Common Vulnerabilities and Exposures (CVE)

CVE-2026-18685

Aug 3, 2026 23:15:08 UTC

A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the component modem.so. Such manipulation leads to command injection. It is possible to launch the...

CVE-2025-4373

Aug 3, 2026 23:04:37 UTC

A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function. When the position at which to insert the character is large, the position will overflow, leading to a buffer underwrite.

CVE-2026-9804

Aug 3, 2026 23:04:09 UTC

A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an expor...

CVE-2026-50493

Aug 3, 2026 22:59:19 UTC

Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-50341

Aug 3, 2026 22:59:18 UTC

Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.

CVE-2026-50416

Aug 3, 2026 22:59:18 UTC

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.

CVE-2026-62835

Aug 3, 2026 22:59:17 UTC

Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.

CVE-2026-58275

Aug 3, 2026 22:59:17 UTC

Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-58630

Aug 3, 2026 22:59:16 UTC

Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-62825

Aug 3, 2026 22:59:16 UTC

Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-57106

Aug 3, 2026 22:59:15 UTC

Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-56191

Aug 3, 2026 22:59:15 UTC

Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.

CVE-2026-50517

Aug 3, 2026 22:59:14 UTC

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

CVE-2026-49159

Aug 3, 2026 22:59:14 UTC

Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.

CVE-2026-35425

Aug 3, 2026 22:59:13 UTC

Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.