Total
398710 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-62909 | 3 Apple, Linux, Microsoft | 6 Macos, Linux Kernel, .net and 3 more | 2026-08-14 | N/A | 7.8 HIGH |
| Uncaught exception in .NET allows an authorized attacker to elevate privileges locally. | |||||
| CVE-2026-18085 | 1 Blackberry | 1 Unified Endpoint Manager | 2026-08-14 | N/A | 6.9 MEDIUM |
| An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows Arbitrary File Download and Potential Denial of Service. | |||||
| CVE-2026-64908 | 1 Microsoft | 5 365 Apps, Access, Office 2019 and 2 more | 2026-08-14 | N/A | 7.8 HIGH |
| Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. | |||||
| CVE-2026-18084 | 1 Blackberry | 1 Unified Endpoint Manager | 2026-08-14 | N/A | 6.1 MEDIUM |
| Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackBerry UEM allows Cross-Site Scripting (XSS). This issue affects UEM: 12.23.0 QF8 or earlier. | |||||
| CVE-2026-64915 | 1 Microsoft | 6 365 Apps, Microsoft 365, Office 2019 and 3 more | 2026-08-14 | N/A | 7.8 HIGH |
| Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |||||
| CVE-2026-64906 | 1 Microsoft | 5 365 Apps, Access, Office 2019 and 2 more | 2026-08-14 | N/A | 7.8 HIGH |
| Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. | |||||
| CVE-2026-63531 | 1 Microsoft | 6 365 Apps, Microsoft 365, Office 2019 and 3 more | 2026-08-14 | N/A | 5.5 MEDIUM |
| Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |||||
| CVE-2026-63529 | 1 Microsoft | 5 365 Apps, Office 2016, Office 2019 and 2 more | 2026-08-14 | N/A | 5.5 MEDIUM |
| Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | |||||
| CVE-2026-63524 | 1 Microsoft | 6 365 Apps, Microsoft 365, Office 2016 and 3 more | 2026-08-14 | N/A | 5.5 MEDIUM |
| Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | |||||
| CVE-2026-70312 | 1 Microsoft | 5 365 Apps, Microsoft 365, Office 2019 and 2 more | 2026-08-14 | N/A | 5.5 MEDIUM |
| Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | |||||
| CVE-2026-70313 | 1 Microsoft | 5 365 Apps, Microsoft 365, Office 2019 and 2 more | 2026-08-14 | N/A | 7.8 HIGH |
| Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | |||||
| CVE-2026-65810 | 1 Microsoft | 14 .net Framework, Windows 10 1607, Windows 10 1809 and 11 more | 2026-08-14 | N/A | 7.8 HIGH |
| Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally. | |||||
| CVE-2026-3987 | 1 Watchguard | 37 Firebox Cloud, Firebox M270, Firebox M290 and 34 more | 2026-08-14 | N/A | 7.2 HIGH |
| A path traversal vulnerability in the Fireware OS Web UI on WatchGuard Firebox systems may allow a privileged authenticated remote attacker to execute arbitrary code in the context of an elevated system process. | |||||
| CVE-2026-65768 | 1 Microsoft | 1 Teams | 2026-08-14 | N/A | 8.8 HIGH |
| Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-70322 | 1 Microsoft | 5 365 Apps, Microsoft 365, Office 2019 and 2 more | 2026-08-14 | N/A | 5.5 MEDIUM |
| Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | |||||
| CVE-2026-54297 | 1 Faraday Project | 1 Faraday | 2026-08-14 | N/A | 7.5 HIGH |
| Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. From 1.0.0 until 1.10.6 and 2.14.3, Faraday::NestedParamsEncoder, the default nested query parameter encoder/decoder in Faraday, decodes nested query strings without enforcing a maximum nesting depth. A crafted query string causes Faraday to build a deeply nested Ruby Hash structure. The internal dehash routine then recursively walks this attacker-controlled structure without a depth limit. At sufficient depth, Ruby raises an uncaught SystemStackError (stack level too deep), crashing the calling thread or worker. This can lead to denial of service in applications that pass attacker-controlled query strings to Faraday's nested query parsing or URL-building paths. This vulnerability is fixed in 1.10.6 and 2.14.3. | |||||
| CVE-2026-53175 | 1 Linux | 1 Linux Kernel | 2026-08-14 | N/A | 9.8 CRITICAL |
| In the Linux kernel, the following vulnerability has been resolved: inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush On netns teardown, fqdir_pre_exit() walks the fqdir rhashtable and flushes every fragment queue that is not yet complete using inet_frag_queue_flush(). That helper frees all the skbs queued on the fragment queue but does not set INET_FRAG_COMPLETE, and leaves q->fragments_tail and q->last_run_head pointing at the freed skbs. The queue itself stays in the rhashtable. fqdir_pre_exit() first lowers high_thresh to 0 to stop new queue lookups, but it cannot stop a fragment that already obtained the queue through inet_frag_find() earlier and stalled just before taking the queue lock. Once that fragment resumes after the flush and takes the queue lock, it passes the INET_FRAG_COMPLETE check and then dereferences the freed fragments_tail. inet_frag_queue_insert() reads FRAG_CB() and ->len of that pointer and, on the append path, writes ->next_frag, causing a slab use-after-free. IPv6, nf_conntrack_reasm6 and 6lowpan reassembly share the same flush path and are affected as well. Reset rb_fragments, fragments_tail and last_run_head in inet_frag_queue_flush() so a flushed queue no longer points at the freed skbs. A fragment that resumes after the flush and takes the queue lock then finds an empty queue and starts a new run instead of dereferencing the freed fragments_tail. ip_frag_reinit() already performed this reset after its own flush, so drop the now duplicate code there. | |||||
| CVE-2026-4035 | 1 Lfprojects | 1 Mlflow | 2026-08-14 | N/A | 7.7 HIGH |
| A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gateway secrets, which can be exploited to exfiltrate sensitive server-side environment credentials to an attacker-controlled endpoint. This issue arises because the `api_key` field in gateway secrets can accept `$ENV_VAR` references, which are resolved against the MLflow server's environment during runtime. The resolved secrets are then sent in provider authentication headers to the configured upstream `api_base`. This vulnerability can be exploited by low-privileged authenticated users in basic-auth deployments or by unauthenticated users in default deployments without `basic-auth`. The impact includes potential leakage of sensitive credentials such as cloud artifact credentials (`AWS_ACCESS_KEY_ID`, `AWS_SECRET_ACCESS_KEY`), which could lead to artifact poisoning and cross-boundary code execution in downstream environments. The issue is fixed in version 3.11.0. | |||||
| CVE-2026-43001 | 1 Openstack | 1 Keystone | 2026-08-14 | N/A | 7.9 HIGH |
| An issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authenticating application credential. This allowed an attacker holding an unrestricted application credential for project A to create an EC2 credential targeting project B; a subsequent /v3/ec2tokens exchange would then issue a Keystone token scoped to project B while still carrying the original app_cred_id, enabling cross-project lateral movement within the credential owner's role footprint. | |||||
| CVE-2026-34881 | 1 Openstack | 1 Glance | 2026-08-14 | N/A | 5.0 MEDIUM |
| OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use of HTTP redirects, an authenticated user can bypass URL validation checks and redirect to internal services. Only glance image import functionality is affected. In particular, the web-download and glance-download import methods are subject to this vulnerability, as is the optional (not enabled by default) ovf_process image import plugin. | |||||
