnerability in Friendica through the 2026.08-dev branch allows authenticated users with a free self-registered account to probe internal network services via the link-preview endpoint. The endpoint fetches any user-supplied URL without applying an internal IP deny list. An attacker can use this to scan the internal network or access cloud metadata services.
Published: August 11, 2026; 12:17:42 PM UTC
11 hours ago
|
|
CVE-2026-72596
8.1 (High)
Show References |
A broken access control vulnerability in Ghost Foundation Ghost 5.x allows authenticated Author-role users to delete posts owned by other users. The post model permissible() cascade is missing the branch that handles the combined isAuthor and isDestroy condition, causing the authorization check to fall through and permit the deletion. An attacker with an Author account can delete any post on the platform.
Published: August 11, 2026; 12:17:42 PM UTC
11 hours ago
|
|
CVE-2026-72595
8.1 (High)
Show References |
A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to update ticket records belonging to other teams via the TicketsController@update endpoint. The endpoint calls no authorize() method and performs no team-scoped ownership check. An attacker with any agent account can modify, escalate, or corrupt tickets assigned to other teams.
Published: August 11, 2026; 12:17:42 PM UTC
11 hours ago
|
|
CVE-2026-72563
8.1 (High)
Show References |
A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to overwrite lead records belonging to other teams via the LeadsController@update endpoint. The endpoint performs no authorization check, and the Lead model has guarded set to an empty array making all columns mass-assignable. An attacker with any agent account can corrupt lead data across team boundaries.
Published: August 11, 2026; 12:17:42 PM UTC
11 hours ago
|
|
CVE-2026-72562
8.8 (High)
Show References |
An SQL injection vulnerability in Pimcore admin-ui-classic-bundle through version 2.3 allows authenticated backend users to execute arbitrary SQL via the DataObject grid id column filter. The filter value is concatenated directly into the SQL WHERE clause without parameterization. An attacker with backend access can exfiltrate or modify all database contents.
Published: August 11, 2026; 12:17:42 PM UTC
11 hours ago
|
|
CVE-2026-72561
8.8 (High)
Show References |
A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 allows any authenticated non-administrative user to reconfigure the platform global OIDC/SSO settings via an unprotected configuration endpoint. The endpoint performs no administrative role check before applying new OIDC issuer settings. An attacker can redirect all SSO logins to an attacker-controlled identity provider, enabling credential harvesting for all platform users.
Published: August 11, 2026; 12:17:42 PM UTC
11 hours ago
|
|
CVE-2026-72560
6.5 (Medium)
Show References |
A server-side request forgery vulnerability in HumanSignal Label Studio through 1.24.0.dev0 exists because SSRF_PROTECTION_ENABLED is set to false by default. The import-from-URL endpoint fetches any caller-supplied URL including internal loopback addresses on the default installation. An authenticated user can use this to reach internal services, cloud metadata endpoints, and other resources not intended for external access.
Published: August 11, 2026; 12:17:41 PM UTC
11 hours ago
|
|
CVE-2026-72559
5.4 (Medium)
Show References |
A stored cross-site scripting vulnerability in HortusFox 5.9 allows authenticated workspace members to inject persistent JavaScript into plant notes via Parsedown rendered without safe mode. Notes are rendered unescaped in the browser of every user who views the affected plant. An attacker can use this to steal session cookies or perform actions in the context of other users including administrators.
Published: August 11, 2026; 12:17:41 PM UTC
11 hours ago
|
|
CVE-2026-72558
8.8 (High)
Show References |
An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows authenticated staff to read the entire database via the contact search RLIKE clause. The clause concatenates a user-supplied value into the SQL query without sanitization. An attacker with staff-level access can exfiltrate all database contents including donor and member records.
Published: August 11, 2026; 12:17:41 PM UTC
11 hours ago
|
|
CVE-2026-72557
8.8 (High)
Show References |
An unrestricted file upload vulnerability in Cockpit CMS 2.6.0 allows authenticated users to upload files of any extension including PHP scripts via the asset upload endpoint. The allowed_uploads configuration defaults to wildcard (*) and uploaded files are stored in a web-accessible directory. An attacker with any authenticated account can upload a PHP webshell and execute arbitrary OS commands on the server.
Published: August 11, 2026; 12:17:41 PM UTC
11 hours ago
|
|
CVE-2026-72556
8.8 (High)
Show References |
A remote code execution vulnerability in ZoneMinder 1.39.17 allows any authenticated user to execute OS commands by exploiting a broken permission check in the Filter class. The canEdit() and canDelete() methods invoke nonexistent methods on the ZM\User class, causing PHP __call() to return a truthy value that bypasses the permission check for all users. Any authenticated user can trigger filter-based OS command execution regardless of their assigned role.
Published: August 11, 2026; 12:17:41 PM UTC
11 hours ago
|
|
CVE-2026-72555
8.1 (High)
Show References |
A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 exists because the Config.roles_active flag defaults to false, causing all permission checks on ticket, client, and user handlers to behave as no-ops on default installations. All authenticated users bypass ownership and administrative access controls. An attacker with any user account can read, modify, or delete tickets, clients, and users belonging to any other account.
Published: August 11, 2026; 12:17:41 PM UTC
11 hours ago
|
|
CVE-2026-72554
6.5 (Medium)
Show References |
A broken access control vulnerability in Ladybird Web Solution Faveo Helpdesk 2.0.3 allows any self-registered customer to read ticket conversations belonging to other customers via the v1 REST API. The API verifies the existence of the requested ticket but not ownership, enabling any authenticated user to access arbitrary ticket threads including internal agent notes containing sensitive information.
Published: August 11, 2026; 12:17:41 PM UTC
11 hours ago
|
|
CVE-2026-72553
5.4 (Medium)
Show References |
A stored cross-site scripting vulnerability in ElkArte Forum 2.0 Beta 1 allows any registered member to inject persistent JavaScript into the profile fields cust_blurb and cust_locate. The fields are saved without HTML encoding and rendered unescaped in profile views visible to administrators. An attacker can craft a payload that executes in an administrator session, enabling session hijacking or privilege escalation.
Published: August 11, 2026; 12:17:40 PM UTC
11 hours ago
|
|
CVE-2026-72552
7.5 (High)
Show References |
A server-side request forgery vulnerability in Dub as of 2026-07-10 allows unauthenticated remote attackers to make the server issue HTTP requests to arbitrary internal or external hosts via the metatags edge endpoint. The endpoint fetches any caller-supplied URL without applying a denylist or requiring authentication. An attacker can use this to scan internal services or exfiltrate data from cloud metadata endpoints.
Published: August 11, 2026; 12:17:40 PM UTC
11 hours ago
|
|
CVE-2026-72551
8.8 (High)
Show References |
A remote code execution vulnerability in Apioo Fusio 8.8.3 allows authenticated users with the Developer role to execute arbitrary OS commands by exploiting a PHP-Sandbox allow-list bypass. The sandbox allow-list permits functions that transitively invoke system(), enabling a developer to escape the sandbox and gain OS command execution on the server. An attacker with a Developer-role account can achieve full server compromise.
Published: August 11, 2026; 12:17:40 PM UTC
11 hours ago
|
|
CVE-2026-72550
9.8 (Critical)
Show References |
An SQL injection vulnerability in Friendica through the 2026.08-dev branch allows unauthenticated remote attackers to execute arbitrary SQL statements via the photo-view order parameter. The parameter is concatenated unescaped into a SHOW COLUMNS query via a bare PDO::query() call, enabling stacked statement injection. An unauthenticated attacker can read, modify, or delete the entire database.
Published: August 11, 2026; 12:17:40 PM UTC
11 hours ago
|
|
CVE-2026-72549
5.3 (Medium)
Show References |
An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to map any email address or username to its internal user objectId via the getUserId Parse cloud function. The function performs no authentication before resolving and returning the internal identifier. An attacker can use this to enumerate user accounts and target subsequent attacks.
Published: August 11, 2026; 12:17:40 PM UTC
11 hours ago
|
|
CVE-2026-72548
7.5 (High)
Show References |
An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any organisation tenant record via the gettenant Parse cloud function. The function accepts a contactId parameter and returns the full tenant record without authentication or authorization checks. An attacker can enumerate and disclose tenant configuration data for any organisation in the system.
Published: August 11, 2026; 12:17:40 PM UTC
11 hours ago
|
|
CVE-2026-72547
7.1 (High)
Show References |
An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event organiser to bulk import attendees into events belonging to other accounts via the postImportAttendee endpoint. The endpoint loads the target event by ID without verifying ownership against the requesting organiser account. An attacker can inject bulk attendee data into any event in the system regardless of account boundaries.
Published: August 11, 2026; 12:17:40 PM UTC
11 hours ago
|
|
CVE-2026-72546
7.1 (High)
Show References |
An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event organiser to inject attendees and orders into events belonging to other accounts via the postInviteAttendee endpoint. The endpoint loads the target event by ID without scoping the query to the authenticated organiser account. An attacker can modify event data and financial records across account boundaries.
Published: August 11, 2026; 12:17:40 PM UTC
11 hours ago
|
|
CVE-2026-72545
7.5 (High)
Show References |
An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to write to any contact record via the updatecontacttour Parse cloud function. The function performs no authentication or authorization before updating the target contact record. An attacker can corrupt or overwrite contact data for any user in the system without credentials.
Published: August 11, 2026; 12:17:39 PM UTC
11 hours ago
|
|
CVE-2026-72544
7.5 (High)
Show References |
An integrity verification vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to forge document audit-trail entries via the triggerevent Parse cloud function. The function accepts viewer identity and IP address as caller-supplied parameters without authentication, allowing fabrication of arbitrary audit log entries. An attacker can tamper with the legal audit trail of any signed document, undermining non-repudiation.
Published: August 11, 2026; 12:17:39 PM UTC
11 hours ago
|
|
CVE-2026-72543
7.5 (High)
Show References |
An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any contact record via the getcontact Parse cloud function. The function executes with useMasterKey and performs no authentication or authorization checks before returning the requested contact object. An attacker can enumerate and read all contact records including personally identifiable information without credentials.
Published: August 11, 2026; 12:17:39 PM UTC
11 hours ago
|
|
CVE-2026-72542
5.4 (Medium)
Show References |
A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows authenticated operators to write job progress and read job metrics for any job in the workspace regardless of ownership. The job_metrics handlers accept no authorization extractor, bypassing workspace-level access controls. An operator can monitor sensitive job execution data and inject misleading progress for jobs they do not own.
Published: August 11, 2026; 12:17:39 PM UTC
11 hours ago
|
|
CVE-2026-72541
6.5 (Medium)
Show References |
A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace member to overwrite any resource type schema via the update_resource_type endpoint. The endpoint omits the administrator permission check that the corresponding delete_resource_type endpoint enforces. An attacker with workspace member privileges can corrupt resource type definitions, breaking workflows that depend on them.
Published: August 11, 2026; 12:17:39 PM UTC
11 hours ago
|
|
CVE-2026-72540
4.3 (Medium)
Show References |
An insecure direct object reference vulnerability in PhotoPrism through commit bb0b933 allows any user with a valid preview token to retrieve the original-resolution cover photo of any album. The AlbumCover handler does not verify that the requesting user is authorized to access the specified album before serving the cover image. An attacker with any valid preview token can enumerate and download album cover images belonging to other users.
Published: August 11, 2026; 12:17:39 PM UTC
11 hours ago
|
|
CVE-2026-72539
6.5 (Medium)
Show References |
An information disclosure vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace member to read legacy ownerless draft scripts that contain plaintext resource credentials. Drafts with a null owner email bypass ACL enforcement and are returned to any workspace member who queries the drafts endpoint. Sensitive credentials stored in these drafts are exposed across ACL boundaries.
Published: August 11, 2026; 12:17:39 PM UTC
11 hours ago
|
|
CVE-2026-72538
8.8 (High)
Show References |
An argument injection vulnerability in PrefectHQ Prefect through 3.8.2 allows authenticated users to achieve remote code execution via the git_clone pull step branch field. The branch parameter is passed directly to git pull without sanitization, enabling injection of arbitrary git arguments. This represents a distinct code path from the incomplete fix applied for CVE-2026-5366 and allows command execution on the Prefect server.
Published: August 11, 2026; 12:17:39 PM UTC
11 hours ago
|
|
CVE-2026-72537
8.8 (High)
Show References |
A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to take over any user account including superusers by provisioning a SCIM user that matches an existing local user by username. The SCIM user ingest function adopts pre-existing local accounts by username without validating scope boundaries. An attacker can rewrite or delete any account, including the superuser, using only a limited provisioning credential.
Published: August 11, 2026; 12:17:38 PM UTC
11 hours ago
|
|
CVE-2026-72536
8.6 (High)
Show References |
A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to manipulate any tenant Stripe subscription via the stripeCreateIntent GraphQL mutation. The mutation lacks authentication and authorization checks, exposing Stripe payment intent creation to unauthenticated callers. An attacker can create payment intents and alter billing for any tenant without credentials.
Published: August 11, 2026; 12:17:38 PM UTC
11 hours ago
|
|
CVE-2026-72535
8.6 (High)
Show References |
A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to mint Stripe Billing Portal sessions for any tenant via the stripeCustomerPortal GraphQL mutation. The mutation performs no authentication or authorization checks before creating a customer portal session linked to any tenant Stripe account. An attacker can access and manage subscription data for any tenant without credentials.
Published: August 11, 2026; 12:17:38 PM UTC
11 hours ago
|
|
CVE-2026-72534
8.8 (High)
Show References |
A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token to gain superuser privileges by provisioning a SCIM group that matches an existing administrator group by name. The SCIM group ingest function adopts any existing group by name and replaces its membership without validating the source scope against the target group. An attacker can grant their provisioning token full IdP superuser access and lock out all existing administrators.
Published: August 11, 2026; 12:17:38 PM UTC
11 hours ago
|
|
CVE-2026-72533
8.8 (High)
Show References |
An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypass Docker proxy authorization checks via non-canonical URL normalization, defeating all authorization middleware. The proxy endpoint fails to normalize request paths before applying access controls, allowing crafted requests to be interpreted differently by the proxy and the authorization layer. Successful exploitation grants the attacker root-level access to the underlying Docker host.
Published: August 11, 2026; 12:17:38 PM UTC
11 hours ago
|
|
CVE-2026-50237
7.4 (High)
Show References |
A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelmChartRepository with an arbitrary URL that the console pod fetches server-side, bypassing tenant egress restrictions. Combined with catalog metadata poisoning and admin-mediated chart installation, this enables privilege escalation.
Published: August 11, 2026; 12:17:38 PM UTC
11 hours ago
|
|
CVE-2026-50236
7.4 (High)
Show References |
An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflection from the console pod's privileged network position.
Published: August 11, 2026; 12:17:38 PM UTC
11 hours ago
|
|
CVE-2026-13739
8.8 (High)
Show References |
A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs. Software customers upgrade to resolved maintenance release. Update Command Center.
Published: August 11, 2026; 12:17:38 PM UTC
11 hours ago
|
|
CVE-2026-13738
9.2 (Critical)
Show References |
CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.
Published: August 11, 2026; 12:17:37 PM UTC
11 hours ago
|
|
CVE-2026-13737
9.2 (Critical)
Show References |
CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale X.
Published: August 11, 2026; 12:17:37 PM UTC
11 hours ago
|