| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Genexus Protection Server 9.7.2.10 contains an unquoted service path vulnerability in the protsrvservice Windows service configuration. Attackers can exploit the unquoted binary path to execute arbitrary code with elevated LocalSystem privileges by placing malicious executables in specific file system locations. |
| Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network. |
| Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. |
| Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. |
| Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. |
| Nitro PDF Pro before 14.43 for Windows contains a NULL pointer dereference vulnerability in the JavaScript implementation of app.alert(). When app.alert() is called with more than one argument and the first argument evaluates to null (for example, app.alert(app.activeDocs, true) when app.activeDocs is null), the engine routes the call through a fallback path intended for non-string arguments. In this path, js_ValueToString() is invoked on the null value and returns an invalid string pointer, which is then passed to JS_GetStringChars() without validation. Dereferencing this pointer leads to an access violation and application crash when opening a crafted PDF. For example, 14.41.1.4 and 14.42.0.34 have been reported as vulnerable. |
| Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network. |
| Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network. |
| Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. |
| Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. |
| Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. |
| Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network. |
| Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. |
| Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network. |
| Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network. |
| Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network. |
| Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network. |
| Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network. |
| Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. |
| Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network. |