Live feed All digests
← 2026-06-21 2026-08-13

Security Digest — 2026-08-13

11495
Total vulnerabilities
629
Critical
3956
High
4
Actively exploited

Top vulnerabilities

CVE / IDTitleSeverityCVSSSourceDate
CVE-2026-5430The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supportCRITICAL10.0NVD2026-08-06
CVE-2026-65553Unauthenticated Remote Code Execution (RCE) in Spider Analyser &#8211; WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions.CRITICAL10.0NVD2026-08-06
CVE-2026-66665Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.CRITICAL10.0NVD2026-08-06
CVE-2026-11976The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both CRITICAL10.0NVD2026-08-06
CVE-2026-14812The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator CRITICAL10.0NVD2026-08-06
CVE-2026-56162Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.CRITICAL10.0NVD2026-08-07
CVE-2026-63508Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevCRITICAL10.0NVD2026-08-07
CVE-2026-65667Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.CRITICAL10.0NVD2026-08-07
CVE-2026-66915Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.6.9 - An unauthenticated attacker could execute arCRITICAL10.0NVD2026-08-10
CVE-2026-72898Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint aCRITICAL10.0NVD2026-08-10
CVE-2026-72899Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposesCRITICAL10.0NVD2026-08-10
CVE-2026-58231SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafCRITICAL10.0NVD2026-08-11
CVE-2026-58115A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running InCRITICAL10.0NVD2026-08-11
CVE-2026-48056Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 improCRITICAL10.0NVD2026-08-11
CVE-2026-17061A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2CRITICAL10.0NVD2026-08-11
CVE-2026-48362ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CRITICAL10.0NVD2026-08-11
CVE-2026-27302Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary codeCRITICAL10.0NVD2026-08-11
CVE-2026-71398Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary codeCRITICAL10.0NVD2026-08-11
CVE-2026-45618LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitCRITICAL10.0NVD2026-08-11
CVE-2026-67282Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker CRITICAL10.0NVD2026-08-12
CVE-2026-73299Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks rCRITICAL10.0NVD2026-08-12
CVE-2024-27253IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to performCRITICAL10.0NVD2026-08-12
CVE-2026-63508Microsoft Planetary Computer Pro Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-56162Azure SQL Database Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-65667Microsoft Teams Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-08-11
CVE-2026-56163Microsoft Azure Kubernetes Service Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-66803Azure Cosmos DB Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-56191Microsoft Exchange Online Tampering VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-57106Data Quality Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-62825Azure Key Vault Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-58630Azure App Service on Azure Stack Hub Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-58275Azure DNS Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-07-14
CVE-2026-45480Azure Active Directory Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-06-09
CVE-2026-48567Azure HorizonDB Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-06-09
CVE-2022-49043xmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a use-after-free.CRITICAL10.0Microsoft2025-01-14
CVE-2026-40175Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection ChainCRITICAL10.0Microsoft2026-04-14
CVE-2017-20230Storable versions before 3.05 for Perl has a stack overflowCRITICAL10.0Microsoft2026-04-14
CVE-2026-33819Microsoft Bing Remote Code Execution VulnerabilityCRITICAL10.0Microsoft2026-04-14
CVE-2026-32186Microsoft Bing Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-04-14
CVE-2026-33107Azure Databricks Elevation of Privilege VulnerabilityCRITICAL10.0Microsoft2026-04-14