| | CVE-2026-63046 | Apache | high | 8.8 | 0.4%
| | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in … | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-62440 | Apache | critical | 9.1 | 0.3%
| | Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowi… | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-61422 | Apache | medium | 4.3 | 0.2%
| | Authenticated pre-validation SSRF vulnerability in Apache CloudStack's template and ISO registration… | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-61400 | Apache | high | 8.8 | 1.5%
| | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in… | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-61399 | Apache | medium | 4.8 | 0.3%
| | Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Lock Use… | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-61398 | Apache | critical | 9.1 | 0.3%
| | Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance… | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-61397 | Apache | high | 7.5 | 0.3%
| | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAut… | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-59799 | Apache | high | 8.8 | 0.3%
| | Improper Privilege Management vulnerability in Apache CloudStack's Two-factor authentication plugin … | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-59780 | Apache | high | 7.5 | 0.3%
| | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's LDAP… | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-59657 | Apache | high | 7.5 | 0.2%
| | Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack with AsyncJob storage … | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-59655 | Apache | high | 7.5 | 0.3%
| | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAut… | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-59085 | Apache | critical | 9.1 | 0.3%
| | Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable … | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-50222 | Apache | high | 7.5 | 0.3%
| | Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in A… | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-50112 | Apache | high | 8.8 | 0.5%
| | SSRF via Metalink Mirror URL Resolution:
An authenticated tenant can register a template pointing t… | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-47359 | Apache | high | 8.8 | 1.1%
| | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabi… | Aug 21, 2026 | Aug 27, 2026 |
| | CVE-2026-74866 | Red Hat | medium | 5.8 | 0.2%
| | @fastify/busboy is a multipart form-data parser for Node.js. Its multipart part-header parser splits… | Aug 21, 2026 | Aug 21, 2026 |
| | CVE-2026-79655 | Red Hat | high | 7.8 | 0.1%
| | A flaw was found in sos clean, a utility within the sos package. This vulnerability allows a local a… | Aug 21, 2026 | Aug 21, 2026 |
| | CVE-2026-77680 | Red Hat | medium | 5.3 | 0.3%
| | An algorithmic complexity flaw exists in libsoup's HTTP Range header processing that persists after … | Aug 21, 2026 | Aug 21, 2026 |
| | CVE-2026-74581 | Red Hat | high | 7.8 | 0.4%
| ✓ Fix | In the Linux kernel, the following vulnerability has been resolved:
net: ipv6: clear suppressed fib6… | Aug 21, 2026 | Aug 21, 2026 |
| | CVE-2026-74583 | Red Hat | high | 7.8 | 0.1%
| | In the Linux kernel, the following vulnerability has been resolved:
net/sched: cls_route: fix fastma… | Aug 21, 2026 | Aug 21, 2026 |
| | CVE-2026-74580 | Red Hat | high | 7.3 | 0.1%
| | In the Linux kernel, the following vulnerability has been resolved:
vhost: reset the vring metadata … | Aug 21, 2026 | Aug 21, 2026 |
| | CVE-2026-74582 | Red Hat | high | 7.0 | 0.1%
| | In the Linux kernel, the following vulnerability has been resolved:
packet: use consistent hard_head… | Aug 21, 2026 | Aug 21, 2026 |
| | CVE-2026-79992 | Red Hat | high | 7.8 | 0.1%
| | A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing mal… | Aug 21, 2026 | Aug 21, 2026 |
| | CVE-2026-77648 | Red Hat | low | 2.2 | 0.2%
| | In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that
bypass import_f… | Aug 20, 2026 | Aug 20, 2026 |
| | CVE-2026-69851 | Microsoft | critical | 9.9 | 0.4%
| | Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevat… | Aug 20, 2026 | Aug 25, 2026 |
| | CVE-2026-69836 | Microsoft | critical | 10.0 | 1.6%
| | Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute c… | Aug 20, 2026 | Aug 25, 2026 |
| | CVE-2026-69558 | Microsoft | high | 8.6 | 0.5%
| | Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized … | Aug 20, 2026 | Aug 25, 2026 |
| | CVE-2026-69555 | Microsoft | critical | 10.0 | 0.4%
| | Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a ne… | Aug 20, 2026 | Aug 24, 2026 |
| | CVE-2026-69543 | Microsoft | high | 8.5 | 0.3%
| | Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevat… | Aug 20, 2026 | Aug 26, 2026 |
| | CVE-2026-69519 | Microsoft | high | 8.6 | 0.6%
| | Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose infor… | Aug 20, 2026 | Aug 25, 2026 |
| | CVE-2026-69400 | Microsoft | critical | 9.6 | 0.6%
| | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps a… | Aug 20, 2026 | Aug 24, 2026 |
| | CVE-2026-68789 | Microsoft | critical | 9.9 | 0.5%
| | Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Da… | Aug 20, 2026 | Aug 24, 2026 |
| | CVE-2026-68782 | Microsoft | critical | 9.9 | 0.5%
| | Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Da… | Aug 20, 2026 | Aug 24, 2026 |
| | CVE-2026-66800 | Microsoft | high | 8.6 | 0.5%
| | Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose… | Aug 20, 2026 | Aug 24, 2026 |
| | CVE-2026-66309 | Microsoft | critical | 9.1 | 0.5%
| | Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges ov… | Aug 20, 2026 | Aug 24, 2026 |
| | CVE-2026-65816 | Microsoft | critical | 10.0 | 0.5%
| | Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevat… | Aug 20, 2026 | Aug 24, 2026 |
| | CVE-2026-65801 | Microsoft | critical | 10.0 | 0.5%
| | Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to e… | Aug 20, 2026 | Aug 24, 2026 |
| | CVE-2026-65770 | Microsoft | critical | 10.0 | 0.6%
| | Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed … | Aug 20, 2026 | Aug 25, 2026 |
| | CVE-2026-62834 | Microsoft | critical | 9.3 | 0.3%
| | Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attack… | Aug 20, 2026 | Aug 24, 2026 |
| | CVE-2026-55015 | Microsoft | medium | 5.5 | 0.5%
| | Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny servic… | Aug 20, 2026 | Aug 26, 2026 |
| | CVE-2026-55013 | Microsoft | high | 7.1 | 0.2%
| | Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to per… | Aug 20, 2026 | Aug 26, 2026 |
| | CVE-2026-72848 | Red Hat | high | 8.6 | 0.5%
| | SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documente… | Aug 20, 2026 | Aug 20, 2026 |
| | CVE-2026-72818 | Red Hat | high | 7.5 | 0.5%
| | The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and app… | Aug 20, 2026 | Aug 20, 2026 |
| | CVE-2026-55893 | Red Hat | medium | 7.0 | 0.1%
| ✓ Fix | Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.… | Aug 20, 2026 | Aug 20, 2026 |
| | CVE-2026-55894 | Red Hat | medium | 5.5 | 0.1%
| ✓ Fix | Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.… | Aug 20, 2026 | Aug 20, 2026 |
| | CVE-2026-77643 | Red Hat | medium | 4.4 | 0.2%
| | A cross-site scripting vulnerability in
queryparser/termgenerator_internal.cc in Xapian xapian-core… | Aug 20, 2026 | Aug 20, 2026 |
| | CVE-2026-70654 | Red Hat | medium | 4.4 | 0.1%
| | libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, applicati… | Aug 20, 2026 | Aug 20, 2026 |
| | CVE-2026-70651 | Red Hat | medium | 6.1 | 0.1%
| | libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips b… | Aug 20, 2026 | Aug 20, 2026 |
| | CVE-2026-70652 | Red Hat | medium | 5.0 | 0.1%
| | libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips b… | Aug 20, 2026 | Aug 20, 2026 |
| | CVE-2026-69242 | Red Hat | high | 7.8 | 0.2%
| | libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, a crafted… | Aug 20, 2026 | Aug 20, 2026 |