Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44793
Total
3597
Critical
13314
High
13164
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-69836 | CRITICAL | 10.0 | Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network. | Aug 20, 2026 |
| CVE-2026-69558 | HIGH | 8.6 | Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network. | Aug 20, 2026 |
| CVE-2026-69555 | CRITICAL | 10.0 | Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | Aug 20, 2026 |
| CVE-2026-69543 | HIGH | 8.5 | Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network. | Aug 20, 2026 |
| CVE-2026-69519 | HIGH | 8.6 | Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network. | Aug 20, 2026 |
| CVE-2026-69419 | HIGH | 8.5 | Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network. | Aug 20, 2026 |
| CVE-2026-69400 | CRITICAL | 9.6 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. | Aug 20, 2026 |
| CVE-2026-68789 | CRITICAL | 9.9 | Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a … | Aug 20, 2026 |
| CVE-2026-68782 | CRITICAL | 9.9 | Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a … | Aug 20, 2026 |
| CVE-2026-67448 | MEDIUM | 6.5 | Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/server.go origin middleware checks the raw RequestURI for the /api/ … | Aug 20, 2026 |
| CVE-2026-67447 | MEDIUM | 5.3 | Mailpit is an email testing tool and API for developers. From 1.30.0 until 1.30.5, Mailpit's internal/smtpd/smtpd.go readData() function calls bufio.Reader.ReadBytes before applying the len(data)+len(line) size … | Aug 20, 2026 |
| CVE-2026-66800 | HIGH | 8.6 | Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network. | Aug 20, 2026 |
| CVE-2026-66309 | CRITICAL | 9.1 | Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | Aug 20, 2026 |
| CVE-2026-65816 | CRITICAL | 10.0 | Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | Aug 20, 2026 |
| CVE-2026-65801 | CRITICAL | 10.0 | Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network. | Aug 20, 2026 |
| CVE-2026-65770 | CRITICAL | 10.0 | Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over … | Aug 20, 2026 |
| CVE-2026-64773 | UNKNOWN | — | An attacker that can reach a container's published TCP port may be able to force the host's forwarding process to buffer an unbounded amount of … | Aug 20, 2026 |
| CVE-2026-63509 | CRITICAL | 9.9 | Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network. | Aug 20, 2026 |
| CVE-2026-62945 | MEDIUM | 4.3 | TREK is a collaborative travel planner. Prior to 3.1.3, TREK file upload, update, and link actions accept attacker-controlled reservation_id, place_id, and assignment_id values without using … | Aug 20, 2026 |
| CVE-2026-62834 | CRITICAL | 9.3 | Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network. | Aug 20, 2026 |
| CVE-2026-55894 | UNKNOWN | — | Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c sh_disassemble() function computes an idx value from a raw 16-bit instruction without ensuring it … | Aug 20, 2026 |
| CVE-2026-55893 | UNKNOWN | — | Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c SH floating-point decoders such as opFADD, opFMUL, and opFSUB call set_reg() and set_reg_n() using … | Aug 20, 2026 |
| CVE-2026-55769 | UNKNOWN | — | CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG opened superuser connections without pinning search_path in … | Aug 20, 2026 |
| CVE-2026-55765 | HIGH | 8.5 | CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG embedded cleartext role passwords in `ALTER ROLE` … | Aug 20, 2026 |
| CVE-2026-55491 | MEDIUM | 5.4 | BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton failed to escape meetingName in record-and-playback/screenshare/playback/index.html.erb when generating the screenshare playback format. A low-privileged user … | Aug 20, 2026 |