| CVE / ID | Title | Severity | CVSS | Source | Date |
|---|
| CVE-2026-64633 | A vulnerability allowing remote unauthenticated code execution on the agent host. | CRITICAL | 10.0 | NVD | 2026-08-04 |
| CVE-2026-16940 | The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing un | CRITICAL | 10.0 | NVD | 2026-08-05 |
| CVE-2026-48168 | PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vuln | CRITICAL | 10.0 | NVD | 2026-08-05 |
| CVE-2026-5430 | The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or support | CRITICAL | 10.0 | NVD | 2026-08-06 |
| CVE-2026-65553 | Unauthenticated Remote Code Execution (RCE) in Spider Analyser – WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions. | CRITICAL | 10.0 | NVD | 2026-08-06 |
| CVE-2026-66665 | Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions. | CRITICAL | 10.0 | NVD | 2026-08-06 |
| CVE-2026-11976 | The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both | CRITICAL | 10.0 | NVD | 2026-08-06 |
| CVE-2026-14812 | The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator | CRITICAL | 10.0 | NVD | 2026-08-06 |
| CVE-2026-56162 | Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. | CRITICAL | 10.0 | NVD | 2026-08-07 |
| CVE-2026-63508 | Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elev | CRITICAL | 10.0 | NVD | 2026-08-07 |
| CVE-2026-65667 | Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. | CRITICAL | 10.0 | NVD | 2026-08-07 |
| CVE-2026-66915 | Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.6.7 - An unauthenticated attacker could execute ar | CRITICAL | 10.0 | NVD | 2026-08-10 |
| CVE-2026-72898 | Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint a | CRITICAL | 10.0 | NVD | 2026-08-10 |
| CVE-2026-72899 | Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes | CRITICAL | 10.0 | NVD | 2026-08-10 |
| CVE-2022-36648 | CVE-2022-36648 | CRITICAL | 10.0 | Microsoft | 2024-09-10 |
| CVE-2025-32433 | Erlang/OTP SSH Vulnerable to Pre-Authentication RCE | CRITICAL | 10.0 | Microsoft | 2025-04-08 |
| CVE-2026-56163 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-66803 | Azure Cosmos DB Remote Code Execution Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-56191 | Microsoft Exchange Online Tampering Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-57106 | Data Quality Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-62825 | Azure Key Vault Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-58630 | Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-58275 | Azure DNS Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-40412 | Azure Orbital Spatio Remote Code Execution Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-23652 | Microsoft Power Pages Remote Code Execution Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-47280 | Azure Resource Manager Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-42822 | Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-42826 | Azure DevOps Information Disclosure Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-41104 | Microsoft Planetary Computer Pro Information Disclosure Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-42901 | Microsoft Entra ID Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-42960 | Possible cache poisoning via promiscuous records for the authority section | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-65667 | Microsoft Teams Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-06 |
| CVE-2026-56162 | Azure SQL Database Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-06 |
| CVE-2026-63508 | Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-06 |
| CVE-2026-10090 | A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cl | CRITICAL | 9.9 | NVD | 2026-08-05 |
| CVE-2026-71268 | OpenPLC Runtime v3's compile_program function (webserver/openplc.py) parses directives from uploaded Structured Text (.s | CRITICAL | 9.9 | NVD | 2026-08-05 |
| CVE-2026-7329 | An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic | CRITICAL | 9.9 | NVD | 2026-08-05 |
| CVE-2026-8709 | An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server bef | CRITICAL | 9.9 | NVD | 2026-08-05 |
| CVE-2026-9193 | An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and | CRITICAL | 9.9 | NVD | 2026-08-05 |
| CVE-2026-20303 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering t | CRITICAL | 9.9 | NVD | 2026-08-05 |