Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.4 MEDIUM
CVE-2026-77643 — Xapian Cross-Site Scripting Vulnerability

A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and before 1.4.32 exists due to incomplete HTML escaping by Xapian::MSet::snippet(). …

xapian-core | Remote | Cross-Site Scripting
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
7.5 HIGH
CVE-2026-77642 — Tor Out-of-Bounds Write Vulnerability

tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact is minor for most Tor roles, but potentially majo…

tor | Remote | Memory Corruption
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
8.5 HIGH
CVE-2026-72860 — 9router Server-Side Request Forgery via /api/provider-nodes/validate Because the IPv4-Map…

The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP requests to it, guarding the destination with assertPublicUrl from src/shared/utils/…

Remote | Server-Side Request Forgery
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
8.6 HIGH
CVE-2026-72848 — langchain-community SitemapLoader Does Not Apply restrict_to_same_domain to Nested Sitema…

SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf url entries. The loop over url elements filters cros…

Remote | Server-Side Request Forgery
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
6.4 MEDIUM
CVE-2026-72846 — Lightdash Scheduled Delivery Webhook URLs Are Not Validated, Allowing Server-Side Request…

Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendWebhook in packages/backend/src/clients/GoogleChat/GoogleChatClient.ts and in packages/backend/src/c…

Remote | Server-Side Request Forgery
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
9.8 CRITICAL
CVE-2026-72843 — EverShop Missing Authorization on PATCH /api/customers/:id Allows Unauthenticated Account…

The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/updateCustomer/route.json, which causes the admin authentication middleware to …

Remote | Authorization
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
7.5 HIGH
CVE-2026-72818 — NLTK TweetTokenizer URL Pattern Backtracks Catastrophically on Naked-Domain-Like Input

The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+…

Remote | Denial of Service
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
6.5 MEDIUM
CVE-2026-70105 — Microsoft Word Information Disclosure Vulnerability

Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
7.7 HIGH
CVE-2026-69855 — Microsoft Copilot in Azure Information Disclosure Vulnerability

Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.

Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
9.9 CRITICAL
CVE-2026-69851 — Microsoft Entra ID Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
10.0 CRITICAL
CVE-2026-69836 — Microsoft Entra ID Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
8.6 HIGH
CVE-2026-69558 — Microsoft Partner Center Information Disclosure Vulnerability

Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.

Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
10.0 CRITICAL
CVE-2026-69555 — Azure Arc Elevation of Privilege Vulnerability

Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
8.5 HIGH
CVE-2026-69543 — Azure Virtual Machines Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.

Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
8.6 HIGH
CVE-2026-69519 — Azure Stack HCI Information Disclosure Vulnerability

Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.

Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
8.5 HIGH
CVE-2026-69419 — Azure Data Manager for Energy Remote Code Execution Vulnerability

Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network.

Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
9.6 CRITICAL
CVE-2026-69400 — Azure Logic Apps Elevation of Privilege Vulnerability

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
9.9 CRITICAL
CVE-2026-68789 — Azure SQL Database Elevation of Privilege Vulnerability

Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
9.9 CRITICAL
CVE-2026-68782 — Azure SQL Database Elevation of Privilege Vulnerability

Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
6.5 MEDIUM
CVE-2026-67448 — Mailpit: WebSocket origin check bypass via percent-encoded path (regression of CVE-2026-2…

Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/server.go origin middleware checks the raw RequestURI for the /api/ prefix while Go's ServeMux rout…

mailpit | Remote | Authorization
Aug 20, 2026 Aug 20, 2026
Aug 20, 2026
Aug 20, 2026
Showing 20 of 11707 Results