Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-62873 — Microsoft 365 Admin Center Elevation of Privilege Vulnerability

Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
8.7 HIGH
CVE-2026-62836 — Azure SQL Managed Instance Elevation of Privilege Vulnerability

Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
9.9 CRITICAL
CVE-2026-62830 — Azure SRE Agent Elevation of Privilege Vulnerability

Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
9.3 CRITICAL
CVE-2026-59118 — Microsoft Power Apps Elevation of Privilege Vulnerability

Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
9.9 CRITICAL
CVE-2026-59115 — Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability

'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
10.0 CRITICAL
CVE-2026-56162 — Azure SQL Database Elevation of Privilege Vulnerability

Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
9.6 CRITICAL
CVE-2026-56161 — Azure Logic Apps Information Disclosure Vulnerability

Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
9.9 CRITICAL
CVE-2026-50515 — Azure Service Bus Remote Code Execution Vulnerability

Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
9.9 CRITICAL
CVE-2026-50481 — Azure Active Directory Elevation of Privilege Vulnerability

Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
8.8 HIGH
CVE-2026-49163 — Application Insights Profiler Elevation of Privilege Vulnerability

Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network.

Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
4.3 MEDIUM
CVE-2026-17264 — Medixant RadiAnt DICOM Out-of-bounds write

Opening a crafted DICOM file containing malicious JPEG-compressed pixel data triggers an attacker-controlled heap out-of-bounds write, which may allow an attacker to remotely execute arbitrary code.

Remote | Memory Corruption
Aug 07, 2026 Aug 07, 2026
Aug 07, 2026
Aug 07, 2026
7.8 HIGH
CVE-2026-8325 — PDF File Parsing Out-of-Bounds Write Vulnerability in Autodesk Revit

A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corr…

revit | Memory Corruption
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
7.8 HIGH
CVE-2026-7867 — Udisks2: udisks2: local privilege escalation via as-user option spoofing

A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() …

Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
7.8 HIGH
CVE-2026-7406 — BMP File Parsing Untrusted Pointer Dereference in certain Autodesk products

A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute ar…

autocad autocad_lt revit | Memory Corruption
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
5.5 MEDIUM
CVE-2026-7405 — TIF File Parsing Out-of-Bounds Read in certain Autodesk products

A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A malicious actor can leverage this v…

autocad autocad_lt revit | Denial of Service
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
4.1 MEDIUM
CVE-2026-71555 — PILOS: Reverse tabnabbing in room description

PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. From 2.1.0 until 4.14.1, PILOS does not send a Cross-Origin-Opener-Policy response header, so pages opened by PI…

pilos | Remote | Information Disclosure
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
5.3 MEDIUM
CVE-2026-71554 — h2: Duplicate Host header could facilitate request smuggling

h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than one Host header, and forward every Host header to t…

Remote | Injection
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
5.1 MEDIUM
CVE-2026-71498 — node-re2: Out-of-bounds heap read in `replace`/`split` via a `Buffer` ending in a truncat…

node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.26.1, passing a Buffer whose final bytes form a truncated (incomplete) multi-byte UTF-8 sequence could cause the nati…

| Memory Corruption
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
4.7 MEDIUM
CVE-2026-71497 — jsoup: Cleaner may expose markup with custom raw-text elements

jsoup is a Java library for working with real-world HTML. From 1.14.3 until 1.23.1, jsoup's HTML parser could incorrectly handle a malformed tag name ending in a control character, causing the tag to…

Remote | Cross-Site Scripting
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
7.5 HIGH
CVE-2026-71488 — league/commonmark: Quadratic-time denial of service when parsing crafted Markdown

league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic time complexity when …

commonmark | Remote | Denial of Service
Aug 06, 2026 Aug 06, 2026
Aug 06, 2026
Aug 06, 2026
Showing 20 of 10116 Results