Export limit exceeded: 25579 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (25579 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-56167 | 1 Microsoft | 2 Azure Ai Search, Azure Ai Search | 2026-07-24 | 8.5 High |
| Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-56165 | 1 Microsoft | 2 Account, Microsoft Account | 2026-07-24 | 9.8 Critical |
| Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-58275 | 1 Microsoft | 1 Azure Dns | 2026-07-24 | 10 Critical |
| Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-62825 | 1 Microsoft | 1 Azure Key Vault | 2026-07-24 | 10 Critical |
| Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-56191 | 1 Microsoft | 1 Exchange Online | 2026-07-24 | 10 Critical |
| Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. | ||||
| CVE-2026-50517 | 1 Microsoft | 1 365 Copilot | 2026-07-24 | 9.9 Critical |
| Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network. | ||||
| CVE-2026-49159 | 1 Microsoft | 1 Graph | 2026-07-24 | 6.5 Medium |
| Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. | ||||
| CVE-2026-35425 | 1 Microsoft | 1 Azure Api Management | 2026-07-24 | 8 High |
| Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network. | ||||
| CVE-2026-56160 | 1 Microsoft | 1 Azure Red Hat Openshift | 2026-07-23 | 9.1 Critical |
| Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-54120 | 1 Microsoft | 1 Surface Management Services | 2026-07-23 | 9.9 Critical |
| Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network. | ||||
| CVE-2026-54733 | 1 Microsoft | 1 O365-moodle | 2026-07-23 | N/A |
| The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0.5, and 5.1.1, the Microsoft Office 365 Integration plugin local_o365 Teams SSO endpoint sso_login.php base64-decodes a JWT payload and authenticates users from the upn claim without verifying the JWT signature, allowing an unauthenticated attacker to forge a token and obtain a Moodle session as an O365-authenticated user. This issue is fixed in versions 4.5.6, 5.0.5, and 5.1.1. | ||||
| CVE-2026-57205 | 1 Microsoft | 1 Simplechat | 2026-07-23 | 4.3 Medium |
| SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.203, the authenticated GET /api/user/info/<user_id> and GET /api/user/profile-image/<user_id> endpoints in application/single_app/route_backend_users.py accepted a caller-supplied user_id and read the matching Cosmos DB user-settings document without object-level authorization, allowing a low-privilege authenticated user to retrieve another user's email address, display name, and profile image. This issue is fixed in version 0.241.203. | ||||
| CVE-2026-57206 | 1 Microsoft | 1 Simplechat | 2026-07-23 | 8.6 High |
| SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.206, several plugin validation routes in application/single_app/plugin_validation_endpoint.py, including `POST /api/admin/plugins/test-instantiation`, `GET /api/admin/plugins/health-check/<plugin_name>`, `POST /api/admin/plugins/repair/<plugin_name>`, and `POST /api/plugins/validate`, relied on @swagger_route(security=get_auth_security()) documentation without enforcing @login_required, @user_required, or @admin_required at runtime, allowing unauthenticated or unauthorized clients to invoke plugin validation, health, and repair behavior. This issue is fixed in version 0.241.206. | ||||
| CVE-2026-50522 | 1 Microsoft | 3 Sharepoint Server, Sharepoint Server 2016, Sharepoint Server 2019 | 2026-07-22 | 9.8 Critical |
| Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-62826 | 1 Microsoft | 3 Sharepoint Server, Sharepoint Server 2016, Sharepoint Server 2019 | 2026-07-22 | 4.6 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||||
| CVE-2026-50659 | 2 Microsoft, Redhat | 6 .net, .net Framework, Visual Studio 2022 and 3 more | 2026-07-22 | 6.5 Medium |
| Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network. | ||||
| CVE-2025-69624 | 3 Gonitro, Microsoft, Nitro | 3 Nitro Pdf Pro, Windows, Pdf Pro | 2026-07-22 | 7.5 High |
| Nitro PDF Pro before 14.43 for Windows contains a NULL pointer dereference vulnerability in the JavaScript implementation of app.alert(). When app.alert() is called with more than one argument and the first argument evaluates to null (for example, app.alert(app.activeDocs, true) when app.activeDocs is null), the engine routes the call through a fallback path intended for non-string arguments. In this path, js_ValueToString() is invoked on the null value and returns an invalid string pointer, which is then passed to JS_GetStringChars() without validation. Dereferencing this pointer leads to an access violation and application crash when opening a crafted PDF. For example, 14.41.1.4 and 14.42.0.34 have been reported as vulnerable. | ||||
| CVE-2026-50304 | 1 Microsoft | 10 .net, .net Framework, Windows 10 1607 and 7 more | 2026-07-22 | 7.5 High |
| Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network. | ||||
| CVE-2026-50649 | 2 Microsoft, Redhat | 4 .net, .net Framework, Visual Studio 2026 and 1 more | 2026-07-22 | 7.8 High |
| Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally. | ||||
| CVE-2026-50647 | 1 Microsoft | 15 .net, .net Framework, Windows 10 1607 and 12 more | 2026-07-22 | 7.5 High |
| Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. | ||||