| CVE / ID | Title | Severity | CVSS | Source | Date |
|---|
| CVE-2026-97359 | HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows u | CRITICAL | 10.0 | NVD | 2026-09-24 |
| CVE-2026-97360 | HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticat | CRITICAL | 10.0 | NVD | 2026-09-24 |
| CVE-2026-61732 | Decepticon is an autonomous hacking agent for red teams. Versions prior to 1.1.17 wrap web crawl results — the output of | CRITICAL | 10.0 | NVD | 2026-09-24 |
| CVE-2026-100382 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia Fo | CRITICAL | 10.0 | NVD | 2026-09-25 |
| CVE-2026-97163 | Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 | CRITICAL | 10.0 | NVD | 2026-09-26 |
| CVE-2026-96587 | The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These cr | CRITICAL | 10.0 | NVD | 2026-09-29 |
| CVE-2026-71379 | The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted PO | CRITICAL | 10.0 | NVD | 2026-09-29 |
| CVE-2026-96349 | Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions. | CRITICAL | 10.0 | NVD | 2026-09-30 |
| CVE-2026-76570 | Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables 1.21.1 - The fron | CRITICAL | 10.0 | NVD | 2026-09-30 |
| CVE-2026-102427 | Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader. | CRITICAL | 10.0 | NVD | 2026-09-30 |
| CVE-2026-55107 | Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted | CRITICAL | 10.0 | NVD | 2026-09-30 |
| CVE-2026-61732 | Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output composed into LLM context | CRITICAL | 10.0 | GitHub | 2026-09-24 |
| CVE-2026-59167 | SunEditor: Critical XSS vulnerability - sanitizer bypass | CRITICAL | 10.0 | GitHub | 2026-09-24 |
| CVE-2026-56163 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-56191 | Microsoft Exchange Online Tampering Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-57106 | Data Quality Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-58275 | Azure DNS Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-58630 | Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-62825 | Azure Key Vault Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2026-66803 | Azure Cosmos DB Remote Code Execution Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-07-14 |
| CVE-2025-55241 | Azure Entra ID Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2025-09-09 |
| CVE-2025-54914 | Azure Networking Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2025-09-09 |
| CVE-2024-24576 | Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows | CRITICAL | 10.0 | Microsoft | 2024-04-09 |
| CVE-2025-62168 | Squid vulnerable to information disclosure via authentication credential leakage in error handling | CRITICAL | 10.0 | Microsoft | 2025-10-14 |
| CVE-2025-59503 | Azure Compute Resource Provider Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2025-10-14 |
| CVE-2022-49043 | xmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a use-after-free. | CRITICAL | 10.0 | Microsoft | 2025-01-14 |
| CVE-2025-53767 | Azure OpenAI Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2025-08-12 |
| CVE-2025-29813 | Azure DevOps Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2025-05-13 |
| CVE-2026-19072 | Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each e | CRITICAL | 9.9 | NVD | 2026-09-24 |
| CVE-2026-93425 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories tRPC proc | CRITICAL | 9.9 | NVD | 2026-09-24 |
| CVE-2026-82377 | Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete weblog content belo | CRITICAL | 9.9 | NVD | 2026-09-28 |
| CVE-2026-85526 | Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with in | CRITICAL | 9.9 | NVD | 2026-09-28 |
| CVE-2026-87799 | Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10, | CRITICAL | 9.9 | NVD | 2026-09-28 |
| CVE-2026-84154 | A Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release | CRITICAL | 9.9 | NVD | 2026-09-29 |
| CVE-2026-45499 | Azure OpenAI Elevation of Privilege Vulnerability | CRITICAL | 9.9 | Microsoft | 2026-07-14 |
| CVE-2026-50517 | Microsoft M365 Copilot Remote Code Execution Vulnerability | CRITICAL | 9.9 | Microsoft | 2026-07-14 |
| CVE-2026-54120 | Microsoft Surface Remote Code Execution Vulnerability | CRITICAL | 9.9 | Microsoft | 2026-07-14 |
| CVE-2026-57092 | Microsoft Windows VMSwitch Elevation of Privilege Vulnerability | CRITICAL | 9.9 | Microsoft | 2026-07-14 |
| CVE-2026-57100 | Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability | CRITICAL | 9.9 | Microsoft | 2026-07-14 |
| CVE-2026-44210 | Kata Containers have VM Escape via virtiofsd Argument Injection through Default-Enabled Pod Annotations | CRITICAL | 9.9 | Microsoft | 2026-07-14 |