| CVE / ID | Title | Severity | CVSS | Source | Date |
|---|
| CVE-2026-33591 | A vulnerability in Wapt Server before version 2.6.1.17813 allows a remote unauthenticated attacker to bypass
security r | CRITICAL | 10.0 | NVD | 2026-08-03 |
| CVE-2026-48323 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vul | CRITICAL | 10.0 | NVD | 2026-08-03 |
| CVE-2026-48330 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL | CRITICAL | 10.0 | NVD | 2026-08-03 |
| CVE-2026-48331 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in priv | CRITICAL | 10.0 | NVD | 2026-08-03 |
| CVE-2026-64633 | A vulnerability allowing remote unauthenticated code execution on the agent host. | CRITICAL | 10.0 | NVD | 2026-08-04 |
| CVE-2026-16940 | The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing un | CRITICAL | 10.0 | NVD | 2026-08-05 |
| CVE-2026-48168 | PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vuln | CRITICAL | 10.0 | NVD | 2026-08-05 |
| CVE-2026-5430 | The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or support | CRITICAL | 10.0 | NVD | 2026-08-06 |
| CVE-2026-65553 | Unauthenticated Remote Code Execution (RCE) in Spider Analyser – WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions. | CRITICAL | 10.0 | NVD | 2026-08-06 |
| CVE-2026-66665 | Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions. | CRITICAL | 10.0 | NVD | 2026-08-06 |
| CVE-2026-11976 | The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both | CRITICAL | 10.0 | NVD | 2026-08-06 |
| CVE-2026-14812 | The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator | CRITICAL | 10.0 | NVD | 2026-08-06 |
| CVE-2026-56162 | Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. | CRITICAL | 10.0 | NVD | 2026-08-07 |
| CVE-2026-63508 | Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elev | CRITICAL | 10.0 | NVD | 2026-08-07 |
| CVE-2026-65667 | Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. | CRITICAL | 10.0 | NVD | 2026-08-07 |
| CVE-2026-65667 | Microsoft Teams Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-06 |
| CVE-2026-56162 | Azure SQL Database Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-06 |
| CVE-2026-63508 | Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-06 |
| CVE-2026-56163 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-66803 | Azure Cosmos DB Remote Code Execution Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-56191 | Microsoft Exchange Online Tampering Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-57106 | Data Quality Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-62825 | Azure Key Vault Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-58630 | Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-58275 | Azure DNS Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-32169 | Azure Cloud Shell Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-03-10 |
| CVE-2026-42960 | Possible cache poisoning via promiscuous records for the authority section | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-46595 | Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-39821 | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-40412 | Azure Orbital Spatio Remote Code Execution Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-23652 | Microsoft Power Pages Remote Code Execution Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-47280 | Azure Resource Manager Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-42822 | Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-42826 | Azure DevOps Information Disclosure Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-41104 | Microsoft Planetary Computer Pro Information Disclosure Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-42901 | Microsoft Entra ID Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2025-62168 | Squid vulnerable to information disclosure via authentication credential leakage in error handling | CRITICAL | 10.0 | Microsoft | 2025-10-14 |
| CVE-2025-59503 | Azure Compute Resource Provider Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2025-10-14 |
| CVE-2025-65041 | Microsoft Partner Center Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2025-12-09 |
| CVE-2025-65037 | Azure Container Apps Remote Code Execution Vulnerability | CRITICAL | 10.0 | Microsoft | 2025-12-09 |