Search
Search Results (971 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-73299 | 1 Microsoft | 1 Prompty | 2026-08-12 | 10 Critical |
| Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controlled template could traverse constructor and prototype properties to execute JavaScript in the host Node.js process. This issue is fixed in versions 0.1.5 and 2.0.0-beta.5. | ||||
| CVE-2026-50516 | 1 Microsoft | 1 Azure Kubernetes Service | 2026-08-12 | 9.4 Critical |
| Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-13797 | 4 Apple, Google, Linux and 1 more | 4 Macos, Chrome, Linux Kernel and 1 more | 2026-08-12 | 9.6 Critical |
| Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-13781 | 4 Apple, Google, Linux and 1 more | 4 Macos, Chrome, Linux Kernel and 1 more | 2026-08-12 | 9.6 Critical |
| Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | ||||
| CVE-2026-59118 | 1 Microsoft | 3 Copilot Cowork, Power-apps, Power Apps | 2026-08-11 | 9.3 Critical |
| Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2024-21403 | 1 Microsoft | 2 Azure Kubernetes Service, Azure Kubernetes Service Confidential Containers | 2026-08-10 | 9 Critical |
| Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability | ||||
| CVE-2024-21376 | 1 Microsoft | 2 Azure Kubernetes Service, Azure Kubernetes Service Confidential Containers | 2026-08-10 | 9 Critical |
| Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability | ||||
| CVE-2024-21364 | 1 Microsoft | 2 Azure Active Site Recovery, Azure Site Recovery | 2026-08-10 | 9.3 Critical |
| Microsoft Azure Site Recovery Elevation of Privilege Vulnerability | ||||
| CVE-2021-34458 | 1 Microsoft | 4 Windows Server 2004, Windows Server 2016, Windows Server 2019 and 1 more | 2026-08-10 | 9.9 Critical |
| Windows Kernel Remote Code Execution Vulnerability | ||||
| CVE-2023-35385 | 1 Microsoft | 19 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 16 more | 2026-08-10 | 9.8 Critical |
| Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | ||||
| CVE-2023-36911 | 1 Microsoft | 20 Windows 10, Windows 10 1507, Windows 10 1607 and 17 more | 2026-08-10 | 9.8 Critical |
| Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | ||||
| CVE-2023-36910 | 1 Microsoft | 20 Windows 10, Windows 10 1507, Windows 10 1607 and 17 more | 2026-08-10 | 9.8 Critical |
| Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | ||||
| CVE-2021-34473 | 1 Microsoft | 1 Exchange Server | 2026-08-10 | 9.1 Critical |
| Microsoft Exchange Server Remote Code Execution Vulnerability | ||||
| CVE-2021-34523 | 1 Microsoft | 1 Exchange Server | 2026-08-10 | 9 Critical |
| Microsoft Exchange Server Elevation of Privilege Vulnerability | ||||
| CVE-2023-21709 | 1 Microsoft | 2 Exchange Server, Exchange Server 2016 | 2026-08-10 | 9.8 Critical |
| Microsoft Exchange Server Elevation of Privilege Vulnerability | ||||
| CVE-2021-38647 | 1 Microsoft | 11 Azure Automation State Configuration, Azure Automation Update Management, Azure Diagnostics and 8 more | 2026-08-10 | 9.8 Critical |
| Open Management Infrastructure (OMI) Remote Code Execution Vulnerability | ||||
| CVE-2021-26432 | 1 Microsoft | 15 Windows 10, Windows 10 1507, Windows 10 1607 and 12 more | 2026-08-10 | 9.8 Critical |
| Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability | ||||
| CVE-2021-26424 | 1 Microsoft | 19 Windows 10, Windows 10 1507, Windows 10 1607 and 16 more | 2026-08-10 | 9.9 Critical |
| Windows TCP/IP Remote Code Execution Vulnerability | ||||
| CVE-2026-19171 | 2 Google, Microsoft | 2 Chrome, Windows | 2026-08-08 | 9.6 Critical |
| Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | ||||
| CVE-2026-68823 | 1 Microsoft | 1 Azure Confidential Ledger | 2026-08-07 | 9.1 Critical |
| Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network. | ||||