Search Results (9228 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-68407 1 Linux 1 Linux Kernel 2026-08-11 5.3 Medium
In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: free RNR data on MBSSID mismatch nl80211_parse_beacon() rejects EMA RNR data when there are fewer RNR entries than MBSSID entries. The rejected RNR allocation has not been attached to the beacon data yet, so free it before returning the error.
CVE-2026-11940 1 Python 1 Cpython 2026-08-11 N/A
tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself.  The extraction fallback validated the symlink at it's archived location but recreated it at the hardlink's shallower path, letting a relative target the filter judged contained escape the destination directory.  This allowed a malicious tar archive to create a symlink pointing outside the destination, enabling out-of-destination file reads or writes. This was an incomplete fix of CVE-2025-4330.
CVE-2026-63077 1 Jetbrains 1 Teamcity 2026-08-10 9.8 Critical
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
CVE-2026-65945 1 Apache 1 Ranger 2026-08-10 6.5 Medium
Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.
CVE-2026-71577 1 Redhat 1 Multicluster Globalhub 2026-08-10 6.3 Medium
A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed hubs read access to a shared communication topic. This allows a compromised managed hub to intercept and collect sensitive bootstrap kubeconfigs, which contain API server tokens intended for other hubs. These tokens have an extended validity of approximately 9.86 years, significantly increasing the risk of unauthorized access and information disclosure to other managed clusters.
CVE-2026-18464 2 Wordpress, Wp Maps Pro 2 Wordpress, Wp Maps Pro 2026-08-10 7.5 High
The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not restrict the operation it dispatches, allowing unauthenticated attackers to trigger uncontrolled recursion that exhausts server resources, resulting in a Denial of Service.
CVE-2026-15970 1 Hashicorp 2 Consul, Consul Enterprise 2026-08-10 4.2 Medium
Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are vulnerable to an L7 intention authorization bypass when a service proxy is configured with a custom public listener. An authenticated mesh workload may reach HTTP paths that are blocked by a path-based deny intention. This vulnerability, CVE-2026-15970, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
CVE-2026-69659 1 Ash-project 1 Ash 2026-08-10 N/A
Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node via a crafted keyset pagination cursor. Read actions with keyset pagination deserialize the client-supplied page[:after] or page[:before] cursor in decode_values/2 in lib/ash/page/keyset.ex, which base64-decodes the value and passes it to :erlang.binary_to_term/2 without bounding its size. The Erlang external term format supports zlib-compressed payloads, which the decoder inflates transparently, so a cursor of a few kilobytes can allocate tens of megabytes of heap in a single call. Ash itself only ever encodes cursors uncompressed, so the decoder accepts a term shape its encoder never produces. Concurrent requests aggregate these allocations and can terminate the node. This issue affects ash: from 1.17.0 before 3.31.1.
CVE-2024-21405 1 Microsoft 23 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 20 more 2026-08-10 7 High
Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability
CVE-2024-21403 1 Microsoft 2 Azure Kubernetes Service, Azure Kubernetes Service Confidential Containers 2026-08-10 9 Critical
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
CVE-2024-21397 1 Microsoft 1 Azure File Sync 2026-08-10 5.3 Medium
Microsoft Azure File Sync Elevation of Privilege Vulnerability
CVE-2024-21355 1 Microsoft 22 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 19 more 2026-08-10 7 High
Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability
CVE-2023-38181 1 Microsoft 2 Exchange Server, Exchange Server 2016 2026-08-10 8.8 High
Microsoft Exchange Server Spoofing Vulnerability
CVE-2023-38182 1 Microsoft 2 Exchange Server, Exchange Server 2016 2026-08-10 8 High
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-35388 1 Microsoft 2 Exchange Server, Exchange Server 2016 2026-08-10 8 High
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-36928 1 Microsoft 1 Edge Chromium 2026-08-10 6 Medium
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2023-36876 1 Microsoft 2 Windows Server 2008, Windows Server 2008 R2 2026-08-10 7.1 High
Reliability Analysis Metrics Calculation (RacTask) Elevation of Privilege Vulnerability
CVE-2021-34520 1 Microsoft 5 Sharepoint Foundation, Sharepoint Foundation 2013, Sharepoint Server and 2 more 2026-08-10 8.1 High
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2021-34532 2 Microsoft, Redhat 4 Asp.net Core, Visual Studio 2019, Enterprise Linux and 1 more 2026-08-10 5.5 Medium
ASP.NET Core and Visual Studio Information Disclosure Vulnerability
CVE-2021-26426 1 Microsoft 16 Windows 10, Windows 10 1507, Windows 10 1607 and 13 more 2026-08-10 7 High
Windows User Account Profile Picture Elevation of Privilege Vulnerability