Retour aux CVE tendances

Semaine du 24 août 2026

CVE tendances* des 7 derniers jours (du 17 août 2026 au 24 août 2026)

1
CVE-2026-19478Gitlab / Gitlab
Nouveau
Score SYRN96
CVSS9.4
Activité97
Publié17/08/2026
StatutTrès actif

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.

2
CVE-2023-32243Wpdeveloper / Essential Addons For Elementor
Score SYRN97
CVSS9.8
Activité81
Publié12/05/2023
StatutTrès actif

Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This issue affects Essential Addons for Elementor: from 5.4.0 through 5.7.1.

3
CVE-2026-69836Microsoft / Microsoft Entra Id
NouveauKEV
Score SYRN96
CVSS10.0
Activité61
Publié20/08/2026
StatutTrès actif

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

4
CVE-2026-19490Netscaler / Adc
Nouveau
Score SYRN91
CVSS9.3
Activité44
Publié19/08/2026
StatutTrès actif

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

5
CVE-2026-73570Synacor / Zimbra Collaboration Suite
KEV
Score SYRN95
CVSS8.9
Activité44
Publié13/08/2026
StatutTrès actif

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

6
CVE-2026-64849Lfprojects / Mlflow
NouveauKEV
Score SYRN97
CVSS9.3
Activité37
Publié17/08/2026
StatutTrès actif

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated address, allowing attackers to reach internal or cloud metadata services and receive response_status and response_body. This issue is fixed in version 3.15.0.

7
CVE-2023-28121Automattic / Woocommerce
Score SYRN97
CVSS9.8
Activité36
Publié12/04/2023
StatutTrès actif

An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to send requests on behalf of an elevated user, like administrator. This allows a remote, unauthenticated attacker to gain admin access on a site that has the affected version of the plugin activated.

8
CVE-2026-65400Apple / Macos
KEV
Score SYRN95
CVSS7.1
Activité31
Publié06/08/2026
StatutTrès actif

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.

9
CVE-2026-59310Vmware / Cloud Foundation
KEV
Score SYRN97
CVSS9.8
Activité31
Publié30/07/2026
StatutTrès actif

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

10
CVE-2026-33824Microsoft / Microsoft Windows
KEV
Score SYRN97
CVSS9.8
Activité31
Publié14/04/2026
StatutTrès actif

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

* Le classement tendance est basé sur le nombre de signalements collectés par les sources de threat intelligence de SYRN sur la période donnée.

Surveillez ces vulnérabilités et soyez alerté lorsque de nouvelles menaces ciblent votre stack.

Commencer gratuitement