Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

48872
Total
3924
Critical
14491
High
14240
Medium
CVE ID Severity Score Description Published
CVE-2026-57105 HIGH 8.0 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Aug 11, 2026
CVE-2026-57104 HIGH 8.8 Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network. Aug 11, 2026
CVE-2026-56179 HIGH 8.3 Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network. Aug 11, 2026
CVE-2026-56174 HIGH 7.8 Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. Aug 11, 2026
CVE-2026-54984 HIGH 7.8 Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally. Aug 11, 2026
CVE-2026-54981 HIGH 7.8 Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally. Aug 11, 2026
CVE-2026-54123 MEDIUM 5.5 Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information locally. Aug 11, 2026
CVE-2026-54113 HIGH 7.5 Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network. Aug 11, 2026
CVE-2026-50516 CRITICAL 9.4 Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. Aug 11, 2026
CVE-2026-50472 HIGH 7.0 Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally. Aug 11, 2026
CVE-2026-49179 HIGH 8.8 Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network. Aug 11, 2026
CVE-2026-48483 MEDIUM 5.4 TypeBot is a chatbot builder tool. Prior to version 3.17.0, Typebot's WhatsApp status forwarding feature stores a workspace-configured webhook forwarding URL and later POSTs WhatsApp … Aug 11, 2026
CVE-2026-48446 MEDIUM 5.5 CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file … Aug 11, 2026
CVE-2026-48445 MEDIUM 6.2 CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability … Aug 11, 2026
CVE-2026-48444 MEDIUM 6.2 CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability … Aug 11, 2026
CVE-2026-48443 MEDIUM 6.2 CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust … Aug 11, 2026
CVE-2026-48442 HIGH 7.1 CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Arbitrary … Aug 11, 2026
CVE-2026-48440 HIGH 8.1 ColdFusion is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends … Aug 11, 2026
CVE-2026-48439 HIGH 7.5 CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust … Aug 11, 2026
CVE-2026-48438 HIGH 7.5 CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to … Aug 11, 2026
CVE-2026-48437 MEDIUM 5.5 CAI Content Credentials is affected by an Improper Certificate Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability … Aug 11, 2026
CVE-2026-48436 MEDIUM 6.5 CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability … Aug 11, 2026
CVE-2026-48435 MEDIUM 6.2 CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this … Aug 11, 2026
CVE-2026-48434 MEDIUM 6.2 CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust … Aug 11, 2026
CVE-2026-48387 MEDIUM 6.2 CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability … Aug 11, 2026