| CVE / ID | Title | Severity | CVSS | Source | Date |
|---|
| CVE-2026-5430 | The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or support | CRITICAL | 10.0 | NVD | 2026-08-06 |
| CVE-2026-65553 | Unauthenticated Remote Code Execution (RCE) in Spider Analyser – WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions. | CRITICAL | 10.0 | NVD | 2026-08-06 |
| CVE-2026-66665 | Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions. | CRITICAL | 10.0 | NVD | 2026-08-06 |
| CVE-2026-11976 | The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both | CRITICAL | 10.0 | NVD | 2026-08-06 |
| CVE-2026-14812 | The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator | CRITICAL | 10.0 | NVD | 2026-08-06 |
| CVE-2026-56162 | Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. | CRITICAL | 10.0 | NVD | 2026-08-07 |
| CVE-2026-63508 | Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elev | CRITICAL | 10.0 | NVD | 2026-08-07 |
| CVE-2026-65667 | Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. | CRITICAL | 10.0 | NVD | 2026-08-07 |
| CVE-2026-66915 | Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.6.9 - An unauthenticated attacker could execute ar | CRITICAL | 10.0 | NVD | 2026-08-10 |
| CVE-2026-72898 | Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint a | CRITICAL | 10.0 | NVD | 2026-08-10 |
| CVE-2026-72899 | Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes | CRITICAL | 10.0 | NVD | 2026-08-10 |
| CVE-2026-58231 | SAP Commerce Cloud allows an unauthenticated
attacker to abuse a default authentication client and submit specially craf | CRITICAL | 10.0 | NVD | 2026-08-11 |
| CVE-2026-58115 | A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running In | CRITICAL | 10.0 | NVD | 2026-08-11 |
| CVE-2026-48056 | Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 impro | CRITICAL | 10.0 | NVD | 2026-08-11 |
| CVE-2026-17061 | A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2 | CRITICAL | 10.0 | NVD | 2026-08-11 |
| CVE-2026-48362 | ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | CRITICAL | 10.0 | NVD | 2026-08-11 |
| CVE-2026-27302 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code | CRITICAL | 10.0 | NVD | 2026-08-11 |
| CVE-2026-71398 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code | CRITICAL | 10.0 | NVD | 2026-08-11 |
| CVE-2026-45618 | LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbit | CRITICAL | 10.0 | NVD | 2026-08-11 |
| CVE-2026-67282 | Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker | CRITICAL | 10.0 | NVD | 2026-08-12 |
| CVE-2026-73299 | Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks r | CRITICAL | 10.0 | NVD | 2026-08-12 |
| CVE-2024-27253 | IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform | CRITICAL | 10.0 | NVD | 2026-08-12 |
| CVE-2026-63508 | Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-56162 | Azure SQL Database Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-65667 | Microsoft Teams Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-56163 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-66803 | Azure Cosmos DB Remote Code Execution Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-56191 | Microsoft Exchange Online Tampering Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-57106 | Data Quality Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-62825 | Azure Key Vault Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-58630 | Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-58275 | Azure DNS Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-45480 | Azure Active Directory Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-06-09 |
| CVE-2026-48567 | Azure HorizonDB Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-06-09 |
| CVE-2022-49043 | xmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a use-after-free. | CRITICAL | 10.0 | Microsoft | 2025-01-14 |
| CVE-2026-40175 | Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain | CRITICAL | 10.0 | Microsoft | 2026-04-14 |
| CVE-2017-20230 | Storable versions before 3.05 for Perl has a stack overflow | CRITICAL | 10.0 | Microsoft | 2026-04-14 |
| CVE-2026-33819 | Microsoft Bing Remote Code Execution Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-04-14 |
| CVE-2026-32186 | Microsoft Bing Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-04-14 |
| CVE-2026-33107 | Azure Databricks Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-04-14 |