CVE Feed

    Dashboard / CVE

    5.6
    Medium

    CVE-2026-59130

    Last Modified: 25 Aug 2026

    No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.

    Published: 11 Aug 2026
    8.8
    High

    CVE-2026-59133

    Last Modified: 28 Aug 2026

    Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network.

    Published: 11 Aug 2026
    5.5
    Medium

    CVE-2026-59128

    Last Modified: 17 Aug 2026

    Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.

    Published: 11 Aug 2026
    7.8
    High

    CVE-2026-59127

    Last Modified: 17 Aug 2026

    Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.

    Published: 11 Aug 2026
    9.8
    Critical

    CVE-2026-59124

    Last Modified: 16 Aug 2026

    Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.

    Published: 11 Aug 2026
    6.5
    Medium

    CVE-2026-47285

    Last Modified: 12 Aug 2026

    Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose information over a network.

    Published: 11 Aug 2026
    7.2
    High

    CVE-2026-47299

    Last Modified: 13 Aug 2026

    Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network.

    Published: 11 Aug 2026
    8.8
    High

    CVE-2026-59113

    Last Modified: 12 Aug 2026

    Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.

    Published: 11 Aug 2026
    7.4
    High

    CVE-2026-58612

    Last Modified: 17 Aug 2026

    Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.

    Published: 11 Aug 2026
    8.8
    High

    CVE-2026-49179

    Last Modified: 17 Aug 2026

    Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.

    Published: 11 Aug 2026
    7.8
    High

    CVE-2026-54984

    Last Modified: 17 Aug 2026

    Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.

    Published: 11 Aug 2026
    7.5
    High

    CVE-2026-54113

    Last Modified: 17 Aug 2026

    Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.

    Published: 11 Aug 2026
    6.5
    Medium

    CVE-2026-40375

    Last Modified: 17 Aug 2026

    Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.

    Published: 11 Aug 2026
    8.1
    High

    CVE-2026-63520

    Last Modified: 17 Aug 2026

    Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

    Published: 11 Aug 2026
    6.5
    Medium

    CVE-2026-63516

    Last Modified: 12 Aug 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

    Published: 11 Aug 2026
    6.5
    Medium

    CVE-2026-63512

    Last Modified: 17 Aug 2026

    Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.

    Published: 11 Aug 2026
    8.8
    High

    CVE-2026-63514

    Last Modified: 13 Aug 2026

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

    Published: 11 Aug 2026
    6.5
    Medium

    CVE-2026-62837

    Last Modified: 17 Aug 2026

    Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

    Published: 11 Aug 2026
    8.8
    High

    CVE-2026-62827

    Last Modified: 12 Aug 2026

    Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

    Published: 11 Aug 2026
    4.6
    Medium

    CVE-2026-62829

    Last Modified: 11 Aug 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

    Published: 11 Aug 2026
    8
    High

    CVE-2026-57105

    Last Modified: 17 Aug 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

    Published: 11 Aug 2026
    8.8
    High

    CVE-2026-65768

    Last Modified: 12 Aug 2026

    Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.

    Published: 11 Aug 2026
    7.8
    High

    CVE-2026-58650

    Last Modified: 12 Aug 2026

    Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

    Published: 11 Aug 2026
    7.8
    High

    CVE-2026-56174

    Last Modified: 17 Aug 2026

    Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

    Published: 11 Aug 2026
    7
    High

    CVE-2026-50472

    Last Modified: 17 Aug 2026

    Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.

    Published: 11 Aug 2026
    9.1
    Critical

    CVE-2026-69223

    Last Modified: 17 Aug 2026

    Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.

    Published: 11 Aug 2026
    4.6
    Medium

    CVE-2025-48506

    Last Modified: 13 Aug 2026

    Uncontrolled search paths in Vitis™ Unified installation path on local Windows machines could allow DLL injection into these install paths, potentially resulting in arbitrary code execution.

    Published: 11 Aug 2026
    7.5
    High

    CVE-2026-73088

    Last Modified: 17 Aug 2026

    Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, normalizeStats() in node.js, reached unconditionally through getStat() and loadStat() on every browserslist() call, processes untrusted browserslist-stats.json, opts.stats, and CLI --stats data with an unguarded for...in loop and plain-object bracket access and assignment, allowing inherited Object.prototype keys including __proto__, toString, valueOf, constructor, hasOwnProperty, and isPrototypeOf to cause an uncaught TypeError or modify the prototype of the returned normalized object. This issue is fixed in version 4.28.7.

    Published: 11 Aug 2026
    6.2
    Medium

    CVE-2026-48434

    Last Modified: 14 Aug 2026

    CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.

    Published: 11 Aug 2026
    1
    Low

    CVE-2025-61970

    Last Modified: 13 Aug 2026

    Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to create arbitrary code, potentially resulting in binary hijacking.

    Published: 11 Aug 2026
    6.2
    Medium

    CVE-2026-48443

    Last Modified: 14 Aug 2026

    CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.

    Published: 11 Aug 2026
    4.7
    Medium

    CVE-2026-47922

    Last Modified: 14 Aug 2026

    CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.

    Published: 11 Aug 2026
    4
    Medium

    CVE-2026-71390

    Last Modified: 14 Aug 2026

    CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized limited write access. Exploitation of this issue does not require user interaction.

    Published: 11 Aug 2026
    7.1
    High

    CVE-2026-48442

    Last Modified: 14 Aug 2026

    CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Arbitrary file system read. An attacker could leverage this vulnerability to gain unauthorized read access to files or directories outside the intended restrictions. Exploitation of this issue does not require user interaction. Scope is changed.

    Published: 11 Aug 2026
    6.2
    Medium

    CVE-2026-48445

    Last Modified: 14 Aug 2026

    CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.

    Published: 11 Aug 2026
    6.2
    Medium

    CVE-2026-48387

    Last Modified: 14 Aug 2026

    CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.

    Published: 11 Aug 2026
    6.5
    Medium

    CVE-2026-48436

    Last Modified: 14 Aug 2026

    CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.

    Published: 11 Aug 2026
    7.5
    High

    CVE-2026-48438

    Last Modified: 14 Aug 2026

    CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.

    Published: 11 Aug 2026
    5.5
    Medium

    CVE-2026-48446

    Last Modified: 14 Aug 2026

    CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.

    Published: 11 Aug 2026
    6.2
    Medium

    CVE-2026-48444

    Last Modified: 14 Aug 2026

    CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.

    Published: 11 Aug 2026
    6.2
    Medium

    CVE-2026-48435

    Last Modified: 14 Aug 2026

    CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.

    Published: 11 Aug 2026
    7.5
    High

    CVE-2026-48439

    Last Modified: 14 Aug 2026

    CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.

    Published: 11 Aug 2026
    5.5
    Medium

    CVE-2026-48437

    Last Modified: 14 Aug 2026

    CAI Content Credentials is affected by an Improper Certificate Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.

    Published: 11 Aug 2026
    6.2
    Medium

    CVE-2026-71389

    Last Modified: 14 Aug 2026

    CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue does not require user interaction.

    Published: 11 Aug 2026
    9.8
    Critical

    CVE-2026-12571

    Last Modified: 13 Aug 2026

    An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.

    Published: 11 Aug 2026
    2.3
    Low

    CVE-2026-73087

    Last Modified: 13 Aug 2026

    Dozzle is a realtime log viewer for docker containers. From 10.5.2 until 10.6.15, the isBlockedIP SSRF guard in internal/notification/dispatcher/webhook.go, used by safeDialContext for webhook notification URLs, does not inspect IPv4 addresses embedded in 6to4, NAT64, Teredo, or IPv4-compatible IPv6 addresses, allowing an authenticated user to reach loopback or link-local targets that the guard intends to block. This issue is fixed in version 10.6.15.

    Published: 11 Aug 2026
    4.6
    Medium

    CVE-2025-0041

    Last Modified: 13 Aug 2026

    Uncontrolled search paths in the Vitis™ Embedded Single File Download (SFD) for local Windows installation could allow a low-privileged user to create arbitrary code execution.

    Published: 11 Aug 2026
    8.5
    High

    CVE-2026-43606

    Last Modified: 13 Aug 2026

    Observable Timing Discrepancy in the AMD Vitis Libraries ECDSA secp256k1 component could allow attackers with local access to potentially perform timing analysis or electromagnetic emanation attacks, resulting in high confidentiality and integrity impact due to the exposure of private cryptographic keys.

    Published: 11 Aug 2026
    7.4
    High

    CVE-2026-73086

    Last Modified: 13 Aug 2026

    nanoid is a secure, URL-friendly, unique string ID generator for JavaScript. Prior to versions 3.3.12 and 5.1.11, the nanoid(size) function in index.js and index.cjs coerces the user-influenced size parameter to a signed 32-bit integer, allowing a value of 2147483648 to become -2147483648 and corrupt the process-wide CSPRNG poolOffset in fillPool(), which causes subsequent session tokens, CSRF tokens, API keys, and unique identifiers to become the deterministic string "uuuuuuuuuuuuuuuuuuuuu" until the process restarts. This issue is fixed in versions 3.3.12 and 5.1.11.

    Published: 11 Aug 2026
    5.3
    Medium

    CVE-2026-73085

    Last Modified: 13 Aug 2026

    Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.36.0, the jwtAuthCheck function in server/auth/TokenManager.js treats JWTs with the refresh token type as bearer access tokens on API and WebSocket resource endpoints such as /api/me instead of restricting them to /auth/refresh, allowing refresh tokens to authenticate as the associated users. This issue is fixed in version 2.36.0.

    Published: 11 Aug 2026