Common Vulnerabilities and Exposures (CVE)

CVE-2026-57105

Aug 29, 2026 16:20:50 UTC

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVE-2026-65768

Aug 29, 2026 16:20:49 UTC

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.

CVE-2026-58650

Aug 29, 2026 16:20:48 UTC

Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

CVE-2026-56174

Aug 29, 2026 16:20:47 UTC

Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

CVE-2026-50472

Aug 29, 2026 16:20:46 UTC

Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.

CVE-2026-82481

Aug 29, 2026 14:43:52 UTC

The cohttp package before 6.3.0 for OCaml allows directory traversal.

CVE-2026-82477

Aug 29, 2026 14:12:42 UTC

In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers to access internal network resources via the Tenable proxy endpoint. This occurs in apps/backend/src/tenable/tenable.controller.ts.

CVE-2026-82457

Aug 29, 2026 13:47:58 UTC

su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before assigning to uid_t and gid_t, allowing truncation of out-of-range values to zero. Attackers can supply large numeric identifiers that truncat...

CVE-2026-82456

Aug 29, 2026 13:47:57 UTC

argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface us...

CVE-2026-82455

Aug 29, 2026 13:47:56 UTC

RubyGems fails to re-validate path containment after filesystem symlink resolution during gem extraction. When a pre-existing symlink inside the destination directory points outside the extraction root, extracted files that appear to be wri...

CVE-2026-82454

Aug 29, 2026 13:47:56 UTC

The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The decodeAppleToken function extracted the 'alg' field from the attacker-supplied JWT header and passed...

CVE-2026-82453

Aug 29, 2026 13:47:55 UTC

rust-iot-platform through commit 5df942ab stores user passwords in cleartext without hashing in the user model. Attackers can read API responses from user retrieval and listing routes to obtain plaintext credentials for all accounts.

CVE-2026-82452

Aug 29, 2026 13:47:54 UTC

rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures. Unauthenticated attackers can create, update, list, retrieve, and d...

CVE-2026-82451

Aug 29, 2026 13:47:54 UTC

Formwork through 2.3.14 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer header host unescaped. Unauthenticated attackers can craft malicious Referer headers to inject markup that executes in a...

CVE-2026-82450

Aug 29, 2026 13:47:53 UTC

BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Create Books permissions to upload a PHP polyglot file as a book cover. Attackers can...