6.5
CVE-2026-26120 - Microsoft Bing Tampering Vulnerability
Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network.
8.6
CVE-2026-23658 - Azure DevOps: msazure Elevation of Privilege Vulnerability
Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
9.8
CVE-2026-32191 - Microsoft Bing Images Remote Code Execution Vulnerability
Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.
8.6
CVE-2026-26138 - Microsoft Purview Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.
8.6
CVE-2026-26139 - Microsoft Purview Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.
10
CVE-2026-32169 - Azure Cloud Shell Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network.
6.8
CVE-2026-32747 - SiYuan: Incomplete sensitive path blocklist in globalCopyFiles allows reading /proc and Docker secrβ¦
SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the globalCopyFiles API eads source files using filepath.Abs() with no workspace boundary check, relying solely on util.IsSensitivePath() whose blocklist omits /proc/, /run/secrets/, and home directory dotfiles. An admiβ¦
1.2
CVE-2026-3230 - Improper key_share validation in TLS 1.3 HelloRetryRequest
Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead to a compromise in the confidentiality of TLS-protected communications via a crafted HelloRetryRequest followed by a ServerHello message that omits the required key_share extension, resβ¦
5.1
CVE-2026-27740 - Discourse has Stored XSS in AI Triage Automation
Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a cross-site scripting vulnerability that arises because the system trusts the raw output from an AI Large Language Model (LLM) and renders it using htmlSafe in the Review Queue interfaβ¦
8.6
CVE-2026-32622 - SQLBot: Remote Code Execution via Terminology Poisoning
SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a Stored Prompt Injection vulnerability that chains three flaws: a missing permission check on the Excel upload API allowing any authenticated user to upload malicious terminology, uβ¦