| CVE / ID | Title | Severity | CVSS | Source | Date |
|---|
| CVE-2026-48772 | ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 2.0.0 through 3.0.8, the ProxySQL MySQL | CRITICAL | 10.0 | NVD | 2026-06-19 |
| CVE-2026-45480 | Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network. | CRITICAL | 10.0 | NVD | 2026-06-19 |
| CVE-2026-48908 | A vulnerability in the SP Page Builder for Joomla allows the upload of arbitrary files for unauthenticated users, ultima | CRITICAL | 10.0 | NVD | 2026-06-20 |
| CVE-2026-48939 | A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature | CRITICAL | 10.0 | NVD | 2026-06-20 |
| GHSA-r253-r9jw-qg44 | Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_args | CRITICAL | 10.0 | GitHub | 2026-06-18 |
| GHSA-82fg-2r99-h7v6 | Duplicate Advisory: PickleScan's pkgutil.resolve_name has a universal blocklist bypass | CRITICAL | 10.0 | GitHub | 2026-06-17 |
| CVE-2026-54782 | CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation | CRITICAL | 10.0 | GitHub | 2026-06-19 |
| CVE-2026-45480 | Azure Active Directory Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-06-09 |
| CVE-2026-48567 | Azure HorizonDB Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-06-09 |
| CVE-2025-29813 | Azure DevOps Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2025-05-13 |
| CVE-2026-42960 | Possible cache poisoning via promiscuous records for the authority section | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-46595 | Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-39821 | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-40412 | Azure Orbital Spatio Remote Code Execution Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-23652 | Microsoft Power Pages Remote Code Execution Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-47280 | Azure Resource Manager Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-42822 | Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-42826 | Azure DevOps Information Disclosure Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-41104 | Microsoft Planetary Computer Pro Information Disclosure Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-42901 | Microsoft Entra ID Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-32169 | Azure Cloud Shell Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-03-10 |
| CVE-2025-55241 | Azure Entra ID Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2025-09-09 |
| CVE-2025-54914 | Azure Networking Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2025-09-09 |
| CVE-2022-49043 | xmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a use-after-free. | CRITICAL | 10.0 | Microsoft | 2025-01-14 |
| CVE-2026-48584 | Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a networ | CRITICAL | 9.9 | NVD | 2026-06-19 |
| CVE-2026-5366 | Prefect version 3.6.23 is vulnerable to remote code execution due to improper handling of user-controlled input in the ` | CRITICAL | 9.9 | NVD | 2026-06-20 |
| CVE-2026-55255 | Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flo | CRITICAL | 9.9 | GitHub | 2026-06-19 |
| CVE-2026-54051 | Network-AI: Improper Neutralization of Special Elements used in an OS Command | CRITICAL | 9.9 | GitHub | 2026-06-19 |
| GHSA-vmmj-pfw7-fjwp | npm PraisonAI codeMode sandbox escape via Function constructor | CRITICAL | 9.9 | GitHub | 2026-06-18 |
| CVE-2026-47647 | Dynamics 365 Elevation of Privilege Vulnerability | CRITICAL | 9.9 | Microsoft | 2026-06-09 |
| CVE-2026-48584 | Microsoft Azure Synapse Elevation of Privilege Vulnerability | CRITICAL | 9.9 | Microsoft | 2026-06-09 |
| CVE-2025-29972 | Azure Storage Resource Provider Spoofing Vulnerability | CRITICAL | 9.9 | Microsoft | 2025-05-13 |
| CVE-2025-29827 | Azure Automation Elevation of Privilege Vulnerability | CRITICAL | 9.9 | Microsoft | 2025-05-13 |
| CVE-2026-7374 | Kubevirt: kubevirt virt-handler: privilege escalation and node compromise via symlink following vulnerability | CRITICAL | 9.9 | Microsoft | 2026-05-12 |
| CVE-2026-33109 | Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability | CRITICAL | 9.9 | Microsoft | 2026-05-12 |
| CVE-2026-40411 | Azure Virtual Network Gateway Remote Code Execution Vulnerability | CRITICAL | 9.9 | Microsoft | 2026-05-12 |
| CVE-2026-42898 | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | CRITICAL | 9.9 | Microsoft | 2026-05-12 |
| CVE-2026-42823 | Azure Logic Apps Elevation of Privilege Vulnerability | CRITICAL | 9.9 | Microsoft | 2026-05-12 |
| CVE-2026-26030 | GitHub: CVE-2026-26030 Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable | CRITICAL | 9.9 | Microsoft | 2026-03-10 |
| CVE-2026-24304 | Azure Resource Manager Elevation of Privilege Vulnerability | CRITICAL | 9.9 | Microsoft | 2026-01-13 |