Common Vulnerabilities and Exposures (CVE)

CVE-2026-65388

Sep 16, 2026 22:24:20 UTC

A remote attacker who controls a container registry may be able to direct a client's token request to a host of the attacker's choice, and disclose the victim's registry credentials to that host. This vulnerability is addressed in container...

CVE-2026-61599

Sep 16, 2026 22:11:45 UTC

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the djust live transport resolves the LiveView to mount from a client-supplied dotted path by calling `__...

CVE-2026-61589

Sep 16, 2026 22:08:52 UTC

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the WebSocket `handle_mount` and `ViewRuntime._build_request` rebuild an `HttpRequest` via `RequestFactor...

CVE-2026-61596

Sep 16, 2026 22:07:20 UTC

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's per-object authorization (`get_object` + `has_object_permission`, ADR-017) was enforced on the We...

CVE-2026-61588

Sep 16, 2026 22:04:03 UTC

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, when a Django `Model` instance is assigned to a public view attribute, djust serialized it to the client ...

CVE-2026-85880

Sep 16, 2026 21:59:41 UTC

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

CVE-2026-83711

Sep 16, 2026 21:59:41 UTC

Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-80098

Sep 16, 2026 21:59:40 UTC

Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-70352

Sep 16, 2026 21:59:40 UTC

Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-62906

Sep 16, 2026 21:59:39 UTC

Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network.

CVE-2026-62804

Sep 16, 2026 21:59:39 UTC

External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-66307

Sep 16, 2026 21:59:38 UTC

Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.

CVE-2026-66303

Sep 16, 2026 21:59:38 UTC

Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.

CVE-2026-85893

Sep 16, 2026 21:59:37 UTC

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-84003

Sep 16, 2026 21:59:36 UTC

Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network.