Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

49358
Total
3967
Critical
14633
High
14397
Medium
CVE ID Severity Score Description Published
CVE-2026-56162 CRITICAL 10.0 Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. Aug 07, 2026
CVE-2026-56161 CRITICAL 9.6 Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. Aug 07, 2026
CVE-2026-50515 CRITICAL 9.9 Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. Aug 07, 2026
CVE-2026-50481 CRITICAL 9.9 Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. Aug 07, 2026
CVE-2026-49163 HIGH 8.8 Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network. Aug 07, 2026
CVE-2026-17264 MEDIUM 4.3 Opening a crafted DICOM file containing malicious JPEG-compressed pixel data triggers an attacker-controlled heap out-of-bounds write, which may allow an attacker to remotely execute arbitrary … Aug 07, 2026
CVE-2026-15805 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Aug 07, 2026
CVE-2026-8325 HIGH 7.8 A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause … Aug 06, 2026
CVE-2026-7867 HIGH 7.8 A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the … Aug 06, 2026
CVE-2026-7406 HIGH 7.8 A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability … Aug 06, 2026
CVE-2026-7405 MEDIUM 5.5 A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A … Aug 06, 2026
CVE-2026-71555 MEDIUM 4.1 PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. From 2.1.0 until 4.14.1, PILOS does not send a Cross-Origin-Opener-Policy response header, so pages … Aug 06, 2026
CVE-2026-71554 MEDIUM 5.3 h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host … Aug 06, 2026
CVE-2026-71498 MEDIUM 5.1 node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.26.1, passing a Buffer whose final bytes form a truncated (incomplete) multi-byte UTF-8 sequence … Aug 06, 2026
CVE-2026-71497 MEDIUM 4.7 jsoup is a Java library for working with real-world HTML. From 1.14.3 until 1.23.1, jsoup's HTML parser could incorrectly handle a malformed tag name ending … Aug 06, 2026
CVE-2026-71488 HIGH 7.5 league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have … Aug 06, 2026
CVE-2026-71478 MEDIUM 6.1 league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsafe-link filter can be bypassed … Aug 06, 2026
CVE-2026-71476 UNKNOWN Nx is a monorepo solution for TypeScript and polyglot codebases. From version 20.8.0 until 22.7.7 and 23.0.2, the Nx self-hosted HTTP remote cache extracts downloaded … Aug 06, 2026
CVE-2026-71447 UNKNOWN AIL Project contains a stored cross-site scripting vulnerability in the translation controls displayed for chat messages and forum posts. The affected templates inserted message and … Aug 06, 2026
CVE-2026-71446 UNKNOWN AIL Framework contains a stored cross-site scripting vulnerability in the crawler domain view. Crawled URLs were embedded directly into the JavaScript onclick handler used to … Aug 06, 2026
CVE-2026-71445 UNKNOWN AIL Framework contained a reflected cross-site scripting vulnerability in the /tag/add_tags endpoint. When an error occurred while processing a tag operation, the application returned the … Aug 06, 2026
CVE-2026-71439 UNKNOWN Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.6.0 until 11.16.1, Mermaid Radar Diagrams allow … Aug 06, 2026
CVE-2026-71438 UNKNOWN Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid's configuration setters (mermaid.initialize, … Aug 06, 2026
CVE-2026-71437 UNKNOWN Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.5.0 until 11.16.1, Mermaid Architecture Diagrams are … Aug 06, 2026
CVE-2026-71436 UNKNOWN Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 10.6.0 until 10.9.8 and 11.16.1, Mermaid XY … Aug 06, 2026