Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56334
Total
4455
Critical
16700
High
16518
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-83944 | CRITICAL | 10.0 | Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. | Sep 17, 2026 |
| CVE-2026-78501 | HIGH | 7.4 | Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over … | Sep 17, 2026 |
| CVE-2026-77903 | CRITICAL | 9.0 | Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network. | Sep 17, 2026 |
| CVE-2026-70200 | CRITICAL | 10.0 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. | Sep 17, 2026 |
| CVE-2026-70009 | CRITICAL | 9.3 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | Sep 17, 2026 |
| CVE-2026-69865 | CRITICAL | 10.0 | Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network. | Sep 17, 2026 |
| CVE-2026-69399 | CRITICAL | 10.0 | Azure Arc Elevation of Privilege Vulnerability | Sep 17, 2026 |
| CVE-2026-68791 | HIGH | 8.6 | Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network. | Sep 17, 2026 |
| CVE-2026-65323 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Sep 17, 2026 |
| CVE-2026-55946 | MEDIUM | 6.1 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network. | Sep 17, 2026 |
| CVE-2026-93083 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Unwind TX receiver mailbox setup failure mailbox_chan_setup() can request an additional unidirectional TX … | Sep 17, 2026 |
| CVE-2026-93082 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Unwind P2A receiver mailbox setup failure mailbox_chan_setup() can request an additional P2A receiver … | Sep 17, 2026 |
| CVE-2026-93081 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix SCMI device destroy lifetimes scmi_child_dev_find() drops the reference returned by device_find_child() before … | Sep 17, 2026 |
| CVE-2026-93080 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix transport device teardown lookup SCMI transport devices are deliberately excluded from normal … | Sep 17, 2026 |
| CVE-2026-93079 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: cxl/features: Reject Get Feature count larger than the output buffer cxlctl_get_feature() sizes its output buffer … | Sep 17, 2026 |
| CVE-2026-93078 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: cxl/features: Reject Set Features output buffer smaller than the header cxlctl_set_feature() sizes its output buffer … | Sep 17, 2026 |
| CVE-2026-93077 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: cxl/features: Clamp Get Feature output size to the remaining buffer cxl_get_feature() reads a feature in … | Sep 17, 2026 |
| CVE-2026-93076 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: dax/fsdev: clear vmemmap_shift when binding static pgmap Clear pgmap->vmemmap_shift for static DAX devices. When rebinding … | Sep 17, 2026 |
| CVE-2026-93075 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: dax/fsdev: clear pgmap ops and owner on unbind fsdev_dax_probe() sets pgmap->ops = &fsdev_pagemap_ops and pgmap->owner … | Sep 17, 2026 |
| CVE-2026-93074 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: dax/fsdev: use __va(phys) for kaddr in direct_access Use __va(phys) instead of virt_addr + linear_offset for … | Sep 17, 2026 |
| CVE-2026-93073 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: dax: read holder_ops once in dax_holder_notify_failure() dax_holder_notify_failure() reads dax_dev->holder_ops twice without READ_ONCE() -- once for … | Sep 17, 2026 |
| CVE-2026-93072 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: irqchip/renesas-irqc: Fix generic interrupt chip leak on remove The driver allocates domain generic chips probe. … | Sep 17, 2026 |
| CVE-2026-93071 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: media: bcm2835-unicam: Fix asc leaked in error/remove path v4l2_async_nf_add_fwnode_remote() allocates the asc, which is freed … | Sep 17, 2026 |
| CVE-2026-93070 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: media: ipu6: Do not free aux device pdata after init ipu6_bus_initialize_device() stores the isys/psys pdata … | Sep 17, 2026 |
| CVE-2026-93069 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: OPP: Fix cleanup ordering Commit 173e02d67494 ("OPP: Initialize scope-based pointers inline") added initialization for all … | Sep 17, 2026 |