| | CVE-2026-19404 | Red Hat | medium | 6.5 | 0.4%
| | A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintena… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-12570 | Red Hat | medium | 5.0 | 0.1%
| | A flaw was found in Keras. When loading malicious .keras model files using the keras.models.load_mod… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-68083 | Red Hat | medium | — | — | | A flaw was found in ksmbd, a Linux kernel module that provides an in-kernel SMB server. An authentic… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-6426 | Red Hat | low | 4.4 | — | | A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling. The des… | Aug 10, 2026 | Aug 10, 2026 |
| | CVE-2026-12372 | Red Hat | low | 3.7 | — | | A flaw was found in NLTK. A Server-Side Request Forgery (SSRF) vulnerability allows an attacker to i… | Aug 9, 2026 | Aug 9, 2026 |
| | CVE-2026-71870 | Red Hat | medium | 5.5 | 0.1%
| | pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause la… | Aug 7, 2026 | Aug 7, 2026 |
| | CVE-2026-71852 | Red Hat | medium | 5.5 | 0.1%
| | pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause lo… | Aug 7, 2026 | Aug 7, 2026 |
| | CVE-2026-20348 | Cisco | high | 7.5 | 0.3%
| | A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attac… | Aug 7, 2026 | Aug 19, 2026 |
| | CVE-2026-20347 | Cisco | high | 7.5 | 0.3%
| | A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote at… | Aug 7, 2026 | Aug 11, 2026 |
| | CVE-2026-20346 | Cisco | high | 7.5 | 0.3%
| | A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attac… | Aug 7, 2026 | Aug 11, 2026 |
| | CVE-2026-20345 | Cisco | high | 7.5 | 0.3%
| | A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attac… | Aug 7, 2026 | Aug 11, 2026 |
| | CVE-2026-20339 | Cisco | high | 7.5 | 0.3%
| | A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote at… | Aug 7, 2026 | Aug 11, 2026 |
| | CVE-2026-20338 | Cisco | high | 7.5 | 0.3%
| | A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker … | Aug 7, 2026 | Aug 11, 2026 |
| | CVE-2026-20337 | Cisco | high | 7.5 | 0.4%
| | A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker … | Aug 7, 2026 | Aug 11, 2026 |
| | CVE-2026-71560 | Apache | critical | 9.1 | 0.6%
| | Out-of-bounds Read vulnerability in Apache Fory C++ deserialization.
This issue affects Apache Fory… | Aug 7, 2026 | Aug 8, 2026 |
| | CVE-2026-71559 | Apache | high | 7.5 | 0.6%
| | Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an at… | Aug 7, 2026 | Aug 8, 2026 |
| | CVE-2026-71558 | Apache | critical | 9.8 | 0.7%
| | Heap type confusion vulnerability in Apache Fory C++ deserialization.
This issue affects Apache For… | Aug 7, 2026 | Aug 8, 2026 |
| | CVE-2026-18938 | Red Hat | medium | 6.2 | — | | A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC chan… | Aug 7, 2026 | Aug 7, 2026 |
| | CVE-2026-12261 | Red Hat | medium | 5.3 | 0.2%
| | A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resourc… | Aug 7, 2026 | Aug 7, 2026 |
| | CVE-2026-70332 | Microsoft | critical | 9.6 | 0.5%
| | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of… | Aug 7, 2026 | Aug 7, 2026 |
| | CVE-2026-68823 | Microsoft | critical | 9.1 | 0.5%
| | Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to e… | Aug 7, 2026 | Aug 7, 2026 |
| | CVE-2026-65668 | Microsoft | high | 8.8 | 0.4%
| | Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate pri… | Aug 7, 2026 | Aug 7, 2026 |
| | CVE-2026-65667 | Microsoft | critical | 10.0 | 0.4%
| | Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over … | Aug 7, 2026 | Aug 11, 2026 |
| | CVE-2026-63508 | Microsoft | critical | 10.0 | 0.4%
| | Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthori… | Aug 7, 2026 | Aug 7, 2026 |
| | CVE-2026-62918 | Microsoft | high | 7.5 | 0.3%
| | Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker … | Aug 7, 2026 | Aug 7, 2026 |
| | CVE-2026-62896 | Microsoft | critical | 9.6 | 0.4%
| | Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over … | Aug 7, 2026 | Aug 7, 2026 |
| | CVE-2026-62873 | Microsoft | critical | 9.8 | 0.3%
| | Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorize… | Aug 7, 2026 | Aug 7, 2026 |
| | CVE-2026-62836 | Microsoft | high | 8.7 | 0.4%
| | Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance al… | Aug 7, 2026 | Aug 12, 2026 |
| | CVE-2026-62830 | Microsoft | critical | 9.9 | 0.4%
| | Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a … | Aug 7, 2026 | Aug 7, 2026 |
| | CVE-2026-59118 | Microsoft | critical | 9.3 | 0.4%
| | Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over … | Aug 7, 2026 | Aug 11, 2026 |
| | CVE-2026-59115 | Microsoft | critical | 9.9 | 0.6%
| | '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to el… | Aug 7, 2026 | Aug 7, 2026 |
| | CVE-2026-56162 | Microsoft | critical | 10.0 | 0.5%
| | Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges … | Aug 7, 2026 | Aug 8, 2026 |
| | CVE-2026-56161 | Microsoft | critical | 9.6 | 0.4%
| | Improper access control in Azure Logic Apps allows an authorized attacker to disclose information ov… | Aug 7, 2026 | Aug 7, 2026 |
| | CVE-2026-50515 | Microsoft | critical | 9.9 | 0.9%
| | Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code… | Aug 7, 2026 | Aug 7, 2026 |
| | CVE-2026-50481 | Microsoft | critical | 9.9 | 0.5%
| | Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacke… | Aug 7, 2026 | Aug 7, 2026 |
| | CVE-2026-49163 | Microsoft | high | 8.8 | 0.6%
| | Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insigh… | Aug 7, 2026 | Aug 17, 2026 |
| | CVE-2025-63235 | Red Hat | high | 7.5 | 0.3%
| | In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malfor… | Aug 7, 2026 | Aug 7, 2026 |
| | CVE-2026-34502 | Apache | high | 7.5 | 0.5%
| | Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client
This i… | Aug 6, 2026 | Aug 7, 2026 |
| | CVE-2026-34501 | Apache | high | 7.5 | 0.5%
| | Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client.
This issu… | Aug 6, 2026 | Aug 7, 2026 |
| | CVE-2026-34191 | Apache | critical | 9.1 | 0.4%
| | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i… | Aug 6, 2026 | Aug 7, 2026 |
| | CVE-2026-32327 | Apache | critical | 9.1 | 0.5%
| | A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library co… | Aug 6, 2026 | Aug 7, 2026 |
| | CVE-2025-49506 | Apache | high | 7.5 | 0.4%
| | APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with re… | Aug 6, 2026 | Aug 7, 2026 |
| | CVE-2026-68481 | Apache | high | 7.5 | — | | In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully… | Aug 6, 2026 | Aug 7, 2026 |
| | CVE-2026-68079 | Apache | critical | 9.8 | — | | In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an … | Aug 6, 2026 | Aug 7, 2026 |
| | CVE-2026-65583 | Apache | critical | 9.1 | — | | Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcin… | Aug 6, 2026 | Aug 7, 2026 |
| | CVE-2026-63687 | Apache | critical | 9.1 | — | | Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization… | Aug 6, 2026 | Aug 7, 2026 |
| | CVE-2026-61466 | Apache | critical | 9.1 | — | | In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and st… | Aug 6, 2026 | Aug 7, 2026 |
| | CVE-2026-57818 | Apache | high | 8.1 | — | | A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code … | Aug 6, 2026 | Aug 7, 2026 |
| | CVE-2026-46581 | Red Hat | high | 8.1 | 0.3%
| | In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not prope… | Aug 6, 2026 | Aug 6, 2026 |
| | CVE-2026-68480 | Red Hat | high | 8.8 | — | | An attacker executing code on affected system could inject an interrupt at a precise moment to disru… | Aug 6, 2026 | Aug 6, 2026 |