CVE-2026-32597 PyJWT accepts unknown `crit` header extensions (RFC 7515 Β§4.1.11 MUST violation) Microsoft Security 8 Augustus 2026 om 10:40 Information published.
CVE-2026-48524 PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS) Microsoft Security 8 Augustus 2026 om 10:40 Information published.
CVE-2026-55995 Double-free in the iSNS attribute decoder in open-iscsi Microsoft Security 8 Augustus 2026 om 10:41 Information published.
CVE-2026-44944 iscsiuio control-socket authentication bypass in open-iscsi Microsoft Security 8 Augustus 2026 om 10:41 Information published.
CVE-2026-44943 remote limited file-write as root via discovery in open-iscsi Microsoft Security 8 Augustus 2026 om 10:41 Information published.
CVE-2026-6879 Quadratic Behavior in xml.etree.ElementPath Index Predicates Microsoft Security 8 Augustus 2026 om 10:41 Information published.
CVE-2025-62725 Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer Annotations Microsoft Security 8 Augustus 2026 om 10:40 Information published.
CVE-2026-44508 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43618. Reason: This candidate is a duplicate of CVE-2026-43618. Notes: All CVE users should reference CVE-2026-43618 instead of this candidate. Microsoft Security 8 Augustus 2026 om 10:40 Information published.
CVE-2026-44510 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43620. Reason: This candidate is a duplicate of CVE-2026-43620. Notes: All CVE users should reference CVE-2026-43620 instead of this candidate. Microsoft Security 8 Augustus 2026 om 10:40 Information published.
CVE-2026-44509 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43619. Reason: This candidate is a duplicate of CVE-2026-43619. Notes: All CVE users should reference CVE-2026-43619 instead of this candidate. Microsoft Security 8 Augustus 2026 om 10:40 Information published.
CVE-2026-12080 Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keys Microsoft Security 8 Augustus 2026 om 10:40 Information published.
CVE-2026-68480 x86/bugs: Make Safe-RET robust against interrupt injection Microsoft Security 8 Augustus 2026 om 10:01 Information published.
CVE-2019-9192 In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion Microsoft Security 7 Augustus 2026 om 10:07 Information published.
CVE-2019-9924 rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell. Microsoft Security 7 Augustus 2026 om 10:06 Information published.
CVE-2010-4052 Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (resource exhaustion) via a regular expression containing adjacent repetition operators, as demonstrated by a {10,}{10,}{10,}{10,} sequence in the proftpd.gnu.c exploit for ProFTPD. Microsoft Security 7 Augustus 2026 om 10:05 Information published.
CVE-2019-6706 Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships. Microsoft Security 7 Augustus 2026 om 10:03 Information published.
CVE-2018-6829 cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for Libgcrypt's ElGamal implementation. Microsoft Security 7 Augustus 2026 om 09:59 Information published.
CVE-2018-1128 It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is able to sniff packets on network can use this vulnerability to authenticate with ceph service and perform actions allowed by ceph service. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable. Microsoft Security 7 Augustus 2026 om 09:42 Information published.
CVE-2018-5407 Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'. Microsoft Security 7 Augustus 2026 om 09:24 Information published.
CVE-2016-2568 pkexec, when used with --user nonpriv, allows local users to escape to the parent session Microsoft Security 7 Augustus 2026 om 09:20 Information published.
CVE-2007-3205 The parse_str function in (1) PHP, (2) Hardened-PHP, and (3) Suhosin, when called without a second parameter, might allow remote attackers to overwrite arbitrary variables by specifying variable names and values in the string to be parsed. NOTE: it is not clear whether this is a design limitation of the function or a bug in PHP, although it is likely to be regarded as a bug in Hardened-PHP and Suhosin. Microsoft Security 7 Augustus 2026 om 09:19 Information published.