2026-08-07
2026-08-07 10:16Z
CRIT

CVE-2026-71560 — Apache Fory: Out-of-bounds Read vulnerability in Apache Fory C++ deserialization.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71560

Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-bounds heap read in the tagged integer fast-path deserializer, potentially causing information disclosure or denial of service. Users are recommended to upgrade to Apache Fory 1.5.0, which fixes this issue. Applications that do not CVSSv3.1 9.1 (CRITICAL)

CWECWE 502CWECWE 125VNDApacheTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-07
2026-08-07 10:16Z
CRIT

CVE-2026-71558 — Apache Fory: Heap type confusion vulnerability in Apache Fory C++ deserialization.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71558

Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserialization, causing an object of an incompatible type to be treated as the declared base type. This may result in undefined behavior and potentially lead to denial of service or arbitrary code execution. Users are recommended to upgrade t CVSSv3.1 9.8 (CRITICAL)

CWECWE 502CWECWE 843VNDApacheVNDHeapTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-07
2026-08-07 09:16Z
HIGH

CVE-2026-9169 — DLL: Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9169

DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with the privileges of the application by placing a malicious DLL in a user-controlled directory listed in the PATH environment variable, which the SDK traverses when a required dependency is not found locally. CVSSv3.1 8.8 (HIGH)

CWECWE 427VNDDllTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-07
2026-08-07 06:16Z
HIGH

CVE-2026-16263 — Maps: The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16263

The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly validate a user-controlled path before using it in a file inclusion, allowing users with a Subscriber account to include and execute arbitrary existing local PHP files on the server. CVSSv3.1 8.8 (HIGH)

CWECWE 22VNDMapsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-07
2026-08-07 06:16Z
CRIT

CVE-2026-16258 — Ajax: The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16258

The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Search Lite WordPress plugin before 4.14.5 or , this can be leveraged to achieve Remote Code Execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502VNDAjaxTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-07
2026-08-07 06:16Z
CRIT

CVE-2026-16038 — MStore: The MStore API WordPress plugin before 4.21.0 does not verify the payment with the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16038

The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order fully paid without paying and obtain goods or services for free. CVSSv3.1 9.1 (CRITICAL)

CWECWE 862VNDMstoreTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-07
2026-08-07 06:16Z
HIGH

CVE-2026-16030 — MStore: The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16030

The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a token and take over that user's account, including administrator accounts. CVSSv3.1 8.1 (HIGH)

CWECWE 287VNDMstoreTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-07
2026-08-07 06:16Z
HIGH

CVE-2026-15361 — Content: The Content Views WordPress plugin before 4.5 does not perform a capability check on

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15361

The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does not properly sanitise attacker-supplied data before using it in a SQL query, allowing any authenticated user, including Subscribers, to perform SQL injection attacks. CVSSv3.1 8.1 (HIGH)

CWECWE 89VNDContentTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-07
2026-08-07 06:16Z
HIGH

CVE-2026-15215 — Subscriptions: The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15215

The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions for WooCommerce WordPress plugin before 2.0.1 from a user-supplied slug through a nonce-protected AJAX action, allowing users with the Shop Manager role (who lack Subscriptions for WooCommerce WordPress plugin before 2.0.1-management capabilities) to install and activate arbitrary Subscriptions for WooCommerce WordPress plugin CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDSubscriptionsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-07
2026-08-07 06:16Z
CRIT

CVE-2026-14205 — Events: The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14205

The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed booking for a paid event without making a payment. CVSSv3.1 9.8 (CRITICAL)

CWECWE 287VNDEventsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-07
2026-08-07 05:16Z
CRIT

CVE-2026-14365 — TrueBooker: The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14365

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to change the password of arbitrary user accounts, including administrators, which can be leveraged to gain access to those accounts. CVSSv3.1 9.8 (CRITICAL)

CWECWE 862VNDTruebookerTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-07
2026-08-07 05:16Z
CRIT

CVE-2026-14364 — TrueBooker: The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14364

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via improper password reset validation in all versions up to, and including, 1.2.3. This is due to the plugin not properly validating a user's identity before resetting their password. This makes it possible for unauthenticated attackers to reset the password of arbitrary user accounts, including administrators, and gain access to those accounts. CVSSv3.1 9.8 (CRITICAL)

CWECWE 640VNDTruebookerTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-07
2026-08-07 00:16Z
CRIT

CVE-2026-70332 — Server: Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an unauthorized attacker to perform

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70332

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. CVSSv3.1 9.6 (CRITICAL)

CWECWE 918TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-08-07
2026-08-07 00:16Z
CRIT

CVE-2026-68823 — Exposed: dangerous method or function in Azure Confidential Ledger allows an authorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68823

Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network. CVSSv3.1 9.1 (CRITICAL)

CWECWE 749VNDExposedTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-08-07
2026-08-07 00:16Z
HIGH

CVE-2026-65668 — Microsoft: Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65668

Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 284VNDMicrosoftTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-07
2026-08-07 00:16Z
CRIT

CVE-2026-65667 — Microsoft: Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-65667

Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 10.0 (CRITICAL)

CWECWE 862VNDMicrosoftTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-07
2026-08-07 00:16Z
CRIT

CVE-2026-63508 — Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63508

Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 10.0 (CRITICAL)

CWECWE 306TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-07
2026-08-07 00:16Z
CRIT

CVE-2026-62896 — Microsoft: Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62896

Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. CVSSv3.1 9.6 (CRITICAL)

CWECWE 287VNDMicrosoftTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-08-07
2026-08-07 00:16Z
CRIT

CVE-2026-62873 — Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62873

Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 9.8 (CRITICAL)

CWECWE 347TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-07
2026-08-07 00:16Z
HIGH

CVE-2026-62836 — Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62836

Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 8.7 (HIGH)

CWECWE 923TYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-08-07
2026-08-07 00:16Z
CRIT

CVE-2026-62830 — Azure: Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62830

Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network. CVSSv3.1 9.9 (CRITICAL)

CWECWE 862VNDAzureTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-07
2026-08-07 00:16Z
CRIT

CVE-2026-59118 — Microsoft: Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59118

Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 9.3 (CRITICAL)

CWECWE 285VNDMicrosoftTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-08-07
2026-08-07 00:16Z
CRIT

CVE-2026-59115 — Microsoft: '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59115

'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. CVSSv3.1 9.9 (CRITICAL)

CWECWE 35VNDMicrosoftTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-07
2026-08-07 00:16Z
CRIT

CVE-2026-56162 — Azure: Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56162

Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 10.0 (CRITICAL)

CWECWE 287VNDAzureTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-08-07
2026-08-07 00:16Z
CRIT

CVE-2026-56161 — Azure: Improper access control in Azure Logic Apps allows an authorized attacker to disclose information

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56161

Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. CVSSv3.1 9.6 (CRITICAL)

CWECWE 284VNDAzureTYPVulnerability
9.6
CVSS v3.1
98
Edit Score