Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

44793
Total
3597
Critical
13314
High
13164
Medium
CVE ID Severity Score Description Published
CVE-2026-69836 CRITICAL 10.0 Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network. Aug 20, 2026
CVE-2026-69558 HIGH 8.6 Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network. Aug 20, 2026
CVE-2026-69555 CRITICAL 10.0 Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network. Aug 20, 2026
CVE-2026-69543 HIGH 8.5 Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network. Aug 20, 2026
CVE-2026-69519 HIGH 8.6 Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network. Aug 20, 2026
CVE-2026-69419 HIGH 8.5 Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network. Aug 20, 2026
CVE-2026-69400 CRITICAL 9.6 Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. Aug 20, 2026
CVE-2026-68789 CRITICAL 9.9 Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a … Aug 20, 2026
CVE-2026-68782 CRITICAL 9.9 Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a … Aug 20, 2026
CVE-2026-67448 MEDIUM 6.5 Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/server.go origin middleware checks the raw RequestURI for the /api/ … Aug 20, 2026
CVE-2026-67447 MEDIUM 5.3 Mailpit is an email testing tool and API for developers. From 1.30.0 until 1.30.5, Mailpit's internal/smtpd/smtpd.go readData() function calls bufio.Reader.ReadBytes before applying the len(data)+len(line) size … Aug 20, 2026
CVE-2026-66800 HIGH 8.6 Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network. Aug 20, 2026
CVE-2026-66309 CRITICAL 9.1 Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network. Aug 20, 2026
CVE-2026-65816 CRITICAL 10.0 Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network. Aug 20, 2026
CVE-2026-65801 CRITICAL 10.0 Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network. Aug 20, 2026
CVE-2026-65770 CRITICAL 10.0 Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over … Aug 20, 2026
CVE-2026-64773 UNKNOWN An attacker that can reach a container's published TCP port may be able to force the host's forwarding process to buffer an unbounded amount of … Aug 20, 2026
CVE-2026-63509 CRITICAL 9.9 Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network. Aug 20, 2026
CVE-2026-62945 MEDIUM 4.3 TREK is a collaborative travel planner. Prior to 3.1.3, TREK file upload, update, and link actions accept attacker-controlled reservation_id, place_id, and assignment_id values without using … Aug 20, 2026
CVE-2026-62834 CRITICAL 9.3 Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network. Aug 20, 2026
CVE-2026-55894 UNKNOWN Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c sh_disassemble() function computes an idx value from a raw 16-bit instruction without ensuring it … Aug 20, 2026
CVE-2026-55893 UNKNOWN Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c SH floating-point decoders such as opFADD, opFMUL, and opFSUB call set_reg() and set_reg_n() using … Aug 20, 2026
CVE-2026-55769 UNKNOWN CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG opened superuser connections without pinning search_path in … Aug 20, 2026
CVE-2026-55765 HIGH 8.5 CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG embedded cleartext role passwords in `ALTER ROLE` … Aug 20, 2026
CVE-2026-55491 MEDIUM 5.4 BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton failed to escape meetingName in record-and-playback/screenshare/playback/index.html.erb when generating the screenshare playback format. A low-privileged user … Aug 20, 2026