CVE Daily Brief
Date: 2026-08-12
Summary
- Total qualifying CVEs: 181
- Critical: 43
- High: 138
- With GitHub PoC references: 55
- In CISA KEV: 1
Critical
All Critical CVE details are preserved across this issue and managed follow-up comments.
High Index
- 🟠 CVE-2026-20702 | CVSS
8.9 | Protection mechanism failure for some Intel(R) Data Center Attestation Primitives (Intel(R) DCAP) may allow information disclosure. Unprivi…
- 🟠 CVE-2026-19546 | CVSS
8.8 | A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a detailed Statement, Descriptio…
- 🟠 CVE-2026-49179 | CVSS
8.8 | Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized atta…
- 🟠 CVE-2026-57104 | CVSS
8.8 | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attac…
- 🟠 CVE-2026-59113 | CVSS
8.8 | Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.
- 🟠 CVE-2026-59133 | CVSS
8.8 | Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privilege…
- 🟠 CVE-2026-62784 | CVSS
8.8 | Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a netwo…
- 🟠 CVE-2026-62785 | CVSS
8.8 | Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a n…
- 🟠 CVE-2026-62790 | CVSS
8.8 | Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.
- 🟠 CVE-2026-62795 | CVSS
8.8 | Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
- 🟠 CVE-2026-62800 | CVSS
8.8 | Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.
- 🟠 CVE-2026-62816 | CVSS
8.8 | Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent…
- 🟠 CVE-2026-62817 | CVSS
8.8 | Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network.
- 🟠 CVE-2026-62818 | CVSS
8.8 | Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network.
- 🟠 CVE-2026-62822 | CVSS
8.8 | Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.
- 🟠 CVE-2026-62823 | CVSS
8.8 | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.
- 🟠 CVE-2026-62824 | CVSS
8.8 | Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- 🟠 CVE-2026-62827 | CVSS
8.8 | Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- 🟠 CVE-2026-62869 | CVSS
8.8 | Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network.
- 🟠 CVE-2026-62872 | CVSS
8.8 | Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.
- 🟠 CVE-2026-62913 | CVSS
8.8 | Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
- 🟠 CVE-2026-63514 | CVSS
8.8 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- 🟠 CVE-2026-64901 | CVSS
8.8 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- 🟠 CVE-2026-64921 | CVSS
8.8 | Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a netw…
- 🟠 CVE-2026-65658 | CVSS
8.8 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- 🟠 CVE-2026-65663 | CVSS
8.8 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- 🟠 CVE-2026-65665 | CVSS
8.8 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- 🟠 CVE-2026-65767 | CVSS
8.8 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized at…
- 🟠 CVE-2026-65768 | CVSS
8.8 | Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attack…
- 🟠 CVE-2026-65807 | CVSS
8.8 | Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code ove…
- 🟠 CVE-2026-65811 | CVSS
8.8 | Improper input validation in Power BI allows an authorized attacker to execute code over a network.
- 🟠 CVE-2026-65815 | CVSS
8.8 | Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
- 🟠 CVE-2026-66805 | CVSS
8.8 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- 🟠 CVE-2026-66808 | CVSS
8.8 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- 🟠 CVE-2026-69320 | CVSS
8.8 | Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized att…
- 🟠 CVE-2026-70321 | CVSS
8.8 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- 🟠 CVE-2026-70324 | CVSS
8.8 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- 🟠 CVE-2026-70326 | CVSS
8.8 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- 🟠 CVE-2026-70329 | CVSS
8.8 | Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
- 🟠 CVE-2026-70336 | CVSS
8.8 | Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a netw…
- 🟠 CVE-2026-70337 | CVSS
8.8 | Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.
- 🟠 CVE-2026-71386 | CVSS
8.8 | is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the context of the current user.…
- 🟠 CVE-2026-71387 | CVSS
8.8 | ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the curr…
- 🟠 CVE-2026-15426 | CVSS
8.8 | The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to author…
- 🟠 CVE-2026-73222 | CVSS
8.8 | Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by… | PoC 3
- 🟠 CVE-2026-73224 | CVSS
8.8 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FT… | PoC 3
- 🟠 CVE-2026-73226 | CVSS
8.8 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.186, electerm allows an authenticat… | PoC 4
- 🟠 CVE-2026-15606 | CVSS
8.8 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.9. T…
- 🟠 CVE-2026-55676 | CVSS
8.8 | Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at POST /server/php/sub… | PoC 2`
- 🟠 CVE-2026-19556 | CVSS
8.8 | Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a cr…
- 🟠 CVE-2026-19560 | CVSS
8.8 | Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a…
- 🟠 CVE-2026-19426 | CVSS
8.8 | POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directly access and operat…
- 🟠 CVE-2026-11325 | CVSS
8.8 | Description Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, including a remote cod… | PoC 1
- 🟠 CVE-2026-73284 | CVSS
8.8 | RustFS is a distributed object storage system built in Rust. RustFS AddServiceAccount in rustfs/src/admin/handlers/service_account.rs accep… | PoC 4
- 🟠 CVE-2026-73431 | CVSS
8.8 | Vulnerability-Lookup contains an authentication weakness in its account activation and password-recovery mechanism. Activation and recovery… | PoC 1
- 🟠 CVE-2026-56721 | CVSS
8.7 | CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure direct object reference (IDOR) that allows… | PoC 3
- 🟠 CVE-2026-21273 | CVSS
8.7 | is affected by an Improper Input Validation vulnerability that could result in privilege escalation. A low-privileged attacker could exploi…
- 🟠 CVE-2026-73081 | CVSS
8.7 | Activepieces is an open source AI workflow automation platform. Prior to 0.80.0, the worker's code-compilation pipeline builds the on-disk… | PoC 2
- 🟠 CVE-2016-20097 | CVSS
8.7 | Weaver (Fanwei) E-cology 8.0 contains a SQL injection vulnerability in the SignatureDownLoad servlet that allows unauthenticated remote att…
- 🟠 CVE-2022-50997 | CVSS
8.7 | Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint that allows unauthent…
- 🟠 CVE-2026-48413 | CVSS
8.7 | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject…
- 🟠 CVE-2026-72713 | CVSS
8.7 | XAgent contains a path traversal vulnerability in the workspace file endpoint that allows self-registered or default-credential users to re… | PoC 4
- 🟠 CVE-2026-18697 | CVSS
8.7 | An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) process to terminate une…
- 🟠 CVE-2026-48813 | CVSS
8.7 | Flawfinder is a a static analysis tool for finding vulnerabilities in C/C++ source code. Versions prior to 2.0.20 have an improper input ne… | PoC 1
- 🟠 CVE-2026-14863 | CVSS
8.7 | FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated attackers to achieve…
- 🟠 CVE-2026-29036 | CVSS
8.7 | cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointer_inplace() functio… | PoC 1
- 🟠 CVE-2026-66875 | CVSS
8.7 | In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–… | PoC 1
- 🟠 CVE-2025-41770 | CVSS
8.7 | An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to int…
- 🟠 CVE-2026-73078 | CVSS
8.6 | Vim is an open source, command line text editor. Prior to 9.2.0840, runtime/plugin/netrwPlugin.vim loads netrw and runtime/pack/dist/opt/ne… | PoC 2
- 🟠 CVE-2026-20349 | CVSS
8.6 | A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure… | CISA KEV
- 🟠 CVE-2026-48397 | CVSS
8.6 | Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the con…
- 🟠 CVE-2026-48441 | CVSS
8.6 | Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could…
- 🟠 CVE-2026-73247 | CVSS
8.6 | Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/core/runners/pebble/fu… | PoC 1
- 🟠 CVE-2026-18474 | CVSS
8.6 | The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to…
- 🟠 CVE-2026-73072 | CVSS
8.5 | Vim is an open source, command line text editor. Prior to 9.2.0846, set_sofo() in src/spellfile.c reuses sl_sal_first[] without resetting v… | PoC 3
- 🟠 CVE-2026-73079 | CVSS
8.5 | Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. From 0.1.135, to 0.1.168,… | PoC 4
- 🟠 CVE-2026-20898 | CVSS
8.5 | Improper access control in the firmware for some in Alias Checking Trusted Module for some Intel(R) Xeon(R) processors may allow an escalat…
- 🟠 CVE-2026-43606 | CVSS
8.5 | Observable Timing Discrepancy in the AMD Vitis Libraries ECDSA secp256k1 component could allow attackers with local access to potentially p…
- 🟠 CVE-2026-73233 | CVSS
8.5 | FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the FEM Displacement Constraint task dialog in src/M… | PoC 5
- 🟠 CVE-2026-73248 | CVSS
8.5 | calibre is an e-book manager. Prior to 9.12.0, calibre processes attacker-controlled composite_template metadata from a malicious EPUB, OPF… | PoC 3
- 🟠 CVE-2026-73076 | CVSS
8.4 | Vim is an open source, command line text editor. Prior to 9.2.0847, runtime/autoload/vimball.vim allows a crafted vimball member named .Vim… | PoC 2
- 🟠 CVE-2026-73077 | CVSS
8.4 | Vim is an open source, command line text editor. Prior to 9.2.0839, the runtime/ftplugin/sh.vim, runtime/ftplugin/zsh.vim, and runtime/ftpl… | PoC 2
- 🟠 CVE-2026-20789 | CVSS
8.4 | Improper access control for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow an escalation o…
- 🟠 CVE-2026-34635 | CVSS
8.4 | is affected by a Use of Hard-coded Cryptographic Key vulnerability that could result in a Security feature bypass. A low-privileged attacke…
- 🟠 CVE-2026-70130 | CVSS
8.4 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
- 🟠 CVE-2026-53413 | CVSS
8.3 | Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve r…
- 🟠 CVE-2026-53415 | CVSS
8.3 | Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another partic…
- 🟠 CVE-2026-20727 | CVSS
8.3 | Null pointer dereference for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0: Kernel may allow a denial of service. U…
- 🟠 CVE-2026-20741 | CVSS
8.3 | Improper access control for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow a denial of service. Unpriv…
- 🟠 CVE-2026-20776 | CVSS
8.3 | Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow a denial of service. Netw…
- 🟠 CVE-2026-22887 | CVSS
8.3 | Improper buffer restrictions for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0: Kernel may allow a denial of servic…
- 🟠 CVE-2026-24911 | CVSS
8.3 | Stack-based buffer overflow for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0: Kernel may allow a denial of service…
- 🟠 CVE-2026-56179 | CVSS
8.3 | Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent n…
- 🟠 CVE-2026-73241 | CVSS
8.3 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-side RDSTLS in libfreerdp/core/rdstls.c ac… | PoC 4
- 🟠 CVE-2026-73242 | CVSS
8.3 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos/kerberos.c kerbero… | PoC 4
- 🟠 CVE-2026-29035 | CVSS
8.3 | CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow vulnerability in the read_websocket() function that allows unauthentic… | PoC 1
- 🟠 CVE-2026-66154 | CVSS
8.3 | An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044)…
- 🟠 CVE-2026-19557 | CVSS
8.3 | Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised the renderer proce…
- 🟠 CVE-2026-20715 | CVSS
8.2 | Improper input validation in some firmware for some Intel(R) Active Management Technology (Intel(R) AMT) and some Intel(R) Standard Managea…
- 🟠 CVE-2026-21279 | CVSS
8.2 | is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this v…
- 🟠 CVE-2026-69306 | CVSS
8.2 | Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
- 🟠 CVE-2026-48771 | CVSS
8.2 | ishankportfolio is a portfolio website. Prior to version 1.0.1, contact form submissions could potentially be exposed due to improperly sec… | PoC 1
- 🟠 CVE-2026-73214 | CVSS
8.2 | Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, dtls_server_input_handler() and create_new_connected_… | PoC 5
- 🟠 CVE-2026-73031 | CVSS
8.2 | telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers to execute arbitrary JavaScript in victim… | PoC 4
- 🟠 CVE-2026-48763 | CVSS
8.2 | TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at GET /api/v1/typebots/{typebotId}… | PoC 4`
- 🟠 CVE-2026-18710 | CVSS
8.2 | A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity,…
- 🟠 CVE-2026-67558 | CVSS
8.2 | The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match against the BLE advert… | PoC 1
- 🟠 CVE-2026-6484 | CVSS
8.2 | In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution.
- 🟠 CVE-2026-64954 | CVSS
8.2 | Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLL… | PoC 1
- 🟠 CVE-2026-48440 | CVSS
8.1 | ColdFusion is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the cu…
- 🟠 CVE-2026-62778 | CVSS
8.1 | Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network.
- 🟠 CVE-2026-62781 | CVSS
8.1 | Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network.
- 🟠 CVE-2026-62792 | CVSS
8.1 | Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
- 🟠 CVE-2026-62819 | CVSS
8.1 | Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
- 🟠 CVE-2026-62820 | CVSS
8.1 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker…
- 🟠 CVE-2026-62889 | CVSS
8.1 | Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
- 🟠 CVE-2026-63520 | CVSS
8.1 | Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
- 🟠 CVE-2026-65679 | CVSS
8.1 | Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
- 🟠 CVE-2026-65789 | CVSS
8.1 | Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
- 🟠 CVE-2026-66802 | CVSS
8.1 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Azure Attestation service and Devi…
- 🟠 CVE-2026-70340 | CVSS
8.1 | Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
- 🟠 CVE-2026-71331 | CVSS
8.1 | Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker…
- 🟠 CVE-2026-73223 | CVSS
8.1 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious SF… | PoC 3
- 🟠 CVE-2026-73225 | CVSS
8.1 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FT… | PoC 3
- 🟠 CVE-2026-73227 | CVSS
8.1 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious RD… | PoC 3
- 🟠 CVE-2026-19091 | CVSS
8.1 | The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to arbitrary file dele… | PoC 5
- 🟠 CVE-2026-18961 | CVSS
8.1 | The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authenticati…
- 🟠 CVE-2026-16977 | CVSS
8.1 | The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is substituted into a d…
- 🟠 CVE-2026-18057 | CVSS
8.1 | The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it in a SQL statement, a…
- 🟠 CVE-2026-18230 | CVSS
8.1 | The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement through one…
- 🟠 CVE-2026-19594 | CVSS
8.1 | Insufficient input sanitization in Snowflake Python API (snowflake.core) versions prior to 1.13.0 allowed confused-deputy privilege escal…
- 🟠 CVE-2026-70465 | CVSS
8.1 | A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3,…
- 🟠 CVE-2026-70468 | CVSS
8.1 | A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5,…
- 🟠 CVE-2026-47231 | CVSS
8.1 | Admidio is an open-source user management solution. Prior to version 5.0.10, modules/documents-files.php gates state-changing modes by ch… | PoC 1
- 🟠 CVE-2026-66375 | CVSS
8.1 | A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions.
- 🟠 CVE-2026-73286 | CVSS
8.1 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds attacker-controlled… | PoC 4
- 🟠 CVE-2026-73289 | CVSS
8.1 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS evaluates the ForAllValues: and ForAnyValue: se… | PoC 3
- 🟠 CVE-2026-62911 | CVSS
8.0 | Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Notes
- PoC links are collected from NVD references and GitHub repository search. They are untrusted and may include unsafe code.
- Critical CVE details may span multiple managed comments to guarantee completeness without exceeding GitHub issue size limits.
CVE Daily Brief
Date:
2026-08-12Summary
Critical
All Critical CVE details are preserved across this issue and managed follow-up comments.
High Index
8.9| Protection mechanism failure for some Intel(R) Data Center Attestation Primitives (Intel(R) DCAP) may allow information disclosure. Unprivi…8.8| A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a detailed Statement, Descriptio…8.8| Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized atta…8.8| Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attac…8.8| Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.8.8| Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privilege…8.8| Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a netwo…8.8| Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a n…8.8| Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.8.8| Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.8.8| Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.8.8| Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent…8.8| Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network.8.8| Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network.8.8| Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.8.8| Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.8.8| Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.8.8| Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.8.8| Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network.8.8| Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.8.8| Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.8.8| Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.8.8| Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.8.8| Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a netw…8.8| Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.8.8| Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.8.8| Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.8.8| Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized at…8.8| Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attack…8.8| Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code ove…8.8| Improper input validation in Power BI allows an authorized attacker to execute code over a network.8.8| Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.8.8| Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.8.8| Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.8.8| Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized att…8.8| Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.8.8| Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.8.8| Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.8.8| Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.8.8| Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a netw…8.8| Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.8.8| is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the context of the current user.…8.8| ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the curr…8.8| The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to author…8.8| Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by… | PoC38.8| electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FT… | PoC38.8| electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.186, electerm allows an authenticat… | PoC48.8| The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.9. T…8.8| Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads atPOST /server/php/sub… | PoC2`8.8| Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a cr…8.8| Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a…8.8| POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directly access and operat…8.8| Description Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, including a remote cod… | PoC18.8| RustFS is a distributed object storage system built in Rust. RustFS AddServiceAccount in rustfs/src/admin/handlers/service_account.rs accep… | PoC48.8| Vulnerability-Lookup contains an authentication weakness in its account activation and password-recovery mechanism. Activation and recovery… | PoC18.7| CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure direct object reference (IDOR) that allows… | PoC38.7| is affected by an Improper Input Validation vulnerability that could result in privilege escalation. A low-privileged attacker could exploi…8.7| Activepieces is an open source AI workflow automation platform. Prior to 0.80.0, the worker's code-compilation pipeline builds the on-disk… | PoC28.7| Weaver (Fanwei) E-cology 8.0 contains a SQL injection vulnerability in the SignatureDownLoad servlet that allows unauthenticated remote att…8.7| Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint that allows unauthent…8.7| Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject…8.7| XAgent contains a path traversal vulnerability in the workspace file endpoint that allows self-registered or default-credential users to re… | PoC48.7| An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) process to terminate une…8.7| Flawfinder is a a static analysis tool for finding vulnerabilities in C/C++ source code. Versions prior to 2.0.20 have an improper input ne… | PoC18.7| FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated attackers to achieve…8.7| cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointer_inplace() functio… | PoC18.7| In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–… | PoC18.7| An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to int…8.6| Vim is an open source, command line text editor. Prior to 9.2.0840, runtime/plugin/netrwPlugin.vim loads netrw and runtime/pack/dist/opt/ne… | PoC28.6| A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure… | CISA KEV8.6| Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the con…8.6| Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could…8.6| Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/core/runners/pebble/fu… | PoC18.6| The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to…8.5| Vim is an open source, command line text editor. Prior to 9.2.0846, set_sofo() in src/spellfile.c reuses sl_sal_first[] without resetting v… | PoC38.5| Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. From 0.1.135, to 0.1.168,… | PoC48.5| Improper access control in the firmware for some in Alias Checking Trusted Module for some Intel(R) Xeon(R) processors may allow an escalat…8.5| Observable Timing Discrepancy in the AMD Vitis Libraries ECDSA secp256k1 component could allow attackers with local access to potentially p…8.5| FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the FEM Displacement Constraint task dialog in src/M… | PoC58.5| calibre is an e-book manager. Prior to 9.12.0, calibre processes attacker-controlled composite_template metadata from a malicious EPUB, OPF… | PoC38.4| Vim is an open source, command line text editor. Prior to 9.2.0847, runtime/autoload/vimball.vim allows a crafted vimball member named .Vim… | PoC28.4| Vim is an open source, command line text editor. Prior to 9.2.0839, the runtime/ftplugin/sh.vim, runtime/ftplugin/zsh.vim, and runtime/ftpl… | PoC28.4| Improper access control for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Device Drivers may allow an escalation o…8.4| is affected by a Use of Hard-coded Cryptographic Key vulnerability that could result in a Security feature bypass. A low-privileged attacke…8.4| Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.8.3| Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve r…8.3| Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another partic…8.3| Null pointer dereference for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0: Kernel may allow a denial of service. U…8.3| Improper access control for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow a denial of service. Unpriv…8.3| Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow a denial of service. Netw…8.3| Improper buffer restrictions for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0: Kernel may allow a denial of servic…8.3| Stack-based buffer overflow for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 0: Kernel may allow a denial of service…8.3| Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent n…8.3| FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-side RDSTLS in libfreerdp/core/rdstls.c ac… | PoC48.3| FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos/kerberos.c kerbero… | PoC48.3| CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow vulnerability in the read_websocket() function that allows unauthentic… | PoC18.3| An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044)…8.3| Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised the renderer proce…8.2| Improper input validation in some firmware for some Intel(R) Active Management Technology (Intel(R) AMT) and some Intel(R) Standard Managea…8.2| is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this v…8.2| Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.8.2| ishankportfolio is a portfolio website. Prior to version 1.0.1, contact form submissions could potentially be exposed due to improperly sec… | PoC18.2| Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, dtls_server_input_handler() and create_new_connected_… | PoC58.2| telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers to execute arbitrary JavaScript in victim… | PoC48.2| TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint atGET /api/v1/typebots/{typebotId}… | PoC4`8.2| A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity,…8.2| The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match against the BLE advert… | PoC18.2| In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution.8.2| Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLL… | PoC18.1| ColdFusion is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the cu…8.1| Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network.8.1| Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network.8.1| Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network.8.1| Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine8.1| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker…8.1| Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.8.1| Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.8.1| Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.8.1| Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.8.1| Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Azure Attestation service and Devi…8.1| Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.8.1| Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker…8.1| electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious SF… | PoC38.1| electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FT… | PoC38.1| electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious RD… | PoC38.1| The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to arbitrary file dele… | PoC58.1| The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authenticati…8.1| The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is substituted into a d…8.1| The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it in a SQL statement, a…8.1| The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement through one…8.1| Insufficient input sanitization in Snowflake Python API (snowflake.core) versions prior to 1.13.0 allowed confused-deputy privilege escal…8.1| A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3,…8.1| A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5,…8.1| Admidio is an open-source user management solution. Prior to version 5.0.10,modules/documents-files.phpgates state-changing modes by ch… | PoC18.1| A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions.8.1| RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds attacker-controlled… | PoC48.1| RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS evaluates the ForAllValues: and ForAnyValue: se… | PoC38.0| Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.Notes