Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-73081 — Activepieces: Remote Code Execution via Command Injection in Code Step Name

Activepieces is an open source AI workflow automation platform. Prior to 0.80.0, the worker's code-compilation pipeline builds the on-disk path for a Code step from the step's name and passes that pa…

activepieces | Remote | Misconfiguration
Aug 11, 2026 Aug 12, 2026
Aug 11, 2026
Aug 12, 2026
5.5 MEDIUM
CVE-2026-72971 — Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability

Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.

Aug 11, 2026 Aug 14, 2026
Aug 11, 2026
Aug 14, 2026
4.0 MEDIUM
CVE-2026-71390 — CAI Content Credentials | Improper Input Validation (CWE-20)

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security meas…

c2pa c2pa-web c2patool | Authentication
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
6.2 MEDIUM
CVE-2026-71389 — CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191)

CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to c…

c2pa c2pa-web c2patool | Denial of Service
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
8.8 HIGH
CVE-2026-71387 — ColdFusion | Incorrect Authorization (CWE-863)

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to ex…

coldfusion | Authorization
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
8.8 HIGH
CVE-2026-71386 — ColdFusion | Cross-site Scripting (XSS) (CWE-79)

is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arb…

coldfusion | Cross-Site Scripting
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
9.6 CRITICAL
CVE-2026-71384 — ColdFusion | Incorrect Authorization (CWE-863)

is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized…

coldfusion | Authorization
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
7.3 HIGH
CVE-2026-71383 — ColdFusion | Incorrect Authorization (CWE-863)

is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited unau…

coldfusion | Remote | Authorization
Aug 11, 2026 Aug 28, 2026
Aug 11, 2026
Aug 28, 2026
8.1 HIGH
CVE-2026-71331 — Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability

Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.

Aug 11, 2026 Aug 20, 2026
Aug 11, 2026
Aug 20, 2026
8.7 HIGH
CVE-2026-70355 — Microsoft SharePoint Server Elevation of Privilege Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

Aug 11, 2026 Aug 13, 2026
Aug 11, 2026
Aug 13, 2026
7.8 HIGH
CVE-2026-70354 — .NET Core Remote Code Execution Vulnerability

Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.

Aug 11, 2026 Aug 17, 2026
Aug 11, 2026
Aug 17, 2026
5.5 MEDIUM
CVE-2026-70348 — Windows Management Services Denial of Service Vulnerability

Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally.

Aug 11, 2026 Aug 14, 2026
Aug 11, 2026
Aug 14, 2026
7.8 HIGH
CVE-2026-70347 — Windows Installer Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

Aug 11, 2026 Aug 16, 2026
Aug 11, 2026
Aug 16, 2026
7.8 HIGH
CVE-2026-70346 — Windows Installer Elevation of Privilege Vulnerability

Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

Aug 11, 2026 Aug 16, 2026
Aug 11, 2026
Aug 16, 2026
7.8 HIGH
CVE-2026-70345 — Windows Installer Elevation of Privilege Vulnerability

Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

Aug 11, 2026 Aug 16, 2026
Aug 11, 2026
Aug 16, 2026
7.8 HIGH
CVE-2026-70344 — Windows Installer Elevation of Privilege Vulnerability

Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

Aug 11, 2026 Aug 16, 2026
Aug 11, 2026
Aug 16, 2026
8.8 HIGH
CVE-2026-70340 — Azure CycleCloud Elevation of Privilege Vulnerability

Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.

azure_cyclecloud | Remote
Aug 11, 2026 Aug 17, 2026
Aug 11, 2026
Aug 17, 2026
7.8 HIGH
CVE-2026-70338 — Microsoft PowerShell Security Feature Bypass Vulnerability

Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.

Aug 11, 2026 Aug 14, 2026
Aug 11, 2026
Aug 14, 2026
8.8 HIGH
CVE-2026-70337 — Microsoft PowerShell Remote Code Execution Vulnerability

Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.

Aug 11, 2026 Aug 14, 2026
Aug 11, 2026
Aug 14, 2026
8.8 HIGH
CVE-2026-70336 — Visual Studio Code Remote Code Execution Vulnerability

Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.

Aug 11, 2026 Sep 02, 2026
Aug 11, 2026
Sep 02, 2026
Showing 20 of 14281 Results