Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.8 HIGH
CVE-2026-19191 — StableBit DrivePool DrivePoolService DrivePool.Service.exe permission

A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. This vulnerability affects unknown code of the file C:\Program Files\StableBit\DrivePool\DrivePool.Service.exe of the co…

| Authorization
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
9.8 CRITICAL
CVE-2026-14365 — TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Password Reset v…

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properl…

Remote | Authorization
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
9.8 CRITICAL
CVE-2026-14364 — TrueBooker <= 1.2.3 - Missing Authorization to Unauthenticated Arbitrary Password Reset v…

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via improper password reset validation in all versions up to, and including, 1.2.3. Th…

Remote | Authentication
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
6.4 MEDIUM
CVE-2026-12801 — Ultra Addons for Contact Form 7 <= 3.5.43 - Authenticated (Contributor+) Stored Cross-Sit…

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Range Slider 'data-label' and 'data-separator' attributes in all versions up to, and incl…

Remote | Cross-Site Scripting
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
6.5 MEDIUM
CVE-2026-11907 — Stream <= 4.2.0 - Missing Authorization to Authenticated (Subscriber+) Sensitive Informat…

The Stream plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.2.0. This is due to the plugin not properly verifying that a user is authorized to perfor…

Remote | Authorization
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
7.8 HIGH
CVE-2026-19190 — StableBit Scanner ScannerService Scanner.Service.exe permission

A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part of the file C:\Program Files (x86)\StableBit\Scanner\Service\Scanner.Service.exe of the component Scanner…

| Authorization
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
0.0 NA
CVE-2026-49746 — GPU DDK - Dimension Mismatch and Integer Truncation in PMRDevPhysAddrOSMem

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memory access and in certain cases cause GPU UAF of arbitrary pages. Incorrect va…

| Memory Corruption
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
0.0 NA
CVE-2026-45204 — GPU DDK - Out of bounds memory access and kernel NULL pointer dereference in DmaTransfer …

Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger OOB access and kernel null pointer dereference in an error path. Null pointer dereference occur…

| Memory Corruption
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
0.0 NA
CVE-2026-45198 — GPU DDK - RGXFWIF_SYSINIT::sCorememDataStore is untrusted

Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause GPU Firmware to boot up using data from non-secure memory. The GPU thread of …

| Memory Corruption
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
7.8 HIGH
CVE-2026-19189 — Power Sofware PowerISO Kernel Driver scdemu.sys privileges management

A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functionality in the library C:\Windows\System32\drivers\scdemu.sys of the component Kern…

| Authorization
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
9.6 CRITICAL
CVE-2026-70332 — Microsoft Office SharePoint Spoofing Vulnerability

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
9.1 CRITICAL
CVE-2026-68823 — Azure Confidential Ledger Remote Code Execution Vulnerability

Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
8.8 HIGH
CVE-2026-65668 — Microsoft Purview eDiscovery Elevation of Privilege Vulnerability

Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
10.0 CRITICAL
CVE-2026-65667 — Microsoft Teams Elevation of Privilege Vulnerability

Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
10.0 CRITICAL
CVE-2026-63508 — Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability

Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
7.5 HIGH
CVE-2026-62918 — Microsoft Teams Spoofing Vulnerability

Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
9.6 CRITICAL
CVE-2026-62896 — Microsoft Teams Elevation of Privilege Vulnerability

Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
9.8 CRITICAL
CVE-2026-62873 — Microsoft 365 Admin Center Elevation of Privilege Vulnerability

Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
8.7 HIGH
CVE-2026-62836 — Azure SQL Managed Instance Elevation of Privilege Vulnerability

Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
9.9 CRITICAL
CVE-2026-62830 — Azure SRE Agent Elevation of Privilege Vulnerability

Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
Showing 20 of 10106 Results