CVE Feed

    Dashboard / CVE

    8.6
    High

    CVE-2026-69558

    Last Modified: 25 Aug 2026

    Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.

    Published: 20 Aug 2026
    10
    Critical

    CVE-2026-69555

    Last Modified: 29 Aug 2026

    Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

    Published: 20 Aug 2026
    9.6
    Critical

    CVE-2026-69400

    Last Modified: 24 Aug 2026

    Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

    Published: 20 Aug 2026
    8.5
    High

    CVE-2026-69419

    Last Modified: 4 Sept 2026

    Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network.

    Published: 20 Aug 2026
    9.9
    Critical

    CVE-2026-68782

    Last Modified: 24 Aug 2026

    Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

    Published: 20 Aug 2026
    9.1
    Critical

    CVE-2026-66309

    Last Modified: 24 Aug 2026

    Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

    Published: 20 Aug 2026
    10
    Critical

    CVE-2026-65816

    Last Modified: 24 Aug 2026

    Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

    Published: 20 Aug 2026
    9.9
    Critical

    CVE-2026-63509

    Last Modified: 4 Sept 2026

    Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.

    Published: 20 Aug 2026
    10
    Critical

    CVE-2026-65770

    Last Modified: 25 Aug 2026

    Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.

    Published: 20 Aug 2026
    7.1
    High

    CVE-2026-16989

    Last Modified: 24 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper resolution of symbolic links.

    Published: 20 Aug 2026
    6.5
    Medium

    CVE-2026-70105

    Last Modified: 4 Sept 2026

    Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

    Published: 20 Aug 2026
    5.3
    Medium

    CVE-2026-54508

    Last Modified: 21 Aug 2026

    TREK is a collaborative travel planner. Prior to 3.1.0, TREK validates only the initial URL before native redirect following in importGoogleList() and importNaverList() in server/src/services/placeService.ts and resolveGoogleMapsUrl() in server/src/services/mapsService.ts. The affected sinks call checkSsrf() from server/src/utils/ssrfGuard.ts and then use fetch() with redirect: 'follow' instead of the DNS-pinned safeFetch() path, so a public attacker-controlled URL can redirect the server to loopback, RFC 1918, or cloud metadata addresses without revalidation. An authenticated trip member can reach the list-import routes, and any authenticated user can reach /api/maps/resolve-url, allowing blind GET requests to internal services without response-body reflection. This issue is fixed in version 3.1.0.

    Published: 20 Aug 2026
    6.3
    Medium

    CVE-2026-16980

    Last Modified: 24 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to improper validation of symbolic links.

    Published: 20 Aug 2026
    5.5
    Medium

    CVE-2026-16973

    Last Modified: 24 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to disclose sensitive kernel memory due to an out-of-bounds read.

    Published: 20 Aug 2026
    6.5
    Medium

    CVE-2026-16972

    Last Modified: 24 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information due to improper authentication.

    Published: 20 Aug 2026
    6.5
    Medium

    CVE-2026-16964

    Last Modified: 25 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to intercept messages and forge replies due to the exposure of sensitive information.

    Published: 20 Aug 2026
    6.5
    Medium

    CVE-2026-16958

    Last Modified: 24 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.

    Published: 20 Aug 2026
    5.5
    Medium

    CVE-2026-16952

    Last Modified: 24 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to uncontrolled resource consumption.

    Published: 20 Aug 2026
    7.1
    High

    CVE-2026-55013

    Last Modified: 26 Aug 2026

    Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally.

    Published: 20 Aug 2026
    5.5
    Medium

    CVE-2026-55015

    Last Modified: 26 Aug 2026

    Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally.

    Published: 20 Aug 2026
    6.7
    Medium

    CVE-2026-16951

    Last Modified: 24 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local authenticated attacker to execute arbitrary code due to a heap-based buffer overflow.

    Published: 20 Aug 2026
    2
    Low

    CVE-2026-54505

    Last Modified: 25 Aug 2026

    TREK is a collaborative travel planner. Prior to 3.1.0, when the Journey add-on is enabled, TREK interpolates the unescaped activeSuggestion.title value into journey.frontpage.suggestionText through client/src/i18n/TranslationContext.tsx and renders the result with dangerouslySetInnerHTML in client/src/pages/JourneyPage.tsx. A trip owner can store HTML in a qualifying trip title, and GET /api/journeys/suggestions returns that title through getSuggestions(userId) to a collaborator who opens the authenticated Journey page. The markup is inserted as live DOM in the collaborator's session, enabling content spoofing and UI redress, although the default Content Security Policy blocks inline handlers and script execution. This issue is fixed in version 3.1.0.

    Published: 20 Aug 2026
    10
    Critical

    CVE-2026-69836

    Last Modified: 29 Aug 2026

    Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

    Published: 20 Aug 2026
    9.9
    Critical

    CVE-2026-69851

    Last Modified: 25 Aug 2026

    Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

    Published: 20 Aug 2026
    8.6
    High

    CVE-2026-69519

    Last Modified: 25 Aug 2026

    Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.

    Published: 20 Aug 2026
    9.9
    Critical

    CVE-2026-68789

    Last Modified: 24 Aug 2026

    Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

    Published: 20 Aug 2026
    10
    Critical

    CVE-2026-65801

    Last Modified: 24 Aug 2026

    Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.

    Published: 20 Aug 2026
    9.3
    Critical

    CVE-2026-62834

    Last Modified: 24 Aug 2026

    Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.

    Published: 20 Aug 2026
    9.4
    Critical

    CVE-2026-55769

    Last Modified: 21 Aug 2026

    CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG opened superuser connections without pinning search_path in fillDefaultParameters in pkg/management/postgres/pool/profiles.go. A role holding DATABASE OWNER could create overloaded built-in operators in the public schema and change the database or role search_path, causing instance-manager introspection queries such as SELECT COUNT(*) > 0 FROM pg_catalog.pg_extension WHERE extname = $1 to execute attacker-controlled functions as the postgres superuser. The same trust issue affected direct sql.Open("pgx", ...) callsites and the public.user_search SECURITY DEFINER function, enabling PostgreSQL superuser access, operating system command execution through COPY ... FROM PROGRAM, and access to the pod ServiceAccount token. This issue is fixed in versions 1.28.4, 1.29.2, and 1.30.0.

    Published: 20 Aug 2026
    7.3
    High

    CVE-2026-49436

    Last Modified: 21 Aug 2026

    LinkAce is a self-hosted archive to collect website links. Prior to version 2.5.7, the Bulk Link API endpoint (`POST /api/v2/bulk/links`) accepts URLs without any format validation, allowing an authenticated user to store a `javascript:` URI. The stored URI is later rendered verbatim as an `href` in Blade templates, and clicking it executes arbitrary JavaScript in the victim's browser — exfiltrating cookies and session tokens. Version 2.5.7 fixes the issue.

    Published: 20 Aug 2026
    8.5
    High

    CVE-2026-55765

    Last Modified: 25 Aug 2026

    CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG embedded cleartext role passwords in `ALTER ROLE` and `CREATE ROLE` statements generated by SetUserPassword in pkg/management/postgres/utils/roles.go and appendPasswordOption in internal/management/controller/roles/postgres.go. When pg_stat_statements was preloaded with track_utility enabled and an untrusted tenant held pg_monitor or pg_read_all_stats, the tenant could recover platform-managed superuser or application-owner passwords, reconnect through enabled superuser TCP access, and execute operating system commands in the database pod with `COPY ... FROM PROGRAM`. Clusters using SCRAM-SHA-256 verifiers in managed-role Secrets were not affected. This issue is fixed in versions 1.28.4, 1.29.2, and 1.30.0.

    Published: 20 Aug 2026
    6.9
    Medium

    CVE-2026-50192

    Last Modified: 21 Aug 2026

    Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the Kerberos Hub upload path sends the agent's Hub credentials in the custom `X-Kerberos-Hub-PrivateKey` and `X-Kerberos-Hub-PublicKey` request headers to the operator-configured Hub URL (`config.HubURI`). The HTTP client used (`&http.Client{}` in `UploadKerberosHub`) is constructed without a `CheckRedirect` policy, so it follows HTTP redirects automatically. Go's `net/http` strips only sensitive headers (`Authorization`, `Cookie`, `WWW-Authenticate`) on a cross-host redirect; it does not strip custom headers such as `X-Kerberos-Hub-PrivateKey`. As a result, if the configured `HubURI` returns a cross-host 30x redirect, the Hub private key is forwarded verbatim to the redirect target, disclosing the credential to an unintended third party. Version 3.6.26 fixes the issue by implementing the `CheckRedirect` strip plus a cross-host regression test is provided to the maintainer through the advisory's private temporary fork.

    Published: 20 Aug 2026
    4.9
    Medium

    CVE-2026-55489

    Last Modified: 21 Aug 2026

    BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton presenters could submit a presentationId through /api/graphql that identified a presentation belonging to another meeting. akka-bbb-apps/src/main/scala/org/bigbluebutton/core/apps/presentationpod/RemovePresentationPubMsgHdlr.scala did not verify the presentation's meeting identifier before deletion, allowing a presenter who knew the identifier to delete another meeting's presentation and disrupt its availability. This issue is fixed in version 3.0.29.

    Published: 20 Aug 2026
    5.4
    Medium

    CVE-2026-55491

    Last Modified: 21 Aug 2026

    BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton failed to escape meetingName in record-and-playback/screenshare/playback/index.html.erb when generating the screenshare playback format. A low-privileged user could store a crafted meeting name that embedded script content, and the script executed in another user's browser when that user replayed the recording. This issue is fixed in version 3.0.29.

    Published: 20 Aug 2026
    6.3
    Medium

    CVE-2026-72860

    Last Modified: 25 Aug 2026

    The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP requests to it, guarding the destination with assertPublicUrl from src/shared/utils/ssrfGuard.js. That guard compares hostname strings only: it resolves no DNS, does not revalidate after a redirect, and its IPv4-mapped IPv6 branch is unreachable. The branch matches ^::ffff:(\d+\.\d+\.\d+\.\d+)$, but the WHATWG URL parser canonicalizes such literals to hextets before the guard runs, so new URL("http://[::ffff:127.0.0.1]/").hostname yields [::ffff:7f00:1] and the pattern is tested against a string it is never handed. Every IPv4-mapped address therefore passes, and http://[::ffff:7f00:1] and http://[::ffff:a9fe:a9fe] reach loopback and link-local metadata addresses; a hostname whose A record points at an internal address passes as well because no resolution occurs. In the custom-embedding branch the upstream response body is truncated to 200 bytes and returned to the caller whenever the upstream status is neither 2xx nor 401 nor 403, which discloses the beginning of internal responses, and the other validation types remain usable for blind internal port scanning through status and timing differences. The caller-supplied apiKey is forwarded to the internal destination as an Authorization Bearer header. A dashboard session is required by default, and none is required when requireLogin is disabled.

    Published: 20 Aug 2026
    7.1
    High

    CVE-2026-46355

    Last Modified: 25 Aug 2026

    BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton exposed /bigbluebutton/api/handleJoinExistingUser through bigbluebutton-web/grails-app/controllers/org/bigbluebutton/web/controllers/ApiController.groovy. A requester able to supply an existingUserID for an active participant could reuse that participant's session and impersonate the participant in the same meeting because handleJoinExistingUser was a routable controller action rather than a private helper. This issue is fixed in version 3.0.23.

    Published: 20 Aug 2026
    7.8
    High

    CVE-2026-16946

    Last Modified: 24 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a heap buffer overflow.

    Published: 20 Aug 2026
    7.8
    High

    CVE-2026-16945

    Last Modified: 26 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a stack-based buffer overflow.

    Published: 20 Aug 2026
    8.5
    High

    CVE-2026-46682

    Last Modified: 21 Aug 2026

    BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authenticated moderators to inject SQL through the meetingId and userId values used by refreshBreakoutRoomsVisibleForUsers in akka-bbb-apps/src/main/scala/org/bigbluebutton/core/db/BreakoutRoomUserDAO.scala. The method interpolated those values into breakout room visibility queries, allowing arbitrary SQL execution against the application database. This issue is fixed in version 3.0.23.

    Published: 20 Aug 2026
    6.7
    Medium

    CVE-2026-16944

    Last Modified: 24 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a stack-based buffer overflow.

    Published: 20 Aug 2026
    8.2
    High

    CVE-2026-16943

    Last Modified: 24 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a heap-based buffer overflow.

    Published: 20 Aug 2026
    7.8
    High

    CVE-2026-16937

    Last Modified: 24 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management.

    Published: 20 Aug 2026
    8.8
    High

    CVE-2026-16936

    Last Modified: 24 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a buffer overflow.

    Published: 20 Aug 2026
    7.3
    High

    CVE-2026-55893

    Last Modified: 21 Aug 2026

    Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c SH floating-point decoders such as opFADD, opFMUL, and opFSUB call set_reg() and set_reg_n() using sh_info.op.op_count without checking the fixed-size operands[] array. Repeated crafted instructions processed through cs_disasm_iter() or cs_disasm() with CS_ARCH_SH, CS_MODE_SH2A or CS_MODE_SH4A, CS_MODE_SHFPU, and CS_OPT_DETAIL can increment the operand count beyond the 176-byte sh_info allocation and perform a four-byte heap buffer overflow write. The corruption can crash the process and may enable code execution depending on heap layout. This issue is fixed in version 6.0.0-Alpha10.

    Published: 20 Aug 2026
    7.8
    High

    CVE-2026-16935

    Last Modified: 26 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a time-of-check to time-of-use (TOCTOU) race condition.

    Published: 20 Aug 2026
    8.8
    High

    CVE-2026-16934

    Last Modified: 24 Aug 2026

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a heap-based buffer overflow.

    Published: 20 Aug 2026
    6.8
    Medium

    CVE-2026-55894

    Last Modified: 21 Aug 2026

    Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c sh_disassemble() function computes an idx value from a raw 16-bit instruction without ensuring it is within the active mode-specific decode[] function-pointer table. An application using CS_ARCH_SH with CS_MODE_SH2A or CS_MODE_SH4A and CS_MODE_SHFPU can pass crafted bytecode through cs_disasm_iter() or cs_disasm(), causing the decode[idx] test to read outside the table and terminate the process with a segmentation fault. No code execution or information disclosure was demonstrated. This issue is fixed in version 6.0.0-Alpha10.

    Published: 20 Aug 2026
    6.5
    Medium

    CVE-2026-67448

    Last Modified: 21 Aug 2026

    Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/server.go origin middleware checks the raw RequestURI for the /api/ prefix while Go's ServeMux routes using the percent-decoded URL path, and server/websockets/client.go configures websocket.Upgrader.CheckOrigin to return true. A malicious website can request /%61pi/events, skip corsOriginAccessControl(), reach the /api/events WebSocket handler, and receive live message IDs, Message-Id values, sender and recipient fields, subjects, tags, and body snippets from an unauthenticated default Mailpit instance after the user visits the site. This is a regression of the earlier WebSocket origin protection and does not affect deployments protected by --ui-auth-file. This issue is fixed in version 1.30.6.

    Published: 20 Aug 2026
    4.4
    Medium

    CVE-2026-77643

    Last Modified: 21 Aug 2026

    A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). NOTE: this issue exists because of a missed corner case of CVE-2018-0499.

    Published: 20 Aug 2026
    7.5
    High

    CVE-2026-64773

    Last Modified: 1 Sept 2026

    An attacker that can reach a container's published TCP port may be able to force the host's forwarding process to buffer an unbounded amount of that client's data in memory, for as long as the backend container connection takes to complete — with no cap on how much accumulates or how long the wait can be stretched. This vulnerability is addressed in container version 1.2.0.

    Published: 20 Aug 2026