Common Vulnerabilities and Exposures (CVE)

CVE-2026-58425

Aug 14, 2026 17:33:14 UTC

OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)

CVE-2026-73847

Aug 14, 2026 17:33:02 UTC

Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant execute_tool action in admin/ai.php lets a remote unauthenticated attacker submit a forged cross-site request from an attack...

CVE-2026-19846

Aug 14, 2026 17:31:52 UTC

A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument url leads to stack-based bu...

CVE-2026-58427

Aug 14, 2026 17:30:58 UTC

Private org member list leaked via /members API endpoint — incomplete fix for PR #38145

CVE-2026-19847

Aug 14, 2026 17:30:09 UTC

A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component wps.so. The manipulation of the argument pin results in stack-based bu...

CVE-2026-58428

Aug 14, 2026 17:29:36 UTC

Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)

CVE-2026-19639

Aug 14, 2026 17:28:49 UTC

An improper access control vulnerability exists where an authenticated non-administrative application user could potentially view settings outside of their assigned scope.

CVE-2026-58429

Aug 14, 2026 17:28:06 UTC

Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints

CVE-2026-19628

Aug 14, 2026 17:27:26 UTC

A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve arbitrary command execution on the underlying operating system when specific backen...

CVE-2026-50313

Aug 14, 2026 17:26:10 UTC

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

CVE-2026-49162

Aug 14, 2026 17:26:10 UTC

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

CVE-2026-40400

Aug 14, 2026 17:26:09 UTC

Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.

CVE-2026-62835

Aug 14, 2026 17:26:08 UTC

Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.

CVE-2026-58275

Aug 14, 2026 17:26:08 UTC

Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-58630

Aug 14, 2026 17:26:07 UTC

Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.