2026-08-20
2026-08-20 22:17Z
CRIT

CVE-2026-68782 — Improper neutralization of special elements used in an sql command ('sql injection') in Azure

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68782

Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network. CVSSv3.1 9.9 (CRITICAL)

CWECWE 89TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-20
2026-08-20 22:17Z
HIGH

CVE-2026-66800 — Server: Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66800

Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network. CVSSv3.1 8.6 (HIGH)

CWECWE 918TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-20
2026-08-20 22:17Z
CRIT

CVE-2026-66309 — Azure: Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66309

Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284VNDAzureTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-20
2026-08-20 22:17Z
CRIT

CVE-2026-65816 — Use: of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65816

Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 10.0 (CRITICAL)

CWECWE 706TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-20
2026-08-20 22:17Z
CRIT

CVE-2026-65801 — Server: Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65801

Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 10.0 (CRITICAL)

CWECWE 918TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-20
2026-08-20 22:17Z
CRIT

CVE-2026-65770 — Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65770

Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network. CVSSv3.1 10.0 (CRITICAL)

CWECWE 88TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-20
2026-08-20 22:17Z
CRIT

CVE-2026-63509 — Relative: path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63509

Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network. CVSSv3.1 9.9 (CRITICAL)

CWECWE 23VNDRelativeTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-20
2026-08-20 22:17Z
CRIT

CVE-2026-62834 — Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62834

Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 9.3 (CRITICAL)

CWECWE 347TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-20
2026-08-20 22:17Z
HIGH

CVE-2026-55765 — CloudNativePG: Prior to 1.28.4 and 1.29.2, CloudNativePG embedded cleartext role passwords in `ALTER ROLE` and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55765

CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG embedded cleartext role passwords in `ALTER ROLE` and `CREATE ROLE` statements generated by SetUserPassword in pkg/management/postgres/utils/roles.go and appendPasswordOption in internal/management/controller/roles/postgres.go. When pg_stat_statements was preloaded with track_utility enabled and an untrusted tenant held pg_monitor or pg CVSSv3.1 8.5 (HIGH)

CWECWE 522CWECWE 256VNDCloudnativepgTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-20
2026-08-20 22:17Z
HIGH

CVE-2026-46682 — BigBlueButton: Prior to 3.0.23, BigBlueButton allowed authenticated moderators to inject SQL through the meetingId and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46682

BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authenticated moderators to inject SQL through the meetingId and userId values used by refreshBreakoutRoomsVisibleForUsers in akka-bbb-apps/src/main/scala/org/bigbluebutton/core/db/BreakoutRoomUserDAO.scala. The method interpolated those values into breakout room visibility queries, allowing arbitrary SQL execution against the application database. This issue is fixed in version 3.0.23. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDBigbluebuttonTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-20
2026-08-20 22:17Z
HIGH

CVE-2026-19449 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19449

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in cmdnim that may allow an unprivileged local user to executes the payload as root. CVSSv3.1 8.8 (HIGH)

VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-20
2026-08-20 22:17Z
HIGH

CVE-2026-19442 — IBM: Successful exploitation may result in denial of service, privilege escalation, or full compromise of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19442

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer validation flaw exists in the AIX Virtual SCSI (vSCSI) initiator driver. Successful exploitation may result in denial of service, privilege escalation, or full compromise of the client LPAR kernel. CVSSv3.1 8.2 (HIGH)

CWECWE 822VNDIbmTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-20
2026-08-20 22:17Z
HIGH

CVE-2026-19437 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19437

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow. CVSSv3.1 8.1 (HIGH)

CWECWE 787VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-20
2026-08-20 22:17Z
HIGH

CVE-2026-18842 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18842

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to an out-of-bounds write. CVSSv3.1 8.4 (HIGH)

CWECWE 787VNDIbmTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-08-20
2026-08-20 22:17Z
HIGH

CVE-2026-18840 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18840

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to improper validation of an attacker-controlled pointer. CVSSv3.1 8.2 (HIGH)

CWECWE 822VNDIbmTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-20
2026-08-20 22:17Z
CRIT

CVE-2026-18835 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18835

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. CVSSv3.1 9.9 (CRITICAL)

CWECWE 78VNDIbmTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-20
2026-08-20 22:17Z
HIGH

CVE-2026-18832 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18832

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap-based buffer overflow. CVSSv3.1 8.8 (HIGH)

CWECWE 787VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-20
2026-08-20 22:17Z
HIGH

CVE-2026-18824 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18824

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. CVSSv3.1 8.4 (HIGH)

CWECWE 78VNDIbmTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-08-20
2026-08-20 22:17Z
HIGH

CVE-2026-18670 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18670

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service and potentially disclose sensitive information due to an integer underflow. CVSSv3.1 8.2 (HIGH)

CWECWE 190VNDIbmTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-20
2026-08-20 22:17Z
HIGH

CVE-2026-17436 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17436

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap-based buffer overflow. CVSSv3.1 8.8 (HIGH)

CWECWE 787VNDIbmTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-20
2026-08-20 22:17Z
CRIT

CVE-2026-17422 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17422

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a buffer overflow. CVSSv3.1 9.3 (CRITICAL)

CWECWE 787VNDIbmTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-20
2026-08-20 22:17Z
HIGH

CVE-2026-17168 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17168

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary code due to a stack-based buffer overflow. CVSSv3.1 8.5 (HIGH)

CWECWE 787VNDIbmTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-20
2026-08-20 22:17Z
CRIT

CVE-2026-17160 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17160

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer overflow during size computation. CVSSv3.1 9.8 (CRITICAL)

CWECWE 190VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-20
2026-08-20 22:17Z
CRIT

CVE-2026-17157 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17157

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow. CVSSv3.1 9.8 (CRITICAL)

CWECWE 787VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-20
2026-08-20 22:17Z
CRIT

CVE-2026-17152 — IBM: AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-17152

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow. CVSSv3.1 9.8 (CRITICAL)

CWECWE 787VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score