Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
10.0 CRITICAL
CVE-2026-83711 — Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability

Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
9.3 CRITICAL
CVE-2026-80098 — Copilot Studio Elevation of Privilege Vulnerability

Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.

Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
10.0 CRITICAL
CVE-2026-70352 — Azure AI Language Elevation of Privilege Vulnerability

Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.

Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.5 HIGH
CVE-2026-70178 — Microsoft Fabric Elevation of Privilege Vulnerability

Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.

Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.5 HIGH
CVE-2026-69857 — Azure Cosmos DB Spoofing Vulnerability

Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network.

Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.5 HIGH
CVE-2026-65818 — Power Automate Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.

Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
9.1 CRITICAL
CVE-2026-62916 — Microsoft Entra ID Elevation of Privilege Vulnerability

Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.

Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.4 HIGH
CVE-2026-62906 — Microsoft Discovery Studio Information Disclosure Vulnerability

Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network.

Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
6.1 MEDIUM
CVE-2026-18330 — Hardcoded Shared RSA-1024 Private Key in TP-Link Archer AX55 v4

A hard-coded cryptographic key vulnerability exists in the web module of TP-Link Archer AX55 v4. A LAN attacker who captures an HTTP login session may use the known shared RSA private key to decrypt …

| Cryptography
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
7.7 HIGH
CVE-2026-18167 — Stack-based buffer overflow in TP-Link Archer AX55 v4

A stack-based buffer overflow vulnerability exists in the EasyMesh module of TP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit crafted input that causes the easymesh daemon…

| Memory Corruption
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
9.1 CRITICAL
CVE-2026-85224 — D-Link DNS-320 ShareCenter File Sharing file_sharing.cgi os command injection

A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a manipulation of the arg…

Remote | Injection
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
9.9 CRITICAL
CVE-2026-85223 — D-Link DNS-340L CGI dropbox.cgi os command injection

A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of …

dns-340l_firmware | Remote | Injection
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.5 HIGH
CVE-2026-64200 — Out Of Bounds Read in during string conversionwhen parsing a .DSB file in DASYLab

There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read a past the end of an allocated heap buffer during string conversion.…

| Memory Corruption
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.6 HIGH
CVE-2026-64199 — Out Of Bounds Read outside the bounds of an allocated data structure when parsing a .DSB …

There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read outside the bounds of an allocated data structure.  Successful explo…

| Memory Corruption
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.5 HIGH
CVE-2026-64198 — Out Of Bounds Read in file handling when parsing a .DSB file in DASYLab

There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read a few bytes past the end of an allocated heap buffer during file han…

| Memory Corruption
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.5 HIGH
CVE-2026-64197 — Out Of Bounds Write when parsing a .DSB file in DASYLab due to improper validation of use…

There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated data structure. Successful exploitation re…

| Memory Corruption
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.5 HIGH
CVE-2026-64196 — Out Of Bounds Write when parsing a .DSB file in DASYLab due to improper validation of use…

There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated heap. Successful exploitation requires an …

| Memory Corruption
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
8.5 HIGH
CVE-2026-64195 — Out Of Bounds Write parsing a .DSB file in DASYLab due to lack of proper validation of us…

There is an out-of-bounds write vulnerability in DASYLab due to lack of proper validation of user-supplied data. Successful exploitation requires an attacker to get a user to open a specially crafted…

| Memory Corruption
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
6.5 MEDIUM
CVE-2026-9745 — Vulnerabilities exists in IBM Netezza Software

IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This omission may allow a remote a…

Remote | Misconfiguration
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
5.3 MEDIUM
CVE-2026-9744 — Vulnerabilities exists in IBM Netezza Software

IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in …

Remote | Cryptography
Sep 03, 2026 Sep 03, 2026
Sep 03, 2026
Sep 03, 2026
Showing 20 of 12619 Results