Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-93450 — go-openapi/swag jsonutils before 0.27.1 Uncontrolled Recursion in Ordered JSON Marshal an…

go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit. Remote unauthenticated attack…

Remote | Denial of Service
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
4.3 MEDIUM
CVE-2026-93309 — O-RAN-SC SMO OAM VES Collector allocation of resources

A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10. Affected by this issue is some unknown functionality of the component VES Collector. Executing a manipulation can lead to allocation of …

smo_oam | Remote | Denial of Service
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
4.3 MEDIUM
CVE-2026-93308 — O-RAN-SC SMO OAM VES Collector allocation of resources

A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. Affected by this vulnerability is an unknown functionality of the component VES Collector. Performing a manipulation results in allocation of…

smo_oam | Remote | Denial of Service
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
7.7 HIGH
CVE-2026-85887 — M365 Copilot Information Disclosure Vulnerability

Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network.

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
9.9 CRITICAL
CVE-2026-85878 — Azure Database for PostgreSQL Elevation of Privilege Vulnerability

Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
8.2 HIGH
CVE-2026-83946 — Azure Portal Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthorized attacker to perform spoofing over a network.

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
10.0 CRITICAL
CVE-2026-69843 — Microsoft Fabric Elevation of Privilege Vulnerability

Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
10.0 CRITICAL
CVE-2026-62874 — Azure Billing Elevation of Privilege Vulnerability

Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.

Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
6.4 MEDIUM
CVE-2026-2585 — Brizy – Page Builder <= 2.8.14 - Authenticated (Contributor+) Stored Cross-Site Scripting…

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘rootAttributes’ parameter in all versions up to, and including, 2.8.14 due to insufficient input sa…

brizy | Remote | Cross-Site Scripting
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
4.3 MEDIUM
CVE-2026-18441 — LatePoint - Appointment Booking & Scheduling <= 5.6.9 - Unauthenticated Insecure Direct O…

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.9 vi…

Remote | Information Disclosure
Sep 18, 2026 Sep 18, 2026
Sep 18, 2026
Sep 18, 2026
8.7 HIGH
CVE-2026-93436 — vLLM through 0.29.0 Memory Exhaustion via Rejected Requests

vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode disaggregated deployments. Remote attackers can submit requests with max_tokens=0…

vllm vllm | Remote | Denial of Service
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.7 HIGH
CVE-2026-93435 — redis-parser through 3.0.0 Denial of Service via Unbounded Recursion

redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious Redis endpoints to crash the client process through unbounded recursion on nest…

Remote | Denial of Service
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.8 HIGH
CVE-2026-87886 — Acronis Backup Incorrect Default Permissions Vulnerability - [Actively Exploited]

Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for …

CISA KEV | Misconfiguration
Sep 17, 2026 Sep 18, 2026
Sep 17, 2026
Sep 18, 2026
9.6 CRITICAL
CVE-2026-87701 — Azure Cosmos DB Elevation of Privilege Vulnerability

Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.

Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.5 HIGH
CVE-2026-85917 — Azure AI Foundry Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
10.0 CRITICAL
CVE-2026-85889 — Azure AI Foundry Elevation of Privilege Vulnerability

Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
9.9 CRITICAL
CVE-2026-85885 — Microsoft 365 Copilot Elevation of Privilege Vulnerability

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.

Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
10.0 CRITICAL
CVE-2026-83944 — Azure Logic Apps Elevation of Privilege Vulnerability

Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.4 HIGH
CVE-2026-78501 — Microsoft 365 Copilot Business Chat Information Disclosure Vulnerability

Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network.

Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
9.0 CRITICAL
CVE-2026-77903 — Microsoft Dataverse Elevation of Privilege Vulnerability

Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.

Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Showing 20 of 14446 Results