CVE Vulnerability Database
Search and browse 376,666 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-63508 | CRITICAL | 10 | 0.5% | Aug 7, 2026 | Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elev... |
| CVE-2026-62918 | HIGH | 7.5 | 0.3% | Aug 7, 2026 | Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing ... |
| CVE-2026-62896 | CRITICAL | 9.6 | 0.4% | Aug 7, 2026 | Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-62873 | CRITICAL | 9.8 | 0.4% | Aug 7, 2026 | Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevat... |
| CVE-2026-62836 | CRITICAL | 10 | 0.4% | Aug 7, 2026 | Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized... |
| CVE-2026-62830 | CRITICAL | 9.9 | 0.4% | Aug 7, 2026 | Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-59118 | CRITICAL | 9.3 | 0.4% | Aug 7, 2026 | Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-59115 | CRITICAL | 9.9 | 0.6% | Aug 7, 2026 | '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges ove... |
| CVE-2026-56162 | CRITICAL | 10 | 0.5% | Aug 7, 2026 | Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-56161 | CRITICAL | 9.6 | 0.4% | Aug 7, 2026 | Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. |
| CVE-2026-50515 | CRITICAL | 9.9 | 0.9% | Aug 7, 2026 | Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. |
| CVE-2026-50481 | CRITICAL | 9.9 | 0.5% | Aug 7, 2026 | Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privile... |
| CVE-2026-49163 | HIGH | 8.8 | 0.6% | Aug 7, 2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows a... |
| CVE-2026-17264 | MEDIUM | 5.3 | 0.3% | Aug 7, 2026 | Opening a crafted DICOM file containing malicious JPEG-compressed pixel data triggers an attacker-controlled heap out-of... |
| CVE-2026-15805 | — | — | — | Aug 7, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-8325 | HIGH | 7.8 | 0.1% | Aug 6, 2026 | A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A ma... |
| CVE-2026-7867 | HIGH | 7.8 | 0.2% | Aug 6, 2026 | A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization chec... |
| CVE-2026-7406 | HIGH | 7.8 | 0.1% | Aug 6, 2026 | A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference... |
| CVE-2026-7405 | MEDIUM | 5.5 | 0.1% | Aug 6, 2026 | A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-B... |
| CVE-2026-71555 | MEDIUM | 4.1 | 0.2% | Aug 6, 2026 | PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton. From 2.1.0 until 4.14.1, PILOS do... |
| CVE-2026-71554 | MEDIUM | 5.3 | 0.3% | Aug 6, 2026 | h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header ... |
| CVE-2026-71498 | MEDIUM | 5.1 | 0.2% | Aug 6, 2026 | node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.26.1, passing a Buffer whose final byt... |
| CVE-2026-71497 | MEDIUM | 4.7 | 0.2% | Aug 6, 2026 | jsoup is a Java library for working with real-world HTML. From 1.14.3 until 1.23.1, jsoup's HTML parser could incorrectl... |
| CVE-2026-71488 | HIGH | 7.5 | 0.3% | Aug 6, 2026 | league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially craf... |
| CVE-2026-71478 | MEDIUM | 6.1 | 0.2% | Aug 6, 2026 | league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the Attributes... |
