Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-6419 — Wishlist Member <= 3.30.1 - Missing Authorization to Authenticated (Subscriber+) API Secr…

The WishList Member plugin for WordPress is vulnerable to Privilege Escalation via Missing Authorization in versions up to and including 3.30.1. This is due to the missing capability and nonce check …

Remote | Authorization
May 23, 2026 May 26, 2026
May 23, 2026
May 26, 2026
10.0 CRITICAL
CVE-2026-47280 — Azure Resource Manager Elevation of Privilege Vulnerability

Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network.

May 22, 2026 May 27, 2026
May 22, 2026
May 27, 2026
8.8 HIGH
CVE-2026-45659 — Microsoft SharePoint Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

May 22, 2026 May 27, 2026
May 22, 2026
May 27, 2026
10.0 CRITICAL
CVE-2026-42901 — Microsoft Entra ID Elevation of Privilege Vulnerability

Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.

May 22, 2026 May 27, 2026
May 22, 2026
May 27, 2026
7.5 HIGH
CVE-2026-42827 — M365 Copilot Information Disclosure Vulnerability

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

365_copilot | Remote
May 22, 2026 May 27, 2026
May 22, 2026
May 27, 2026
5.3 MEDIUM
CVE-2026-41149 — Mermaid: Improper sanitization of `classDef` in state diagrams leads to HTML injection

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and earlier, as well as 11.0.0-alpha.1 through 11.14.0, are vulnerable to HTML …

mermaid | Remote | Injection
May 22, 2026 May 26, 2026
May 22, 2026
May 26, 2026
5.3 MEDIUM
CVE-2026-41148 — Mermaid: Improper sanitization of `classDefs` in diagrams leads to CSS injection

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and prior, in addition to 11.0.0-alpha.1 through 11.12.0 are vulnerable to CSS …

mermaid | Remote | Injection
May 22, 2026 May 26, 2026
May 22, 2026
May 26, 2026
10.0 CRITICAL
CVE-2026-41104 — Microsoft Planetary Computer Pro Information Disclosure Vulnerability

Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a network.

May 22, 2026 May 29, 2026
May 22, 2026
May 29, 2026
9.3 CRITICAL
CVE-2026-41090 — Microsoft Copilot Tampering Vulnerability

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.

May 22, 2026 May 27, 2026
May 22, 2026
May 27, 2026
10.0 CRITICAL
CVE-2026-40412 — Azure Orbital Spatio Remote Code Execution Vulnerability

Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network.

May 22, 2026 May 27, 2026
May 22, 2026
May 27, 2026
9.9 CRITICAL
CVE-2026-40411 — Azure Virtual Network Gateway Remote Code Execution Vulnerability

Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network.

May 22, 2026 May 27, 2026
May 22, 2026
May 27, 2026
8.8 HIGH
CVE-2026-35430 — Azure Privileged Identity Management (PIM) Elevation of Privilege Vulnerability

Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized attacker to elevate privileges over a network.

May 22, 2026 May 27, 2026
May 22, 2026
May 27, 2026
9.8 CRITICAL
CVE-2026-33843 — Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability

Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

May 22, 2026 May 27, 2026
May 22, 2026
May 27, 2026
7.7 HIGH
CVE-2026-26147 — Azure Stack HCI Information Disclosure Vulnerability

Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network.

May 22, 2026 May 27, 2026
May 22, 2026
May 27, 2026
7.5 HIGH
CVE-2026-23663 — Microsoft Global Secure Access (GSA) Information Disclosure Vulnerability

Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network.

May 22, 2026 May 27, 2026
May 22, 2026
May 27, 2026
10.0 CRITICAL
CVE-2026-23652 — Microsoft Power Pages Remote Code Execution Vulnerability

Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execute code over a network.

May 22, 2026 May 27, 2026
May 22, 2026
May 27, 2026
8.7 HIGH
CVE-2026-41147 — NukeViet CMS: Stored Cross-Site Scripting (XSS) via insufficient server-side input saniti…

NukeViet CMS is a multi Content Management System. Versions 4.5.07 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability caused by insufficient server-side input sanitization in the Req…

nukeviet | Remote | Cross-Site Scripting
May 22, 2026 May 26, 2026
May 22, 2026
May 26, 2026
8.1 HIGH
CVE-2026-41076 — RT: LDAP authentication bypass via empty password

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.9 and prior in addition to 6.0.0 through 6.0.2 contain an authentication bypass vulnerability in RT installations…

request_tracker | Remote | Authentication
May 22, 2026 May 26, 2026
May 22, 2026
May 26, 2026
8.8 HIGH
CVE-2026-41075 — RT: SQL injection via entry_aggregator parameter in JSON search

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 through 5.0.9 and 6.0.0 through 6.0.2 contain an SQL injection vulnerability. An authenticated user can craft i…

request_tracker | Remote | Injection
May 22, 2026 May 26, 2026
May 22, 2026
May 26, 2026
7.1 HIGH
CVE-2026-41074 — RT has broken CSRF protection for authenticated users

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 through 6.0.2 contain a Cross-Site Request Forgery (CSRF) vulnerability. An attacker who can induce a logged-in…

request_tracker | Remote | Cross-Site Request Forgery
May 22, 2026 May 26, 2026
May 22, 2026
May 26, 2026
Showing 20 of 6724 Results