| CVE / ID | Title | Severity | CVSS | Source | Date |
|---|
| CVE-2026-58231 | SAP Commerce Cloud allows an unauthenticated
attacker to abuse a default authentication client and submit specially craf | CRITICAL | 10.0 | NVD | 2026-08-11 |
| CVE-2026-58115 | A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running In | CRITICAL | 10.0 | NVD | 2026-08-11 |
| CVE-2026-48056 | Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 impro | CRITICAL | 10.0 | NVD | 2026-08-11 |
| CVE-2026-17061 | A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2 | CRITICAL | 10.0 | NVD | 2026-08-11 |
| CVE-2026-48362 | ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | CRITICAL | 10.0 | NVD | 2026-08-11 |
| CVE-2026-27302 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code | CRITICAL | 10.0 | NVD | 2026-08-11 |
| CVE-2026-71398 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code | CRITICAL | 10.0 | NVD | 2026-08-11 |
| CVE-2026-45618 | LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbit | CRITICAL | 10.0 | NVD | 2026-08-11 |
| CVE-2026-67282 | Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker | CRITICAL | 10.0 | NVD | 2026-08-12 |
| CVE-2026-73299 | Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks r | CRITICAL | 10.0 | NVD | 2026-08-12 |
| CVE-2024-27253 | IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform | CRITICAL | 10.0 | NVD | 2026-08-12 |
| CVE-2026-15413 | The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator- | CRITICAL | 10.0 | NVD | 2026-08-13 |
| CVE-2026-59500 | CWE-287: Improper Authentication | CRITICAL | 10.0 | NVD | 2026-08-13 |
| CVE-2026-27544 | Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions. | CRITICAL | 10.0 | NVD | 2026-08-13 |
| CVE-2026-61962 | Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions. | CRITICAL | 10.0 | NVD | 2026-08-13 |
| CVE-2026-19188 | A critical OS command injection vulnerability has been identified in the
Haiwell IoT Cloud HMI Gateway product. The vul | CRITICAL | 10.0 | NVD | 2026-08-14 |
| CVE-2026-73678 | MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that a | CRITICAL | 10.0 | NVD | 2026-08-14 |
| CVE-2026-72407 | In the Linux kernel, the following vulnerability has been resolved:
geneve: validate inner network offset in geneve_gro | CRITICAL | 10.0 | NVD | 2026-08-15 |
| CVE-2026-72408 | In the Linux kernel, the following vulnerability has been resolved:
geneve: gate GRO hint in geneve_gro_complete() on g | CRITICAL | 10.0 | NVD | 2026-08-15 |
| CVE-2026-72421 | In the Linux kernel, the following vulnerability has been resolved:
ipv4: fib: Don't ignore error route in local/main t | CRITICAL | 10.0 | NVD | 2026-08-15 |
| CVE-2026-74279 | In the Linux kernel, the following vulnerability has been resolved:
crypto: cavium/cpt - fix DMA cleanup using wrong lo | CRITICAL | 10.0 | NVD | 2026-08-15 |
| CVE-2026-74280 | In the Linux kernel, the following vulnerability has been resolved:
crypto: marvell/octeontx - fix DMA cleanup using wr | CRITICAL | 10.0 | NVD | 2026-08-15 |
| CVE-2026-74309 | In the Linux kernel, the following vulnerability has been resolved:
vdpa/octeon_ep: fix IRQ-to-ring mapping in interrup | CRITICAL | 10.0 | NVD | 2026-08-15 |
| CVE-2026-74475 | In the Linux kernel, the following vulnerability has been resolved:
vxlan: use neigh_ha_snapshot() in route_shortcircui | CRITICAL | 10.0 | NVD | 2026-08-15 |
| CVE-2026-74764 | Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a submitted | CRITICAL | 10.0 | NVD | 2026-08-15 |
| CVE-2026-74253 | Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0 - | CRITICAL | 10.0 | NVD | 2026-08-17 |
| USN-8638-1 | USN-8638-1: Axios vulnerabilities | CRITICAL | 10.0 | Ubuntu | 2026-08-13 |
| GHSA-m5w8-4gq2-6f8x | vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host ( | CRITICAL | 10.0 | GitHub | 2026-08-17 |
| CVE-2026-63508 | Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-56162 | Azure SQL Database Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-65667 | Microsoft Teams Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-56163 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-66803 | Azure Cosmos DB Remote Code Execution Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-56191 | Microsoft Exchange Online Tampering Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-57106 | Data Quality Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-62825 | Azure Key Vault Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-58630 | Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-58275 | Azure DNS Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-42960 | Possible cache poisoning via promiscuous records for the authority section | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-46595 | Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh | CRITICAL | 10.0 | Microsoft | 2026-05-12 |