Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.8 HIGH
CVE-2026-58641 — .NET Elevation of Privilege Vulnerability

Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.

Aug 11, 2026 Sep 03, 2026
Aug 11, 2026
Sep 03, 2026
6.5 MEDIUM
CVE-2026-58639 — Microsoft SharePoint Server Spoofing Vulnerability

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Aug 11, 2026 Aug 12, 2026
Aug 11, 2026
Aug 12, 2026
7.5 HIGH
CVE-2026-58612 — PowerShell Information Disclosure Vulnerability

Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.

powershell | Remote
Aug 11, 2026 Aug 17, 2026
Aug 11, 2026
Aug 17, 2026
8.0 HIGH
CVE-2026-57105 — Microsoft Office SharePoint Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Aug 11, 2026 Aug 12, 2026
Aug 11, 2026
Aug 12, 2026
9.6 CRITICAL
CVE-2026-57104 — Azure Storage Explorer Elevation of Privilege Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network.

Aug 11, 2026 Aug 17, 2026
Aug 11, 2026
Aug 17, 2026
8.3 HIGH
CVE-2026-56179 — Windows Network Address Translation (NAT) Spoofing Vulnerability

Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.

Aug 11, 2026 Aug 13, 2026
Aug 11, 2026
Aug 13, 2026
7.8 HIGH
CVE-2026-56174 — Windows Narrator Braille Elevation of Privilege Vulnerability

Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

Aug 11, 2026 Aug 16, 2026
Aug 11, 2026
Aug 16, 2026
7.8 HIGH
CVE-2026-54984 — Windows Imaging Component Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.

Aug 11, 2026 Aug 16, 2026
Aug 11, 2026
Aug 16, 2026
7.8 HIGH
CVE-2026-54981 — Visual Studio Code Python Extension Security Feature Bypass Vulnerability

Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally.

Aug 11, 2026 Aug 22, 2026
Aug 11, 2026
Aug 22, 2026
5.5 MEDIUM
CVE-2026-54123 — Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information locally.

Aug 11, 2026 Aug 17, 2026
Aug 11, 2026
Aug 17, 2026
7.5 HIGH
CVE-2026-54113 — Remote Procedure Call Denial of Service Vulnerability

Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.

Aug 11, 2026 Aug 16, 2026
Aug 11, 2026
Aug 16, 2026
9.4 CRITICAL
CVE-2026-50516 — Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

Aug 11, 2026 Aug 12, 2026
Aug 11, 2026
Aug 12, 2026
7.0 HIGH
CVE-2026-50472 — Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.

Aug 11, 2026 Aug 16, 2026
Aug 11, 2026
Aug 16, 2026
8.8 HIGH
CVE-2026-49179 — Windows Active Directory Domain Services Remote Code Execution Vulnerability

Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.

Aug 11, 2026 Aug 16, 2026
Aug 11, 2026
Aug 16, 2026
5.4 MEDIUM
CVE-2026-48483 — TypeBot's WhatsApp status forwarding uses unvalidated user-controlled URLs, allowing SSRF…

TypeBot is a chatbot builder tool. Prior to version 3.17.0, Typebot's WhatsApp status forwarding feature stores a workspace-configured webhook forwarding URL and later POSTs WhatsApp marketing/error …

typebot | Remote | Server-Side Request Forgery
Aug 11, 2026 Aug 11, 2026
Aug 11, 2026
Aug 11, 2026
5.5 MEDIUM
CVE-2026-48446 — CAI Content Credentials | Improper Limitation of a Pathname to a Restricted Directory ('P…

CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could…

c2pa c2pa-web c2patool | Path Traversal
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
6.2 MEDIUM
CVE-2026-48445 — CAI Content Credentials | Integer Overflow or Wraparound (CWE-190)

CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the…

c2pa c2pa-web c2patool | Denial of Service
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
6.2 MEDIUM
CVE-2026-48444 — CAI Content Credentials | Integer Overflow or Wraparound (CWE-190)

CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the…

c2pa c2pa-web c2patool | Denial of Service
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
6.2 MEDIUM
CVE-2026-48443 — CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)

CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust sys…

c2pa c2pa-web c2patool | Denial of Service
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
7.1 HIGH
CVE-2026-48442 — CAI Content Credentials | Improper Limitation of a Pathname to a Restricted Directory ('P…

CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Arbitrary file system read. An attacker c…

c2pa c2pa-web c2patool | Path Traversal
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
Showing 20 of 14196 Results