Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
48872
Total
3924
Critical
14491
High
14240
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-57105 | HIGH | 8.0 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | Aug 11, 2026 |
| CVE-2026-57104 | HIGH | 8.8 | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network. | Aug 11, 2026 |
| CVE-2026-56179 | HIGH | 8.3 | Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network. | Aug 11, 2026 |
| CVE-2026-56174 | HIGH | 7.8 | Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. | Aug 11, 2026 |
| CVE-2026-54984 | HIGH | 7.8 | Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally. | Aug 11, 2026 |
| CVE-2026-54981 | HIGH | 7.8 | Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally. | Aug 11, 2026 |
| CVE-2026-54123 | MEDIUM | 5.5 | Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information locally. | Aug 11, 2026 |
| CVE-2026-54113 | HIGH | 7.5 | Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network. | Aug 11, 2026 |
| CVE-2026-50516 | CRITICAL | 9.4 | Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. | Aug 11, 2026 |
| CVE-2026-50472 | HIGH | 7.0 | Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally. | Aug 11, 2026 |
| CVE-2026-49179 | HIGH | 8.8 | Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network. | Aug 11, 2026 |
| CVE-2026-48483 | MEDIUM | 5.4 | TypeBot is a chatbot builder tool. Prior to version 3.17.0, Typebot's WhatsApp status forwarding feature stores a workspace-configured webhook forwarding URL and later POSTs WhatsApp … | Aug 11, 2026 |
| CVE-2026-48446 | MEDIUM | 5.5 | CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file … | Aug 11, 2026 |
| CVE-2026-48445 | MEDIUM | 6.2 | CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability … | Aug 11, 2026 |
| CVE-2026-48444 | MEDIUM | 6.2 | CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability … | Aug 11, 2026 |
| CVE-2026-48443 | MEDIUM | 6.2 | CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust … | Aug 11, 2026 |
| CVE-2026-48442 | HIGH | 7.1 | CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Arbitrary … | Aug 11, 2026 |
| CVE-2026-48440 | HIGH | 8.1 | ColdFusion is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends … | Aug 11, 2026 |
| CVE-2026-48439 | HIGH | 7.5 | CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust … | Aug 11, 2026 |
| CVE-2026-48438 | HIGH | 7.5 | CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to … | Aug 11, 2026 |
| CVE-2026-48437 | MEDIUM | 5.5 | CAI Content Credentials is affected by an Improper Certificate Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability … | Aug 11, 2026 |
| CVE-2026-48436 | MEDIUM | 6.5 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability … | Aug 11, 2026 |
| CVE-2026-48435 | MEDIUM | 6.2 | CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this … | Aug 11, 2026 |
| CVE-2026-48434 | MEDIUM | 6.2 | CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust … | Aug 11, 2026 |
| CVE-2026-48387 | MEDIUM | 6.2 | CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability … | Aug 11, 2026 |