Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network.
CVSSv3.1 8.5 (HIGH)
CWECWE 639TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
1w ago
2026-09-03 23:17Z
HIGH
CVE-2026-65818 — Server: Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges
Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
CVSSv3.1 9.1 (CRITICAL)
CWECWE 288TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-09-03 22:18Z
CRIT
CVE-2026-85224 — Executing a manipulation of the argument fileurl can lead to os command injection.
A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a manipulation of the argument fileurl can lead to os command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
CVSSv3.1 9.1 (CRITICAL)
CWECWE 77CWECWE 78TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-09-03 22:18Z
CRIT
CVE-2026-85223 — Performing a manipulation of the argument callback_url/sync_interval results in os command injection.
A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval results in os command injection. The attack can be initiated remotely. The exploit has been made public and could be used.
CVSSv3.1 9.9 (CRITICAL)
CWECWE 77CWECWE 78TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
1w ago
2026-09-03 21:17Z
CRIT
CVE-2026-85222 — Such manipulation of the argument f_name/f_url/f_flag/f_login_user leads to os command injection.
A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/addon_center.cgi of the component Add-On Center. Such manipulation of the argument f_name/f_url/f_flag/f_login_user leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVSSv3.1 9.1 (CRITICAL)
CWECWE 77CWECWE 78TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
728 × 90 / responsive · programmatic ad slot
1w ago
2026-09-03 21:17Z
CRIT
CVE-2026-85061 — MapLibre: GL JS is an interactive vector tile map library for web browsers.
MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap while removeAttributes() removes attributes from the same collection, shifting indexes and skipping an adjacent dangerous attribute. An attacker who controls untrusted third-party style attribution strings or user-supplied custom attributions can supply consecutive dangerous attributes, causing an attribut
CVSSv3.1 10.0 (CRITICAL)
CWECWE 79VNDMaplibreTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
1w ago
2026-09-03 21:17Z
HIGH
CVE-2026-63376 — TOML: Injected properties become visible throughout the Node.js process and can cause denial of service
toml-node is a TOML parser for Node.js and the browser. Prior to 4.1.2, toml.parse() in lib/compiler.js can be tricked by a table path such as a.b.y.__proto__.__proto__, allowing traversal from a scalar value into Number.prototype and Object.prototype. The currentPath tracking value uses both arrays and strings, so valueAssignments records a comma-joined path such as a,b.y while deepRef checks the dot-joined path a.b.y, allowing the duplicate-key guard to miss and attacker-co
CVSSv3.1 8.2 (HIGH)
CWECWE 1321VNDTomlTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
1w ago
2026-09-03 20:17Z
HIGH
CVE-2026-85053 — CacheStorage: Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote
Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.8 (HIGH)
CWECWE 668VNDCachestorageTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-03 20:17Z
HIGH
CVE-2026-85051 — Type: confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker
Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.8 (HIGH)
CWECWE 843VNDTypeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-03 20:17Z
CRIT
CVE-2026-85050 — Out: of bounds write in WebGL in Google Chrome on on Android prior to
Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 9.6 (CRITICAL)
CWECWE 787TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
1w ago
2026-09-03 20:17Z
HIGH
CVE-2026-85049 — Use: after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote
Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.8 (HIGH)
CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-03 20:17Z
HIGH
CVE-2026-85048 — Use: after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote
Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.3 (HIGH)
CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
1w ago
2026-09-03 20:17Z
CRIT
CVE-2026-85047 — Transactions: Improper input validation in Transactions Platform in Google Chrome on on iOS prior to
Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
CVSSv3.1 9.6 (CRITICAL)
CWECWE 20VNDTransactionsTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
1w ago
2026-09-03 20:17Z
HIGH
CVE-2026-85046 — Type: confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.8 (HIGH)
CWECWE 843VNDTypeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-03 20:17Z
CRIT
CVE-2026-85043 — Incomplete: cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker
Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: High)
CVSSv3.1 9.1 (CRITICAL)
CWECWE 459VNDIncompleteTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-09-03 20:17Z
CRIT
CVE-2026-85042 — Use: after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote
Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 9.6 (CRITICAL)
CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
1w ago
2026-09-03 20:17Z
HIGH
CVE-2026-44506 — Medplum: is a developer platform that enables development of healthcare apps.
Medplum is a developer platform that enables development of healthcare apps. In Medplum versions 4.1.10 through 5.1.6, the /oauth2/register endpoint could return the client_secret of preconfigured OAuth clients defined via the defaultOAuthClients server configuration when a matching redirect_uri was provided. This issue has been patched in version 5.1.7.
CVSSv3.1 8.2 (HIGH)
CWECWE 200VNDMedplumTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
1w ago
2026-09-03 19:17Z
CRIT
CVE-2026-85394 — python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded
python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens that pass verification when algorithms are not explicitly restricted. This is an incomplete fix for CVE-2024-33663.
CVSSv3.1 9.1 (CRITICAL)
CWECWE 347TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-09-03 19:17Z
CRIT
CVE-2026-85391 — Peppermint: through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated
Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published secret to mint valid tokens for arbitrary user IDs and access protected endpoints without credentials.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 798VNDPeppermintTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-03 19:17Z
HIGH
CVE-2026-85388 — Worklenz: Attackers can use time-based and boolean-based blind SQL injection techniques to extract sensitive database
Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER BY clauses. Attackers can use time-based and boolean-based blind SQL injection techniques to extract sensitive database content including password hashes from other tenants. This is an incomplete fix for CVE-2026-25947.
CVSSv3.1 8.1 (HIGH)
CWECWE 89VNDWorklenzTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-03 19:17Z
CRIT
CVE-2026-82526 — R2R: through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to
R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL statements by manipulating the index name parameter in the vector index creation endpoint. The index name is interpolated directly into a CREATE INDEX statement via string formatting without identifier quoting or allowlist validation, enabling arbitrary DDL and DML execution through semicolon-separated statements under the PostgreSQL superuser accoun
CVSSv3.1 9.8 (CRITICAL)
CWECWE 89VNDR2rTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-03 19:17Z
HIGH
CVE-2026-82302 — Incorrect: Authorization (CWE-863) in Kibana can lead to unauthorized configuration modification via Exploiting Incorrectly
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized configuration modification via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).
CVSSv3.1 8.1 (HIGH)
CWECWE 863TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-03 19:17Z
HIGH
CVE-2026-78583 — Incorrect: Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation
Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Input Data Manipulation (CAPEC-153). Elasticsearch cluster privilege declarations originating from integration packages were not validated before being used to mint credentials for enrolled Elastic Agents. A user holding Fleet management privileges could therefore cause every Elastic Agent on a targeted policy to receive a credential carrying arbitrarily elevated Elasticsearch cluster privileges,
CVSSv3.1 8.1 (HIGH)