Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.5 HIGH
CVE-2026-69543 — Azure Virtual Machines Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.

Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
8.6 HIGH
CVE-2026-69519 — Azure Stack HCI Information Disclosure Vulnerability

Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.

Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
8.5 HIGH
CVE-2026-69419 — Azure Data Manager for Energy Remote Code Execution Vulnerability

Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network.

Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
9.6 CRITICAL
CVE-2026-69400 — Azure Logic Apps Elevation of Privilege Vulnerability

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
9.9 CRITICAL
CVE-2026-68789 — Azure SQL Database Elevation of Privilege Vulnerability

Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
9.9 CRITICAL
CVE-2026-68782 — Azure SQL Database Elevation of Privilege Vulnerability

Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
6.5 MEDIUM
CVE-2026-67448 — Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-2…

Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/server.go origin middleware checks the raw RequestURI for the /api/ prefix while Go's ServeMux rout…

mailpit | Remote | Authorization
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
5.3 MEDIUM
CVE-2026-67447 — Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement

Mailpit is an email testing tool and API for developers. From 1.30.0 until 1.30.5, Mailpit's internal/smtpd/smtpd.go readData() function calls bufio.Reader.ReadBytes before applying the len(data)+len…

mailpit | Remote | Denial of Service
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
8.6 HIGH
CVE-2026-66800 — Azure Data Factory Information Disclosure Vulnerability

Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.

Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
9.1 CRITICAL
CVE-2026-66309 — Azure SQL Database Elevation of Privilege Vulnerability

Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
10.0 CRITICAL
CVE-2026-65816 — Azure Arc Elevation of Privilege Vulnerability

Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
10.0 CRITICAL
CVE-2026-65801 — Microsoft Exchange Online Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.

Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
10.0 CRITICAL
CVE-2026-65770 — Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability

Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.

Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
0.0 NA
CVE-2026-64773 — Docker Container Network Forwarding Memory Exhaustion

An attacker that can reach a container's published TCP port may be able to force the host's forwarding process to buffer an unbounded amount of that client's data in memory, for as long as the backen…

container | Denial of Service
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
9.9 CRITICAL
CVE-2026-63509 — Microsoft Fabric Elevation of Privilege Vulnerability

Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.

Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
4.3 MEDIUM
CVE-2026-62945 — TREK: Cross-trip reservation title disclosure via file links

TREK is a collaborative travel planner. Prior to 3.1.3, TREK file upload, update, and link actions accept attacker-controlled reservation_id, place_id, and assignment_id values without using findFore…

trek | Remote | Authorization
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
9.3 CRITICAL
CVE-2026-62834 — Azure Data Factory Elevation of Privilege Vulnerability

Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.

Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
6.8 MEDIUM
CVE-2026-55894 — Capstone SH disassembler `sh_disassemble` out-of-bounds read via crafted SH2A bytecode

Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c sh_disassemble() function computes an idx value from a raw 16-bit instruction without ensuring it…

capstone | Misconfiguration
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
7.3 HIGH
CVE-2026-55893 — Capstone SH disassembler `set_reg_n` heap buffer overflow via crafted SH2A FPU bytecode

Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c SH floating-point decoders such as opFADD, opFMUL, and opFSUB call set_reg() and set_reg_n() usin…

capstone | Memory Corruption
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
9.4 CRITICAL
CVE-2026-55769 — CloudNativePG: Overriding operators can lead to privilege escalation in CloudNativePG for…

CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG opened superuser connections without pinning search_path …

Remote | Authentication
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
Showing 20 of 11695 Results