Critical · CVSS 9.8 · CISA KEV
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.
Published Apr 11, 2018 · Updated Aug 26, 2026
High · CVSS 7 · CISA KEV
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Published Aug 11, 2026 · Updated Aug 25, 2026
Critical · CVSS 10 · CISA KEV
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
Published Jun 30, 2026 · Updated Aug 25, 2026
Critical · CVSS 10 · CISA KEV
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data. Note: Affected version for Weblogic Server Proxy Plug-in for IIS is 12.2.1.4.0 only. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).
Published Jan 20, 2026 · Updated Aug 25, 2026
Critical · CVSS 9.1 · CISA KEV
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
Published Jul 14, 2026 · Updated Aug 24, 2026
Critical · CVSS 9.8 · CISA KEV
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Published Jul 14, 2026 · Updated Aug 24, 2026
Critical · CVSS 9.8 · CISA KEV
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Published Jul 14, 2026 · Updated Aug 24, 2026
Medium · CVSS 5.3 · CISA KEV
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
Published Jul 14, 2026 · Updated Aug 24, 2026
High · CVSS 7.8 · CISA KEV
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
Published Jul 14, 2026 · Updated Aug 24, 2026
High · CVSS 8.9 · CISA KEV
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
Published Aug 13, 2026 · Updated Aug 24, 2026
High · CVSS 7.8 · CISA KEV
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Published Dec 15, 2021 · Updated Aug 22, 2026
High · CVSS 7.8 · CISA KEV
In the Linux kernel, the following vulnerability has been resolved:
crypto: algif_aead - Revert to operating out-of-place
This mostly reverts commit 72548b093ee3 except for the copying of
the associated data.
There is no benefit in operating in-place in algif_aead since the
source and destination come from different mappings. Get rid of
all the complexity added for in-place operation and just copy the
AD directly.
Published Apr 22, 2026 · Updated Aug 21, 2026
Critical · CVSS 9.3 · CISA KEV
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated address, allowing attackers to reach internal or cloud metadata services and receive response_status and response_body. This issue is fixed in version 3.15.0.
Published Aug 17, 2026 · Updated Aug 20, 2026
Medium · CVSS 5.3 · CISA KEV
It was discovered that a nft object or expression could reference a nft set on a different nft table, leading to a use-after-free once that table was deleted.
Published Jan 8, 2024 · Updated Aug 20, 2026
High · CVSS 7.8 · CISA KEV
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system.
The update addresses this vulnerability by correcting how the Windows kernel-mode driver handles objects in memory.
Published May 21, 2020 · Updated Aug 19, 2026
High · CVSS 8.8 · CISA KEV
Internet Explorer Remote Code Execution Vulnerability
Published Mar 11, 2021 · Updated Aug 19, 2026
High · CVSS 8.8 · CISA KEV
Internet Explorer Memory Corruption Vulnerability
Published Mar 11, 2021 · Updated Aug 19, 2026
High · CVSS 7.8 · CISA KEV
Microsoft Exchange Server Remote Code Execution Vulnerability
Published Mar 2, 2021 · Updated Aug 19, 2026
High · CVSS 7.6 · CISA KEV
Microsoft Office Remote Code Execution Vulnerability
Published Mar 11, 2021 · Updated Aug 19, 2026
High · CVSS 7.8 · CISA KEV
Microsoft Exchange Server Remote Code Execution Vulnerability
Published Mar 2, 2021 · Updated Aug 19, 2026
High · CVSS 7.8 · CISA KEV
Microsoft Exchange Server Remote Code Execution Vulnerability
Published Mar 2, 2021 · Updated Aug 19, 2026
Critical · CVSS 9.1 · CISA KEV
Microsoft Exchange Server Remote Code Execution Vulnerability
Published Mar 2, 2021 · Updated Aug 19, 2026
High · CVSS 7.5 · CISA KEV
Active Directory Domain Services Elevation of Privilege Vulnerability
Published Nov 10, 2021 · Updated Aug 19, 2026
High · CVSS 7.8 · CISA KEV
Microsoft Excel Security Feature Bypass Vulnerability
Published Nov 10, 2021 · Updated Aug 19, 2026
High · CVSS 7.5 · CISA KEV
Active Directory Domain Services Elevation of Privilege Vulnerability
Published Nov 10, 2021 · Updated Aug 19, 2026
High · CVSS 7.8 · CISA KEV
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Published Feb 14, 2023 · Updated Aug 19, 2026
High · CVSS 7.3 · CISA KEV
Microsoft Publisher Security Feature Bypass Vulnerability
Published Feb 14, 2023 · Updated Aug 19, 2026
High · CVSS 7.8 · CISA KEV
Microsoft Management Console Remote Code Execution Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
High · CVSS 8.8 · CISA KEV
Microsoft Exchange Server Remote Code Execution Vulnerability
Published Nov 10, 2021 · Updated Aug 19, 2026
High · CVSS 7.8 · CISA KEV
Windows Graphics Component Remote Code Execution Vulnerability
Published Feb 14, 2023 · Updated Aug 19, 2026
Medium · CVSS 5.5 · CISA KEV
Windows Installer Elevation of Privilege Vulnerability
Published Nov 10, 2021 · Updated Aug 19, 2026
Critical · CVSS 9.8 · CISA KEV
Microsoft Configuration Manager Remote Code Execution Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
High · CVSS 8.8 · CISA KEV
Microsoft Exchange Server Remote Code Execution Vulnerability
Published Feb 14, 2023 · Updated Aug 19, 2026
Medium · CVSS 6.5 · CISA KEV
Windows MSHTML Platform Spoofing Vulnerability
Published Oct 8, 2024 · Updated Aug 19, 2026
Medium · CVSS 6.2 · CISA KEV
Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.
Published Feb 10, 2026 · Updated Aug 19, 2026
High · CVSS 7.8 · CISA KEV
Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.
Published Feb 10, 2026 · Updated Aug 19, 2026
High · CVSS 8.8 · CISA KEV
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
Published Feb 10, 2026 · Updated Aug 19, 2026
High · CVSS 8.8 · CISA KEV
Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.
Published Feb 10, 2026 · Updated Aug 19, 2026
High · CVSS 7.8 · CISA KEV
Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
Published Feb 10, 2026 · Updated Aug 19, 2026
High · CVSS 7.8 · CISA KEV
Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
Published Feb 10, 2026 · Updated Aug 19, 2026
Critical · CVSS 9.8 · CISA KEV
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.
Published Aug 6, 2026 · Updated Aug 19, 2026
Critical · CVSS 9.8 · CISA KEV
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
Published Jul 30, 2026 · Updated Aug 19, 2026
Critical · CVSS 9.8 · CISA KEV
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
Published Apr 14, 2026 · Updated Aug 19, 2026
Critical · CVSS 9.4 · CISA KEV
Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard against browser-based attacks, as the current defense uses the User-Agent header starting with the string "Mozilla" as a defense mechanism. This defense is insufficient as the fetch specification allows the User-Agent header to be modified. Combined with a DNS rebinding attack against the browser, and this vulnerability is exploitable against a developer running Ray who inadvertently visits a malicious website, or is served a malicious advertisement (malvertising). This issue has been patched in version 2.52.0.
Published Nov 26, 2025 · Updated Aug 18, 2026
Critical · CVSS 9.8 · CISA KEV
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments
Published Jul 17, 2026 · Updated Aug 17, 2026
High · CVSS 8.8 · CISA KEV
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ.
Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including
BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String).
An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport's brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext.
Because Spring's ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker's JVM through bean factory methods such as Runtime.exec().
This issue affects Apache ActiveMQ Broker: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ All: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ: before 5.19.4, from 6.0.0 before 6.2.3.
Users are recommended to upgrade to version 5.19.4 or 6.2.3, which fixes the issue
Published Apr 7, 2026 · Updated Aug 17, 2026
Critical · CVSS 10 · CISA KEV
An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.
Published Jan 12, 2024 · Updated Aug 15, 2026
Critical · CVSS 9.8 · CISA KEV
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.
Published Feb 11, 2020 · Updated Aug 15, 2026
High · CVSS 7.8 · CISA KEV
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
Published Jan 28, 2022 · Updated Aug 15, 2026
High · CVSS 7 · CISA KEV
Win32k Elevation of Privilege Vulnerability
Published Jan 11, 2022 · Updated Aug 15, 2026