Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49232
Total
3944
Critical
14598
High
14363
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-56161 | CRITICAL | 9.6 | Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. | Aug 07, 2026 |
| CVE-2026-50515 | CRITICAL | 9.9 | Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. | Aug 07, 2026 |
| CVE-2026-50481 | CRITICAL | 9.9 | Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. | Aug 07, 2026 |
| CVE-2026-49163 | HIGH | 8.8 | Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network. | Aug 07, 2026 |
| CVE-2026-17264 | MEDIUM | 4.3 | Opening a crafted DICOM file containing malicious JPEG-compressed pixel data triggers an attacker-controlled heap out-of-bounds write, which may allow an attacker to remotely execute arbitrary … | Aug 07, 2026 |
| CVE-2026-15805 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 07, 2026 |
| CVE-2026-8325 | HIGH | 7.8 | A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause … | Aug 06, 2026 |
| CVE-2026-7867 | HIGH | 7.8 | A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the … | Aug 06, 2026 |
| CVE-2026-7406 | HIGH | 7.8 | A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability … | Aug 06, 2026 |
| CVE-2026-7405 | MEDIUM | 5.5 | A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A … | Aug 06, 2026 |
| CVE-2026-71555 | MEDIUM | 4.1 | PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. From 2.1.0 until 4.14.1, PILOS does not send a Cross-Origin-Opener-Policy response header, so pages … | Aug 06, 2026 |
| CVE-2026-71554 | MEDIUM | 5.3 | h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host … | Aug 06, 2026 |
| CVE-2026-71498 | MEDIUM | 5.1 | node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.26.1, passing a Buffer whose final bytes form a truncated (incomplete) multi-byte UTF-8 sequence … | Aug 06, 2026 |
| CVE-2026-71497 | MEDIUM | 4.7 | jsoup is a Java library for working with real-world HTML. From 1.14.3 until 1.23.1, jsoup's HTML parser could incorrectly handle a malformed tag name ending … | Aug 06, 2026 |
| CVE-2026-71488 | HIGH | 7.5 | league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have … | Aug 06, 2026 |
| CVE-2026-71478 | MEDIUM | 6.1 | league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsafe-link filter can be bypassed … | Aug 06, 2026 |
| CVE-2026-71476 | UNKNOWN | — | Nx is a monorepo solution for TypeScript and polyglot codebases. From version 20.8.0 until 22.7.7 and 23.0.2, the Nx self-hosted HTTP remote cache extracts downloaded … | Aug 06, 2026 |
| CVE-2026-71447 | UNKNOWN | — | AIL Project contains a stored cross-site scripting vulnerability in the translation controls displayed for chat messages and forum posts. The affected templates inserted message and … | Aug 06, 2026 |
| CVE-2026-71446 | UNKNOWN | — | AIL Framework contains a stored cross-site scripting vulnerability in the crawler domain view. Crawled URLs were embedded directly into the JavaScript onclick handler used to … | Aug 06, 2026 |
| CVE-2026-71445 | UNKNOWN | — | AIL Framework contained a reflected cross-site scripting vulnerability in the /tag/add_tags endpoint. When an error occurred while processing a tag operation, the application returned the … | Aug 06, 2026 |
| CVE-2026-71439 | UNKNOWN | — | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.6.0 until 11.16.1, Mermaid Radar Diagrams allow … | Aug 06, 2026 |
| CVE-2026-71438 | UNKNOWN | — | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid's configuration setters (mermaid.initialize, … | Aug 06, 2026 |
| CVE-2026-71437 | UNKNOWN | — | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.5.0 until 11.16.1, Mermaid Architecture Diagrams are … | Aug 06, 2026 |
| CVE-2026-71436 | UNKNOWN | — | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 10.6.0 until 10.9.8 and 11.16.1, Mermaid XY … | Aug 06, 2026 |
| CVE-2026-71435 | MEDIUM | 6.1 | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, the default ("automagic") form notification email rendered user-submitted values … | Aug 06, 2026 |