Common Vulnerabilities and Exposures (CVE)

CVE-2026-17090

Aug 17, 2026 17:54:40 UTC

The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Button Module 'button' (Button Code) Setting in all versions up to, and including, 2.10.2.2 due to insuffi...

CVE-2026-46345

Aug 17, 2026 17:54:16 UTC

compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the `-o/--output` argument in `trestle author jinja` allows writing files outside the intended workspace. The application does not...

CVE-2026-73522

Aug 17, 2026 17:53:20 UTC

COVESA Open1722 through 0.9.2 contains a stack buffer overflow vulnerability that allows unauthenticated remote attackers to write past the end of a fixed 15-slot stack array by sending a crafted UDP datagram containing more than 15 ACF-CAN...

CVE-2025-62593

Aug 17, 2026 17:52:50 UTC

Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard...

CVE-2026-71980

Aug 17, 2026 17:50:41 UTC

Belledonne Communications bcg729 through 1.1.2 contains an out-of-bounds read vulnerability in the decodeSIDframe() function in src/cng.c that allows unauthenticated network-adjacent attackers to trigger a heap read beyond buffer boundaries...

CVE-2026-15993

Aug 17, 2026 17:49:49 UTC

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to blind SQL Injection via '{username}' Placeholder in Dynamic-Choice Field WHERE Clause in all versions up to, and including, 1.1...

CVE-2026-59902

Aug 17, 2026 17:48:55 UTC

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.sctp.SctpMessageCompletionHandler limits incomplete messages and fragment counts but not maxBufferedBytes,...

CVE-2026-63518

Aug 17, 2026 17:48:31 UTC

Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-62886

Aug 17, 2026 17:48:31 UTC

Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.

CVE-2026-58612

Aug 17, 2026 17:48:30 UTC

Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.

CVE-2026-70337

Aug 17, 2026 17:48:30 UTC

Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.

CVE-2026-63513

Aug 17, 2026 17:48:29 UTC

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-63519

Aug 17, 2026 17:48:29 UTC

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-66807

Aug 17, 2026 17:48:28 UTC

Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2026-62722

Aug 17, 2026 17:48:27 UTC

Heap-based buffer overflow in Windows Brokering File System allows an authorized attacker to elevate privileges locally.