Total
398483 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-69400 | 1 Microsoft | 1 Azure Logic Apps | 2026-08-24 | N/A | 9.6 CRITICAL |
| Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. | |||||
| CVE-2026-68789 | 1 Microsoft | 1 Azure Sql Database | 2026-08-24 | N/A | 9.9 CRITICAL |
| Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | |||||
| CVE-2026-68782 | 1 Microsoft | 1 Azure Sql Database | 2026-08-24 | N/A | 9.9 CRITICAL |
| Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | |||||
| CVE-2026-66309 | 1 Microsoft | 1 Azure Sql Database | 2026-08-24 | N/A | 9.1 CRITICAL |
| Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | |||||
| CVE-2026-73196 | 2 Freeipa, Redhat | 2 Freeipa, Enterprise Linux | 2026-08-24 | N/A | 4.3 MEDIUM |
| A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversized One-Time Password (OTP) key value. This oversized key is then decoded and re-encoded without proper size limits, consuming excessive CPU and memory resources. This can lead to a denial of service, degrading the availability of the IPA service. | |||||
| CVE-2026-65801 | 1 Microsoft | 1 Exchange Online | 2026-08-24 | N/A | 10.0 CRITICAL |
| Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network. | |||||
| CVE-2026-66800 | 1 Microsoft | 1 Azure Data Factory | 2026-08-24 | N/A | 8.6 HIGH |
| Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network. | |||||
| CVE-2026-62834 | 1 Microsoft | 1 Azure Data Factory | 2026-08-24 | N/A | 9.3 CRITICAL |
| Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network. | |||||
| CVE-2026-70885 | 1 Oracle | 1 Hyperion Data Relationship Management | 2026-08-24 | N/A | 8.5 HIGH |
| Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H). | |||||
| CVE-2026-17121 | 1 Ibm | 2 Aix, Vios | 2026-08-24 | N/A | 7.5 HIGH |
| IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to uncontrolled recursion. | |||||
| CVE-2026-2640 | 1 Lenovo | 1 Pcmanager | 2026-08-24 | N/A | 5.5 MEDIUM |
| During an internal security assessment, a potential vulnerability was discovered in Lenovo PC Manager that could allow a local authenticated user to terminate privileged processes. | |||||
| CVE-2026-4134 | 1 Lenovo | 1 Software Fix | 2026-08-24 | N/A | 7.3 HIGH |
| During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to execute code with elevated privileges. | |||||
| CVE-2026-4135 | 1 Lenovo | 1 Software Fix | 2026-08-24 | N/A | 6.6 MEDIUM |
| During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to perform an arbitrary file write with elevated privileges. | |||||
| CVE-2026-1636 | 1 Lenovo | 1 Service Bridge | 2026-08-24 | N/A | 6.7 MEDIUM |
| A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allow a local authenticated user to execute code with elevated privileges. | |||||
| CVE-2026-4145 | 1 Lenovo | 1 Software Fix | 2026-08-24 | N/A | 7.8 HIGH |
| During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges. | |||||
| CVE-2026-70876 | 1 Oracle | 1 Hyperion Data Relationship Management | 2026-08-24 | N/A | 9.1 CRITICAL |
| Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H). | |||||
| CVE-2026-70877 | 1 Oracle | 1 Hyperion Data Relationship Management | 2026-08-24 | N/A | 8.8 HIGH |
| Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). | |||||
| CVE-2026-70878 | 1 Oracle | 1 Hyperion Data Relationship Management | 2026-08-24 | N/A | 8.1 HIGH |
| Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). | |||||
| CVE-2026-70880 | 1 Oracle | 1 Hyperion Data Relationship Management | 2026-08-24 | N/A | 10.0 CRITICAL |
| Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Hyperion Data Relationship Management. While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). | |||||
| CVE-2026-70881 | 1 Oracle | 1 Hyperion Data Relationship Management | 2026-08-24 | N/A | 8.1 HIGH |
| Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). | |||||
