Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
10.0 CRITICAL
CVE-2026-70200 — Azure Logic Apps Elevation of Privilege Vulnerability

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
9.3 CRITICAL
CVE-2026-70009 — Azure Arc Elevation of Privilege Vulnerability

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
10.0 CRITICAL
CVE-2026-69865 — Microsoft Container Registry Elevation of Privilege Vulnerability

Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network.

Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
10.0 CRITICAL
CVE-2026-69399 — Azure Arc Elevation of Privilege Vulnerability

Azure Arc Elevation of Privilege Vulnerability

Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.6 HIGH
CVE-2026-68791 — Azure Machine Learning Information Disclosure Vulnerability

Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network.

Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
6.1 MEDIUM
CVE-2026-55946 — Microsoft Copilot Information Disclosure Vulnerability

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.

Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.5 HIGH
CVE-2026-93426 — SigNoz 0.87.0 before 0.142.0 - SQL Injection in v5 Query Builder Field Key Names

SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL. Attackers with Viewer role or highe…

Remote | Injection
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
4.3 MEDIUM
CVE-2026-93307 — O-RAN-SC SMO OAM VES Collector memory allocation

A vulnerability has been found in O-RAN-SC SMO OAM 2025-06-10. Affected is an unknown function of the component VES Collector. Such manipulation of the argument additionalFields.padding leads to unco…

smo_oam | Remote | Memory Corruption
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.4 HIGH
CVE-2026-86688 — Session id is not renewed on authentication in ash_authentication, allowing session fixat…

Session Fixation vulnerability in team-alembic ash_authentication allows an attacker who can plant a session identifier in a victim's browser to hold an authenticated session once that victim signs i…

ash_authentication | Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
9.1 CRITICAL
CVE-2026-76949 — Remember-me sign-in guard reads a session key that is never written in ash_authentication…

Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who can plant a remember-me cookie in a victim's browser to replace that victim's authenticated s…

ash_authentication | Remote | Authentication
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
0.0 NA
CVE-2026-73639 — Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row…

Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tRNS transparency chunk in read_direct8. With a tRNS chunk, read_direct8() adds …

imager | Memory Corruption
Sep 17, 2026 Sep 18, 2026
Sep 17, 2026
Sep 18, 2026
0.0 NA
CVE-2026-73638 — Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF block via unchec…

Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF block via unchecked start offsets in tiff_load_ifd. tiff_load_ifd() validates an IFD entry's data by checking that `entry->of…

imager | Memory Corruption
Sep 17, 2026 Sep 18, 2026
Sep 17, 2026
Sep 18, 2026
9.1 CRITICAL
CVE-2026-54767 — WeGIA: Hardcoded Secret Key Backdoor — Mass Data Destruction via deletar_socios.php

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php exposes an unauthenticated GET endpoint whose chave parameter is checked only …

wegia | Remote | Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
10.0 CRITICAL
CVE-2026-54734 — Prebid Server Java: Vulnerability to request forgery allows for possible host environment…

Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplied parameters into outbound request URLs without using HttpUtil to validate th…

Remote | Server-Side Request Forgery
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
8.8 HIGH
CVE-2026-54671 — WeGIA: Authorization Bypass via Empty Resource Array in InternoControle

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, WeGIA maps InternoControle to an empty resource array in web/controle/control.php, and verificarPermissao in web/dao/MiddlewareDAO.…

wegia | Remote | Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
9.1 CRITICAL
CVE-2026-54670 — WeGIA: Unauthenticated Auth Bypass + Local File Inclusion

WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/contribuicao/controller/control.php accepts attacker-controlled nomeClasse and meto…

wegia | Remote | Path Traversal
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
6.5 MEDIUM
CVE-2026-54648 — CubeCart: Missing Authorization Check in customers.gdpr.inc.php Leads to Unauthorized Cus…

CubeCart is an ecommerce software solution. Prior to 6.7.5, the GDPR tools in admin/sources/customers.gdpr.inc.php rely on page-level CC_PERM_READ access and do not require CC_PERM_DELETE for the pur…

cubecart | Remote | Authorization
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.2 HIGH
CVE-2026-54647 — CubeCart : SQL Injection via download_expire Parameter in settings.index.inc.php

CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/settings.index.inc.php directly concatenates the administrator-controlled download_expire POST parameter into a raw UPDATE st…

cubecart | Remote | Injection
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
7.2 HIGH
CVE-2026-54646 — CubeCart: SQL Identifier Injection via Backtick Bypass in maintenance.index.inc.php

CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/maintenance.index.inc.php places administrator-controlled tablename values into ALTER TABLE, CHECK TABLE, and ANALYZE TABLE s…

cubecart | Remote | Injection
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
4.8 MEDIUM
CVE-2026-54645 — CubeCart: Stored XSS in Product Description Editor via Global Sanitizer Bypass

CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/products.index.inc.php reads the description, description_short, and spec_copy rich-text fields from $GLOBALS['RAW']['POST'] …

cubecart | Remote | Cross-Site Scripting
Sep 17, 2026 Sep 17, 2026
Sep 17, 2026
Sep 17, 2026
Showing 20 of 14441 Results