2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-59113 — Visual: Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59113

Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDVisualTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-57105 — Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57105

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. CVSSv3.1 8.0 (HIGH)

CWECWE 79TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-57104 — Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57104

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 79TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-56179 — Origin: validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56179

Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network. CVSSv3.1 8.3 (HIGH)

CWECWE 346VNDOriginTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-11
2026-08-11 17:18Z
CRIT

CVE-2026-50516 — Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50516

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 9.4 (CRITICAL)

CWECWE 306TYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-49179 — Improper neutralization of special elements used in a command ('command injection') in Windows Active

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49179

Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 77TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:18Z
HIGH

CVE-2026-48440 — ColdFusion: is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48440

ColdFusion is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. CVSSv3.1 8.1 (HIGH)

CWECWE 122VNDColdfusionTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-11
2026-08-11 17:17Z
CRIT

CVE-2026-48362 — ColdFusion: is affected by an Improper Neutralization of Special Elements used in an OS

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48362

ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 10.0 (CRITICAL)

CWECWE 78VNDColdfusionTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-11
2026-08-11 17:17Z
HIGH

CVE-2026-34635 — Use: is affected by a Use of Hard-coded Cryptographic Key vulnerability that could result in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34635

is affected by a Use of Hard-coded Cryptographic Key vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 8.4 (HIGH)

CWECWE 321TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-08-11
2026-08-11 17:17Z
HIGH

CVE-2026-24911 — Intel Proset\/wireless_wifi: Stack-based buffer overflow for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24911

Stack-based buffer overflow for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0: Kernel may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the con CVSSv3.1 8.6 (HIGH) · EPSS 7th percentile

CWECWE 121VNDIntelVNDStackTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-11
2026-08-11 17:17Z
HIGH

CVE-2026-21279 — Input: is affected by an Improper Input Validation vulnerability that could result in a Security

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-21279

is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and limited write access. Exploitation of this issue does not require user interaction. CVSSv3.1 8.2 (HIGH)

CWECWE 20VNDInputTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-08-11
2026-08-11 17:17Z
HIGH

CVE-2026-21273 — Input: is affected by an Improper Input Validation vulnerability that could result in privilege escalation.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-21273

is affected by an Improper Input Validation vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain unauthorized read and write access. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. CVSSv3.1 8.7 (HIGH)

CWECWE 20VNDInputTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:17Z
HIGH

CVE-2026-20776 — Intel Proset\/wireless_wifi: Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20776

Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), CVSSv3.1 8.6 (HIGH) · EPSS 7th percentile

CWECWE 754VNDIntelTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-11
2026-08-11 17:17Z
HIGH

CVE-2026-20749 — Intel Proset\/wireless_wifi: Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20749

Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow an escalation of privilege. Network adversary with an unauthenticated user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality ( CVSSv3.1 8.8 (HIGH) · EPSS 7th percentile

CWECWE 125VNDIntelTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 17:17Z
HIGH

CVE-2026-20727 — Intel Proset\/wireless_wifi: Null pointer dereference for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20727

Null pointer dereference for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0: Kernel may allow a denial of service. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via adjacent access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confid CVSSv3.1 8.6 (HIGH) · EPSS 7th percentile

CWECWE 476VNDIntelVNDNullTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-11
2026-08-11 17:17Z
HIGH

CVE-2026-20349 — Access: A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20349

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a craft CVSSv3.1 8.6 (HIGH)

CWECWE 244VNDAccessTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-08-11
2026-08-11 17:17Z
CRIT

CVE-2026-12571 — ManageEngine: An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12571

An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover. CVSSv3.1 9.8 (CRITICAL)

CWECWE 287CWECWE 640VNDManageengineTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-11
2026-08-11 16:17Z
CRIT

CVE-2026-73080 — SeaweedFS: Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_remote.go fetches a caller-supplied remote endpoint through weed/remote_storage/s3/s3_storage_cli

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73080

SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_remote.go fetches a caller-supplied remote endpoint through weed/remote_storage/s3/s3_storage_client.go and writes the response into a needle. The RPC performs no authentication and no target validation, allowing anyone who can reach a volume server's gRPC port to cause requests to arbitrary hosts, including loopback, link-local, RFC 1918, and cloud metadata e CVSSv3.1 9.3 (CRITICAL)

CWECWE 918VNDSeaweedfsTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-11
2026-08-11 16:17Z
HIGH

CVE-2026-73079 — Sub2API: This lets an authenticated tenant relay requests to arbitrary upstream endpoints using pooled account

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73079

Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. From 0.1.135, to 0.1.168, platform API keys issued to tenants are exchanged for upstream requests made with shared provider accounts (ChatGPT/Codex OAuth, OpenAI platform keys, or an operator-configured base URL) that belong to the operator, not to the caller. The `POST /responses/*subpath` wildcard routes spliced the client-supplied subpath into the upstream URL CVSSv3.1 8.5 (HIGH)

CWECWE 22CWECWE 441VNDSub2apiTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-11
2026-08-11 16:17Z
CRIT

CVE-2026-73069 — Twenty: Prior to 2.15.0, Twenty allowed a workspace administrator with the DATA_MODEL permission to supply

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-73069

Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty allowed a workspace administrator with the DATA_MODEL permission to supply settings.asExpression for the system TS_VECTOR field searchVector through PATCH /rest/metadata/fields/:id or the updateOneField GraphQL mutation, causing buildSqlColumnDefinition in packages/twenty-server/src/engine/twenty-orm/workspace-schema-manager/utils/build-sql-column-definition.util.ts to concatenat CVSSv3.1 9.1 (CRITICAL)

CWECWE 89VNDTwentyTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-11
2026-08-11 16:17Z
HIGH

CVE-2026-67180 — Google: Turbinia allows arbitrary command execution via worker tasks.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-67180

Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing request or influence an evidence path/name obtains code execution on the worker fleet. Fixed on 2026-07-10. CVSSv3.1 8.4 (HIGH)

CWECWE 78VNDGoogleTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-08-11
2026-08-11 16:17Z
HIGH

CVE-2026-56721 — CamaleonCMS: version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure direct object

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56721

CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure direct object reference (IDOR) that allows authenticated low-privileged attackers to overwrite any user's credentials by exploiting a parameter confusion flaw between the authorization filter and action body in the UsersController. Attackers can send a PATCH request to the updated_ajax endpoint setting params[:id] to their own user ID to pass the self-authorization check while sim CVSSv3.1 8.8 (HIGH)

CWECWE 639VNDCamaleoncmsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-11
2026-08-11 16:17Z
HIGH

CVE-2026-53415 — Use: after Free in the annotator function of Zoom Clients may allow a meeting

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53415

Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another participant via network access. CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-11
2026-08-11 16:17Z
HIGH

CVE-2026-53413 — Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53413

Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code execution of another participant via network access. CVSSv3.1 8.3 (HIGH)

CWECWE 787TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-08-11
2026-08-11 16:17Z
HIGH

CVE-2026-19546 — DBI: A flaw was found in DBI.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19546

A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a detailed Statement, Description and Mitigation please reffer to the original https://access.redhat.com/security/cve/cve-2026-19546. CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDDbiTYPVulnerability
8.8
CVSS v3.1
94
Edit Score