CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2026-48407

    Last Modified: 13 Aug 2026

    Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Aug 2026
    7.8
    High

    CVE-2026-48404

    Last Modified: 13 Aug 2026

    Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Aug 2026
    7.8
    High

    CVE-2026-48410

    Last Modified: 13 Aug 2026

    Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Aug 2026
    7.8
    High

    CVE-2026-47940

    Last Modified: 13 Aug 2026

    Lightroom Classic is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 11 Aug 2026
    6.7
    Medium

    CVE-2026-65680

    Last Modified: 17 Aug 2026

    Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally.

    Published: 11 Aug 2026
    6.5
    Medium

    CVE-2026-73216

    Last Modified: 12 Aug 2026

    Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, shutdown_client_connection() in src/server/ns_turn_server.c prematurely calls dec_quota() and releases bandwidth accounting during the first-stage close of a mobility-enabled allocation while preserving the allocation, relay socket, session, and mobility ticket, allowing an authenticated client to bypass --user-quota and --total-quota and exhaust relay ports. This issue is fixed in version 4.17.0.

    Published: 11 Aug 2026
    4
    Medium

    CVE-2026-20712

    Last Modified: 13 Aug 2026

    Incomplete cleanup in some UEFI firmware for some Intel(R) reference platforms within UEFI may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.

    Published: 11 Aug 2026
    7.1
    High

    CVE-2026-73215

    Last Modified: 13 Aug 2026

    Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, turnports_allocate_even() in src/apps/relay/turn_ports.c marks the unused odd sibling port as TPS_TAKEN_ODD for an EVEN-PORT Allocate request with reservation bit R=0 even though no RTCP socket will release it, allowing an authenticated client to permanently exhaust the relay port pool and cause subsequent allocations to fail with STUN error 508. This issue is fixed in version 4.17.0.

    Published: 11 Aug 2026
    4
    Medium

    CVE-2026-20917

    Last Modified: 13 Aug 2026

    Exposure of sensitive information caused by incorrect data forwarding during transient execution for some Intel(R) Processors within Ring 0: Hypervisor and Kernel may allow information disclosure. System software adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.

    Published: 11 Aug 2026
    Unknown

    CVE-2026-19563

    Last Modified: 19 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 11 Aug 2026
    6.9
    Medium

    CVE-2026-72712

    Last Modified: 14 Aug 2026

    Nmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash the application by sending a crafted packet containing a zero-length TCP option. The malformed packet forces the Packet:parse_options() function in nselib/packet.lua to allocate objects in an infinite loop, causing an out-of-memory condition that results in application crash.

    Published: 11 Aug 2026
    Unknown

    CVE-2026-19562

    Last Modified: 19 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 11 Aug 2026
    Unknown

    CVE-2026-19561

    Last Modified: 19 Aug 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 11 Aug 2026
    8.2
    High

    CVE-2026-73214

    Last Modified: 12 Aug 2026

    Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, dtls_server_input_handler() and create_new_connected_udp_socket() in src/apps/relay/dtls_listener.c retain OpenSSL dtls1_reassemble_fragment() state for a 35-byte fragmented ClientHello declaring a 650,000-byte handshake before cookie validation, allowing an unauthenticated remote sender using fresh UDP tuples to exhaust memory without TURN credentials, a completed handshake, a valid cookie, or source spoofing. This issue is fixed in version 4.16.0.

    Published: 11 Aug 2026
    5.8
    Medium

    CVE-2026-73213

    Last Modified: 13 Aug 2026

    Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, addr_less_eq() in src/client/ns_turn_ioaddr.c uses a component-wise comparison for native IPv6 min-max intervals in ioa_addr_in_range(), allowing an authenticated TURN client to relay to an IPv6 peer that is numerically within a configured non-prefix-aligned denied-peer-ip range but is classified as outside it. This issue is fixed in version 4.16.0.

    Published: 11 Aug 2026
    5.8
    Medium

    CVE-2026-73212

    Last Modified: 12 Aug 2026

    Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.1, good_peer_addr() in src/server/ns_turn_server.c uses ioa_addr_in_range() in src/client/ns_turn_ioaddr.c without canonicalizing IPv4-compatible, 6to4, and 64:ff9b::/96 NAT64 address forms, allowing an authenticated RFC 6062 TCP CONNECT relay client to bypass an IPv4 denied-peer-ip range when the Coturn host has a useful translation route. This issue is fixed in version 4.13.1.

    Published: 11 Aug 2026
    4
    Medium

    CVE-2026-20901

    Last Modified: 28 Aug 2026

    Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable data alteration. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (high) and availability (none) impacts.

    Published: 11 Aug 2026
    5.5
    Medium

    CVE-2026-48790

    Last Modified: 13 Aug 2026

    Turso CLI is the command line interface (CLI) to the open-source database Turso. Versions prior to 1.0.26 persist the user's Turso platform JWT to `settings.json` using Viper's default `configPermissions` of `0o644`, leaving the credential file world-readable on standard Linux and macOS systems. Any other local UID on the host can read the file and recover the platform JWT, which grants full Turso platform access scoped to the user's organizations. Version 1.0.26 patches the issue.

    Published: 11 Aug 2026
    9.8
    Critical

    CVE-2026-73211

    Last Modified: 12 Aug 2026

    PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolates the attacker-controlled ActivityPub actor inboxUrl into an SQL query, allowing an unauthenticated remote server to read and write PeerTube database tables, including oAuthToken.accessToken, and take over administrator accounts. This issue is fixed in version 8.1.6.

    Published: 11 Aug 2026
    8.2
    High

    CVE-2026-48771

    Last Modified: 13 Aug 2026

    ishankportfolio is a portfolio website. Prior to version 1.0.1, contact form submissions could potentially be exposed due to improperly secured client-side database configuration and insufficient access control policies. Applications using publicly exposed database credentials or permissive database rules may allow unauthorised users to read, modify, or abuse stored form submission data. This could impact personally identifiable information (PII) submitted through the website contact form, including names, email addresses, phone numbers, and messages. The issue has been patched in version 1.0.1. Users unable to upgrade immediately can reduce risk by disabling public read/write database access, rotating exposed API keys, restricting database policies to authenticated requests only, moving sensitive operations to secure backend/serverless functions, and/or monitoring database activity logs for suspicious access.

    Published: 11 Aug 2026
    9.3
    Critical

    CVE-2026-73090

    Last Modified: 13 Aug 2026

    PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, processUpdateActivity and processUpdateVideo accept an ActivityPub Update containing a Video object without verifying that byActor.url is authorized for the host in videoObject.id, allowing a malicious federated server to rewrite another server's video metadata, visibility, media file, and HLS URLs. This issue is fixed in version 8.2.2.

    Published: 11 Aug 2026
    9.6
    Critical

    CVE-2026-47705

    Last Modified: 13 Aug 2026

    TypeBot is a chatbot builder tool. Version 3.16.1 has a CSV injection vulnerability in the result export functionality. The application does not sanitize or escape user-supplied input when generating CSV files. An attacker can inject spreadsheet formulas into input fields, which are later executed when an administrator opens the exported CSV in spreadsheet software such as Microsoft Excel or LibreOffice Calc. Version 3.17.0 patches the issue.

    Published: 11 Aug 2026
    7
    High

    CVE-2025-54512

    Last Modified: 13 Aug 2026

    A DLL hijacking vulnerability within the AMD Ryzen Master installation could allow a local user-privileged attacker to escalate privileges, potentially resulting in arbitrary code execution.

    Published: 11 Aug 2026
    7.6
    High

    CVE-2026-48767

    Last Modified: 12 Aug 2026

    TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to obtain a live Google Sheets OAuth access token for that workspace by calling the Google Sheets helper `getAccessToken`. The vulnerable path checks only whether the caller has read access to the workspace, decrypts the stored Google OAuth credential, refreshes or retrieves the access token through the Google client, and returns the raw bearer token directly to the caller. Because guest members can also enumerate credential identifiers, a guest can mint and reuse the workspace's Google access token outside Typebot. Version 3.17.0 patches the issue.

    Published: 11 Aug 2026
    8.7
    High

    CVE-2022-50997

    Last Modified: 14 Aug 2026

    Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint that allows unauthenticated remote attackers to extract arbitrary data from the backend database by manipulating the id GET parameter. Attackers can send a single crafted GET request with UNION-based injection payloads through the unsanitized id parameter to retrieve arbitrary data from the Microsoft SQL Server backend. This vulnerability is potentially remediated in software version 10.53 or 10.54. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-18 (UTC).

    Published: 11 Aug 2026
    5.6
    Medium

    CVE-2026-0465

    Last Modified: 13 Aug 2026

    A Use‑After‑Free (UAF) vulnerability in the AMD Ryzen™ Master Utility Driver could allow a local attacker to access kernel memory, potentially resulting in loss of availability

    Published: 11 Aug 2026
    8.7
    High

    CVE-2016-20097

    Last Modified: 13 Aug 2026

    Weaver (Fanwei) E-cology 8.0 contains a SQL injection vulnerability in the SignatureDownLoad servlet that allows unauthenticated remote attackers to read arbitrary files by injecting a UNION SELECT payload into the markId GET parameter, which is concatenated unsanitized into a SQL query. Attackers can control the markPath value returned by the query to supply an attacker-controlled filesystem path, causing the servlet to read and stream back arbitrary files accessible to the application server process, including sensitive configuration files containing database credentials. Disclosure materials indicate that this vulnerability has been remediated, but it's unclear which version resolved the issue. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-18 (UTC).

    Published: 11 Aug 2026
    7
    High

    CVE-2025-0046

    Last Modified: 13 Aug 2026

    Incorrect directory permissions could allow a local user to escalate their privileges, potentially resulting in arbitrary code execution.

    Published: 11 Aug 2026
    7.1
    High

    CVE-2026-48494

    Last Modified: 13 Aug 2026

    TypeBot is a chatbot builder tool. In version 3.16.1, an authenticated user who has read access to any typebot can resume a WhatsApp preview webhook session that belongs to a different typebot by mixing an authorized `typebotId` and `blockId` and a foreign preview phone number tied to another preview session. The WhatsApp test-webhook handler authorizes the parent typebot first, but then resolves the preview chat session only by `wa-preview-{phone}`. As a result, an attacker can inject arbitrary webhook JSON into another workspace's WhatsApp preview session and advance its draft/unpublished flow without any access to the victim typebot. Version 3.17.0 patches the issue.

    Published: 11 Aug 2026
    7
    High

    CVE-2025-8087

    Last Modified: 13 Aug 2026

    A DLL hijacking vulnerability in AMD Power Design Manager could allow a malicious local attacker to escalate privileges during the uninstallation process, potentially resulting in arbitrary code execution.

    Published: 11 Aug 2026
    8.8
    High

    CVE-2026-62869

    Last Modified: 13 Aug 2026

    Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network.

    Published: 11 Aug 2026
    9.4
    Critical

    CVE-2026-50516

    Last Modified: 12 Aug 2026

    Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

    Published: 11 Aug 2026
    4.6
    Medium

    CVE-2026-62917

    Last Modified: 13 Aug 2026

    Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

    Published: 11 Aug 2026
    6.5
    Medium

    CVE-2026-62839

    Last Modified: 14 Aug 2026

    Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

    Published: 11 Aug 2026
    6.5
    Medium

    CVE-2026-58639

    Last Modified: 14 Aug 2026

    Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

    Published: 11 Aug 2026
    8.8
    High

    CVE-2026-65767

    Last Modified: 16 Aug 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.

    Published: 11 Aug 2026
    7.5
    High

    CVE-2026-62898

    Last Modified: 14 Aug 2026

    Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.

    Published: 11 Aug 2026
    5.5
    Medium

    CVE-2026-62738

    Last Modified: 14 Aug 2026

    Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.

    Published: 11 Aug 2026
    8.1
    High

    CVE-2026-71331

    Last Modified: 20 Aug 2026

    Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.

    Published: 11 Aug 2026
    7.8
    High

    CVE-2026-70354

    Last Modified: 17 Aug 2026

    Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.

    Published: 11 Aug 2026
    7.8
    High

    CVE-2026-63522

    Last Modified: 17 Aug 2026

    Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally.

    Published: 11 Aug 2026
    8.8
    High

    CVE-2026-70337

    Last Modified: 14 Aug 2026

    Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.

    Published: 11 Aug 2026
    7.8
    High

    CVE-2026-70338

    Last Modified: 14 Aug 2026

    Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.

    Published: 11 Aug 2026
    8.8
    High

    CVE-2026-70326

    Last Modified: 14 Aug 2026

    Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

    Published: 11 Aug 2026
    9.3
    Critical

    CVE-2026-70306

    Last Modified: 13 Aug 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

    Published: 11 Aug 2026
    8.4
    High

    CVE-2026-70130

    Last Modified: 14 Aug 2026

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

    Published: 11 Aug 2026
    8.3
    High

    CVE-2026-56179

    Last Modified: 14 Aug 2026

    Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.

    Published: 11 Aug 2026
    7.8
    High

    CVE-2026-68817

    Last Modified: 13 Aug 2026

    Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 11 Aug 2026
    7.8
    High

    CVE-2026-68814

    Last Modified: 13 Aug 2026

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 11 Aug 2026
    7.8
    High

    CVE-2026-68812

    Last Modified: 13 Aug 2026

    Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

    Published: 11 Aug 2026