Common Vulnerabilities and Exposures (CVE)

CVE-2026-75976

Aug 18, 2026 23:30:11 UTC

A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. Impacted is the function strcpy of the file /cgi-bin/wan.cgi of the component NVRAM. This manipulation of the argument wan_l2tp_password causes stack-based buffer overflow. Th...

CVE-2025-11729

Aug 18, 2026 23:25:59 UTC

The PPWP: Password Protect Pages, Posts & Full or Partial Content plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability check on the can_access function in all versions up to, and including, 1.9.15. ...

CVE-2026-4740

Aug 18, 2026 23:21:35 UTC

A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubernetes client certificate renewal allows a managed cluster administrator to forge a client ce...

CVE-2026-17107

Aug 18, 2026 23:14:55 UTC

A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests withou...

CVE-2026-16242

Aug 18, 2026 23:14:38 UTC

A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not valid...

CVE-2026-70338

Aug 18, 2026 22:28:48 UTC

Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.

CVE-2026-66804

Aug 18, 2026 22:28:47 UTC

Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

CVE-2026-65791

Aug 18, 2026 22:28:47 UTC

Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.

CVE-2026-62869

Aug 18, 2026 22:28:46 UTC

Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network.

CVE-2026-68823

Aug 18, 2026 22:28:46 UTC

Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network.

CVE-2026-49163

Aug 18, 2026 22:28:45 UTC

Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network.

CVE-2026-65667

Aug 18, 2026 22:28:45 UTC

Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-56162

Aug 18, 2026 22:28:44 UTC

Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-50516

Aug 18, 2026 22:28:44 UTC

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-59118

Aug 18, 2026 22:28:43 UTC

Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.