| CVE / ID | Title | Severity | CVSS | Source | Date |
|---|
| CVE-2026-82222 | Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection.
This issue af | CRITICAL | 10.0 | NVD | 2026-08-28 |
| CVE-2026-54745 | Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the | CRITICAL | 10.0 | NVD | 2026-08-28 |
| CVE-2026-82456 | argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller c | CRITICAL | 10.0 | NVD | 2026-08-29 |
| CVE-2026-82970 | Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePriva | CRITICAL | 10.0 | NVD | 2026-08-31 |
| CVE-2026-81779 | Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software I | CRITICAL | 10.0 | NVD | 2026-08-31 |
| CVE-2026-81780 | Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions. | CRITICAL | 10.0 | NVD | 2026-08-31 |
| CVE-2026-84147 | This vulnerability exists in the ERP system due to improper authentication controls and inadequate file type validation | CRITICAL | 10.0 | NVD | 2026-09-01 |
| CVE-2026-76657 | Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauth | CRITICAL | 10.0 | NVD | 2026-09-01 |
| CVE-2026-76658 | A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthentica | CRITICAL | 10.0 | NVD | 2026-09-01 |
| CVE-2026-83548 | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended altern | CRITICAL | 10.0 | NVD | 2026-09-01 |
| CVE-2026-4357 | The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as wel | CRITICAL | 10.0 | NVD | 2026-09-02 |
| CVE-2026-85061 | MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/do | CRITICAL | 10.0 | NVD | 2026-09-03 |
| CVE-2026-70352 | Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges | CRITICAL | 10.0 | NVD | 2026-09-03 |
| CVE-2026-83711 | Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker | CRITICAL | 10.0 | NVD | 2026-09-03 |
| CVE-2026-75754 | Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in A | CRITICAL | 10.0 | NVD | 2026-09-04 |
| CVE-2026-72811 | SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (clie | CRITICAL | 10.0 | GitHub | 2026-09-03 |
| CVE-2026-69083 | SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachab | CRITICAL | 10.0 | GitHub | 2026-09-03 |
| CVE-2026-69084 | SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on | CRITICAL | 10.0 | GitHub | 2026-09-03 |
| CVE-2022-37968 | Azure Arc-enabled Kubernetes cluster Connect Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2022-10-11 |
| CVE-2017-20230 | Storable versions before 3.05 for Perl has a stack overflow | CRITICAL | 10.0 | Microsoft | 2026-04-14 |
| CVE-2026-32186 | Microsoft Bing Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-04-14 |
| CVE-2026-32213 | Azure AI Foundry Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-04-14 |
| CVE-2026-33105 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-04-14 |
| CVE-2026-33107 | Azure Databricks Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-04-14 |
| CVE-2026-33819 | Microsoft Bing Remote Code Execution Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-04-14 |
| CVE-2026-35431 | Microsoft Entra ID Entitlement Management Spoofing Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-04-14 |
| CVE-2025-62168 | Squid vulnerable to information disclosure via authentication credential leakage in error handling | CRITICAL | 10.0 | Microsoft | 2025-10-14 |
| CVE-2025-59503 | Azure Compute Resource Provider Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2025-10-14 |
| CVE-2026-45480 | Azure Active Directory Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-06-09 |
| CVE-2026-48567 | Azure HorizonDB Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-06-09 |
| CVE-2026-39821 | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-42960 | Possible cache poisoning via promiscuous records for the authority section | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-46595 | Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-40412 | Azure Orbital Spatio Remote Code Execution Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-23652 | Microsoft Power Pages Remote Code Execution Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-47280 | Azure Resource Manager Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-42822 | Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-42826 | Azure DevOps Information Disclosure Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-41104 | Microsoft Planetary Computer Pro Information Disclosure Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-05-12 |
| CVE-2026-42901 | Microsoft Entra ID Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-05-12 |