Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 6 August 2026

RSS

869 vulnerabilities published on 6 August 2026

Severity:
Microsoft Planetary Computer Pro: Unauthorized Privilege Elevation
CVE-2026-63508
A critical function in Microsoft Planetary Computer Pro is missing authentication, allowing an attacker with network access to gain elevated privileges without permission. This could lead to unauthori...
10.0
Azure SQL Database Privilege Elevation Over Network
CVE-2026-56162
An attacker can gain elevated access to your Azure SQL Database over a network if authentication is not properly set up. This is a serious risk because it allows unauthorized access to sensitive data....
10.0
Microsoft Teams Missing Authorization Allows Privilege Elevation
CVE-2026-65667
An unauthorized attacker can elevate their privileges on a network using a missing authorization in Microsoft Teams. This means they could potentially gain control over systems and data they shouldn't...
10.0
Traefik: attackers can spoof identity headers
CVE-2026-54763 GHSA-x677-9fxg-v5c5
Traefik, a web server helper, had a security weakness that allowed hackers to fake identity information. This could happen if a hacker reached a protected part of a website. The good news is that this...
7.5
Premium SEO WordPress plugin ships malicious backdoor
CVE-2026-14812
The Premium SEO WordPress plugin contains a hidden backdoor that can create a secret administrator account and allow an attacker to take control of your website without needing a password. This could ...
10.0
MonsterInsights Pro update distribution compromised, malicious files uploaded
CVE-2026-11976
The official update distribution for MonsterInsights Pro has been compromised. This means that if you've updated your website recently, you may have inadvertently installed a malicious file. We recomm...
10.0
Type Hub <= 2.0.6: Unauthenticated File Upload Risk
CVE-2026-66665
If left unpatched, an attacker could upload malicious files to Type Hub without needing a login. This could lead to unauthorized access or damage to your project, so it's essential to update to a secu...
10.0
Spider Analyser WordPress Plugin Remote Code Execution Risk
CVE-2026-65553
A security flaw in the Spider Analyser WordPress plugin allows hackers to execute malicious code on a website without needing a password. This could lead to sensitive data being stolen or modified. Up...
10.0
Unsupported JWT Algorithm Allows Unauthorized Access in [Software Name]
CVE-2026-5430
The JWT authentication in [Software Name] can accept tokens signed with unknown algorithms, allowing attackers to gain unauthorized access to the system. This could lead to the compromise of administr...
10.0
Azure Service Bus Allows Authorized Attackers to Execute Code Remotely
CVE-2026-50515
An attacker with authorized access to Azure Service Bus can potentially execute malicious code on a network. This is a concern because it could allow unauthorized actions. To protect your system, ensu...
9.9
Azure SRE Agent Privilege Elevation Risk
CVE-2026-62830
The Azure SRE Agent has a missing authorization check, which allows an authorized attacker to gain higher privileges on a network. This means an attacker could potentially take control of the system. ...
9.9
Microsoft Entra Provisioning Service Privilege Elevation Risk
CVE-2026-59115
An authorized attacker can use a specific path in Microsoft Entra Provisioning Service to gain more access than they should have over a network. This could potentially allow them to make changes or ac...
9.9
Azure Active Directory Privilege Elevation Risk
CVE-2026-50481
Azure Active Directory has a vulnerability that allows an authorized user to gain more access than they should over a network. This could potentially lead to unauthorized changes or data theft. It's e...
9.9
OpenReception Appointment Booking Software Allows Unauthorized Admin Access
CVE-2026-48086
Prior to version 1.0.2 of OpenReception's appointment booking software, a user with limited admin privileges could accidentally or intentionally gain full control over all other users and tenants on t...
9.9
Flowise through 3.1.4: Insecure Access to Other Workspaces
CVE-2026-67622
An attacker with a Flowise account can access and manipulate files and settings from other workspaces by exploiting a flaw in the integration with OpenAI Assistants. This could lead to unauthorized da...
8.5
Betheme <= 28.4.2: Unauthenticated Remote Code Execution
CVE-2026-65548
Betheme theme for WordPress has a vulnerability that allows attackers to run malicious code on a website. This could lead to unauthorized access, data theft, or even website takeover. Update Betheme t...
9.9
Microsoft 365 Admin Center Privilege Elevation via Signature Verification
CVE-2026-62873
The Microsoft 365 Admin Center has a weakness that could allow an attacker to gain higher levels of access to the system than they should have. This is a concern because an attacker could use this vul...
9.8
ICS-Park Smart Park Management System v2.0 allows arbitrary code execution
CVE-2026-67688
An attacker can upload malicious files to the system, potentially executing unauthorized code. This could compromise the system's security and allow the attacker to take control. To protect your syste...
9.8
macOS Screen Sharing Authentication Bypass
CVE-2026-65400
A security issue in macOS Screen Sharing allowed an attacker on the same network to access the feature without a password. This could potentially let an unauthorized person see or control your Mac's s...
9.8 KEV
OpenReception: Unauthenticated User Account Takeover
CVE-2026-48087 GHSA-j9rw-x2wv-h5rj
A vulnerability in OpenReception's appointment booking software allowed an attacker to take over a user's account without their password. This happened when an attacker submitted a fake registration r...
9.8
OpenReception creates admin accounts without password protection
CVE-2026-48085 GHSA-qvvq-hhpj-64rp
Prior to version 1.0.1, OpenReception's appointment booking software allowed anyone to create administrative accounts without a password. This means that an attacker could gain full control over the p...
9.8
WGDashboard 4.3.2 and earlier: Root Access via Malicious Input
CVE-2026-15734
A security issue in WGDashboard allows an attacker with permission to inject malicious code, giving them full control over the system. This could lead to unauthorized changes, data theft, or complete ...
9.8
WGDashboard 4.2.3 and earlier: Unauthenticated Root Access
CVE-2026-15733
Authenticated users can execute commands with root privileges on vulnerable WGDashboard installations. This allows attackers to access sensitive data and take control of the system. Update to the late...
9.8
WGDashboard versions 4.2.3 and earlier allow unauthorized webhooks
CVE-2026-15732
Authenticated attackers can make unauthorized web requests and access their responses. This could lead to data theft or unauthorized actions. Update to version 4.2.4 or later to fix the issue.
9.8
Dinky allows unauthorized file uploads on default port
CVE-2026-70558 GHSA-2p66-w3p3-5226
A security issue in Dinky's file upload feature allows anyone who can access the default HTTP port (8888) to write arbitrary files as the Dinky service account. This can lead to unauthorized access an...
9.3