Search Results (9506 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-0281 2 Palo Alto Networks, Paloaltonetworks 4 Cloud Ngfw, Pan-os, Prisma Access and 1 more 2026-08-11 7.1 High
An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to obtain web session tokens. This requires a legitimate user to first click on a malicious link provided by the attacker. The security risk posed by this issue is minimized by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practice deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma® Access are not impacted by this vulnerability.
CVE-2026-46358 1 Openbao 1 Openbao 2026-08-11 4.4 Medium
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's inline auth functionality incorrectly redacted audit log entries, resulting in non-auth headers being removed and auth-related headers being retained in cleartext. This requires an attacker to compromise access to the audit device. Operators should review leaked source authentication material and rotate it as appropriate. This is fixed in OpenBao v2.5.4.
CVE-2026-19363 1 Lmammino 1 Oidc-authorizer 2026-08-11 5.3 Medium
A vulnerability was found in lmammino oidc-authorizer up to 0.4.0. Impacted is an unknown function of the file src/handler.rs of the component Lambda Authorizer. The manipulation results in sensitive information in log files. The attack can be executed remotely. `src/handler.rs` logs raw Authorization header values and complete bearer tokens/JWTs on authentication failure paths, potentially exposing credentials through CloudWatch Logs. `src/models.rs` serializes the complete validated JWT claims set with `serde_json::to_string(token_claims).unwrap()` and propagates it through `context["jwtClaims"]` to downstream integrations. This code performs serialization, not deserialization, and does not process attacker-controlled `jwtClaims` input. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-11940 1 Python 1 Cpython 2026-08-11 N/A
tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself.  The extraction fallback validated the symlink at it's archived location but recreated it at the hardlink's shallower path, letting a relative target the filter judged contained escape the destination directory.  This allowed a malicious tar archive to create a symlink pointing outside the destination, enabling out-of-destination file reads or writes. This was an incomplete fix of CVE-2025-4330.
CVE-2026-71577 1 Redhat 1 Multicluster Globalhub 2026-08-10 6.3 Medium
A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed hubs read access to a shared communication topic. This allows a compromised managed hub to intercept and collect sensitive bootstrap kubeconfigs, which contain API server tokens intended for other hubs. These tokens have an extended validity of approximately 9.86 years, significantly increasing the risk of unauthorized access and information disclosure to other managed clusters.
CVE-2026-18464 2 Wordpress, Wp Maps Pro 2 Wordpress, Wp Maps Pro 2026-08-10 7.5 High
The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not restrict the operation it dispatches, allowing unauthenticated attackers to trigger uncontrolled recursion that exhausts server resources, resulting in a Denial of Service.
CVE-2026-15970 1 Hashicorp 2 Consul, Consul Enterprise 2026-08-10 4.2 Medium
Consul Community Edition and Consul Enterprise 1.20.1 through 2.0.2 are vulnerable to an L7 intention authorization bypass when a service proxy is configured with a custom public listener. An authenticated mesh workload may reach HTTP paths that are blocked by a path-based deny intention. This vulnerability, CVE-2026-15970, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3.
CVE-2024-21405 1 Microsoft 23 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 20 more 2026-08-10 7 High
Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability
CVE-2024-21403 1 Microsoft 2 Azure Kubernetes Service, Azure Kubernetes Service Confidential Containers 2026-08-10 9 Critical
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
CVE-2024-21397 1 Microsoft 1 Azure File Sync 2026-08-10 5.3 Medium
Microsoft Azure File Sync Elevation of Privilege Vulnerability
CVE-2024-21355 1 Microsoft 22 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 19 more 2026-08-10 7 High
Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability
CVE-2023-38181 1 Microsoft 2 Exchange Server, Exchange Server 2016 2026-08-10 8.8 High
Microsoft Exchange Server Spoofing Vulnerability
CVE-2023-38182 1 Microsoft 2 Exchange Server, Exchange Server 2016 2026-08-10 8 High
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-35388 1 Microsoft 2 Exchange Server, Exchange Server 2016 2026-08-10 8 High
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-36928 1 Microsoft 1 Edge Chromium 2026-08-10 6 Medium
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2023-36876 1 Microsoft 2 Windows Server 2008, Windows Server 2008 R2 2026-08-10 7.1 High
Reliability Analysis Metrics Calculation (RacTask) Elevation of Privilege Vulnerability
CVE-2021-34520 1 Microsoft 5 Sharepoint Foundation, Sharepoint Foundation 2013, Sharepoint Server and 2 more 2026-08-10 8.1 High
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2021-34532 2 Microsoft, Redhat 4 Asp.net Core, Visual Studio 2019, Enterprise Linux and 1 more 2026-08-10 5.5 Medium
ASP.NET Core and Visual Studio Information Disclosure Vulnerability
CVE-2021-26426 1 Microsoft 16 Windows 10, Windows 10 1507, Windows 10 1607 and 13 more 2026-08-10 7 High
Windows User Account Profile Picture Elevation of Privilege Vulnerability
CVE-2021-26425 1 Microsoft 19 Windows 10, Windows 10 1507, Windows 10 1607 and 16 more 2026-08-10 7.8 High
Windows Event Tracing Elevation of Privilege Vulnerability