| CVE / ID | Title | Severity | CVSS | Source | Date |
|---|
| CVE-2026-97163 | Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 | CRITICAL | 10.0 | NVD | 2026-09-26 |
| CVE-2026-96587 | The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These cr | CRITICAL | 10.0 | NVD | 2026-09-29 |
| CVE-2026-71379 | The file export endpoint allows any unauthenticated attacker to export arbitrary database tables by sending a crafted PO | CRITICAL | 10.0 | NVD | 2026-09-29 |
| CVE-2026-96349 | Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions. | CRITICAL | 10.0 | NVD | 2026-09-30 |
| CVE-2026-76570 | Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables 1.21.1 - The fron | CRITICAL | 10.0 | NVD | 2026-09-30 |
| CVE-2026-102427 | Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader. | CRITICAL | 10.0 | NVD | 2026-09-30 |
| CVE-2026-55107 | Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted | CRITICAL | 10.0 | NVD | 2026-09-30 |
| CVE-2026-101148 | The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, tre | CRITICAL | 10.0 | NVD | 2026-10-01 |
| CVE-2026-55393 | Unvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLo | CRITICAL | 10.0 | NVD | 2026-10-01 |
| CVE-2026-103956 | Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remot | CRITICAL | 10.0 | NVD | 2026-10-02 |
| CVE-2026-69085 | SiYuan: Unauthenticated SQL injection in searchDocs via unescaped keyword (publish mode): cross-notebook read/write with | CRITICAL | 10.0 | GitHub | 2026-10-01 |
| GHSA-v2f8-6655-7grj | Vibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chain | CRITICAL | 10.0 | GitHub | 2026-10-02 |
| GHSA-jqmf-mx4f-hfr6 | Vibe-Trading LLM-callable tools permit command execution, code injection, and SSRF | CRITICAL | 10.0 | GitHub | 2026-10-02 |
| CVE-2026-92940 | vm2 exposes host HTTPS credentials and TLS traffic through globalAgent | CRITICAL | 10.0 | GitHub | 2026-10-01 |
| CVE-2026-92937 | vm2: GHSA-m283-3h24-438v fix bypass leads to host RCE via call/apply indirection | CRITICAL | 10.0 | GitHub | 2026-10-01 |
| CVE-2026-92941 | vm2 NodeVM can replace the host process TLS trust store | CRITICAL | 10.0 | GitHub | 2026-10-01 |
| CVE-2026-56162 | Azure SQL Database Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-63508 | Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-65667 | Microsoft Teams Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-65770 | Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-65801 | Microsoft Exchange Online Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-65816 | Azure Arc Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-69502 | Azure SQL Database Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-69555 | Azure Arc Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-69836 | Microsoft Entra ID Remote Code Execution Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-08-11 |
| CVE-2026-62874 | Azure Billing Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-09-08 |
| CVE-2026-69399 | Azure Arc Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-09-08 |
| CVE-2026-69843 | Microsoft Fabric Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-09-08 |
| CVE-2026-69865 | Microsoft Container Registry Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-09-08 |
| CVE-2026-70200 | Azure Logic Apps Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-09-08 |
| CVE-2026-70352 | Azure AI Language Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-09-08 |
| CVE-2026-83711 | Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-09-08 |
| CVE-2026-83944 | Azure Logic Apps Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-09-08 |
| CVE-2026-85889 | Azure AI Foundry Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-09-08 |
| CVE-2026-32169 | Azure Cloud Shell Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2026-03-10 |
| CVE-2025-49752 | Azure Bastion Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2025-11-11 |
| CVE-2025-62168 | Squid vulnerable to information disclosure via authentication credential leakage in error handling | CRITICAL | 10.0 | Microsoft | 2025-10-14 |
| CVE-2025-59503 | Azure Compute Resource Provider Elevation of Privilege Vulnerability | CRITICAL | 10.0 | Microsoft | 2025-10-14 |
| CVE-2026-82377 | Missing Authorization in Apache Roller 6.1.5 allows an authenticated user to read, modify, or delete weblog content belo | CRITICAL | 9.9 | NVD | 2026-09-28 |
| CVE-2026-85526 | Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with in | CRITICAL | 9.9 | NVD | 2026-09-28 |