Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56334
Total
4455
Critical
16700
High
16518
Medium
CVE ID Severity Score Description Published
CVE-2026-83944 CRITICAL 10.0 Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. Sep 17, 2026
CVE-2026-78501 HIGH 7.4 Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over … Sep 17, 2026
CVE-2026-77903 CRITICAL 9.0 Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network. Sep 17, 2026
CVE-2026-70200 CRITICAL 10.0 Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. Sep 17, 2026
CVE-2026-70009 CRITICAL 9.3 Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network. Sep 17, 2026
CVE-2026-69865 CRITICAL 10.0 Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network. Sep 17, 2026
CVE-2026-69399 CRITICAL 10.0 Azure Arc Elevation of Privilege Vulnerability Sep 17, 2026
CVE-2026-68791 HIGH 8.6 Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network. Sep 17, 2026
CVE-2026-65323 UNKNOWN — Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Sep 17, 2026
CVE-2026-55946 MEDIUM 6.1 Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network. Sep 17, 2026
CVE-2026-93083 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Unwind TX receiver mailbox setup failure mailbox_chan_setup() can request an additional unidirectional TX … Sep 17, 2026
CVE-2026-93082 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Unwind P2A receiver mailbox setup failure mailbox_chan_setup() can request an additional P2A receiver … Sep 17, 2026
CVE-2026-93081 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix SCMI device destroy lifetimes scmi_child_dev_find() drops the reference returned by device_find_child() before … Sep 17, 2026
CVE-2026-93080 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix transport device teardown lookup SCMI transport devices are deliberately excluded from normal … Sep 17, 2026
CVE-2026-93079 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: cxl/features: Reject Get Feature count larger than the output buffer cxlctl_get_feature() sizes its output buffer … Sep 17, 2026
CVE-2026-93078 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: cxl/features: Reject Set Features output buffer smaller than the header cxlctl_set_feature() sizes its output buffer … Sep 17, 2026
CVE-2026-93077 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: cxl/features: Clamp Get Feature output size to the remaining buffer cxl_get_feature() reads a feature in … Sep 17, 2026
CVE-2026-93076 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: dax/fsdev: clear vmemmap_shift when binding static pgmap Clear pgmap->vmemmap_shift for static DAX devices. When rebinding … Sep 17, 2026
CVE-2026-93075 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: dax/fsdev: clear pgmap ops and owner on unbind fsdev_dax_probe() sets pgmap->ops = &fsdev_pagemap_ops and pgmap->owner … Sep 17, 2026
CVE-2026-93074 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: dax/fsdev: use __va(phys) for kaddr in direct_access Use __va(phys) instead of virt_addr + linear_offset for … Sep 17, 2026
CVE-2026-93073 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: dax: read holder_ops once in dax_holder_notify_failure() dax_holder_notify_failure() reads dax_dev->holder_ops twice without READ_ONCE() -- once for … Sep 17, 2026
CVE-2026-93072 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: irqchip/renesas-irqc: Fix generic interrupt chip leak on remove The driver allocates domain generic chips probe. … Sep 17, 2026
CVE-2026-93071 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: media: bcm2835-unicam: Fix asc leaked in error/remove path v4l2_async_nf_add_fwnode_remote() allocates the asc, which is freed … Sep 17, 2026
CVE-2026-93070 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: media: ipu6: Do not free aux device pdata after init ipu6_bus_initialize_device() stores the isys/psys pdata … Sep 17, 2026
CVE-2026-93069 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: OPP: Fix cleanup ordering Commit 173e02d67494 ("OPP: Initialize scope-based pointers inline") added initialization for all … Sep 17, 2026