Export limit exceeded: 25587 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (25587 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-57989 1 Microsoft 1 Edge Chromium 2026-07-27 7.4 High
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
CVE-2026-57990 1 Microsoft 1 Edge Chromium 2026-07-27 7.4 High
Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
CVE-2025-69624 3 Gonitro, Microsoft, Nitro 3 Nitro Pdf Pro, Windows, Pdf Pro 2026-07-27 7.5 High
Nitro PDF Pro before 14.43 for Windows contains a NULL pointer dereference vulnerability in the JavaScript implementation of app.alert(). When app.alert() is called with more than one argument and the first argument evaluates to null (for example, app.alert(app.activeDocs, true) when app.activeDocs is null), the engine routes the call through a fallback path intended for non-string arguments. In this path, js_ValueToString() is invoked on the null value and returns an invalid string pointer, which is then passed to JS_GetStringChars() without validation. Dereferencing this pointer leads to an access violation and application crash when opening a crafted PDF. For example, 14.41.1.4 and 14.42.0.34 have been reported as vulnerable.
CVE-2026-48561 1 Microsoft 3 365 Copilot Android, 365 Copilot Ios, Edge Copilot 2026-07-26 9.6 Critical
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network.
CVE-2026-62835 1 Microsoft 1 Azure Portal 2026-07-25 9.3 Critical
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
CVE-2026-56191 1 Microsoft 1 Exchange Online 2026-07-24 10 Critical
Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.
CVE-2026-49159 1 Microsoft 1 Graph 2026-07-24 6.5 Medium
Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.
CVE-2026-58630 1 Microsoft 1 Azure App Service 2026-07-24 10 Critical
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-58275 1 Microsoft 1 Azure Dns 2026-07-24 10 Critical
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-62825 1 Microsoft 1 Azure Key Vault 2026-07-24 10 Critical
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-57106 1 Microsoft 1 Office Purview Data Governance 2026-07-24 10 Critical
Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-50517 1 Microsoft 1 365 Copilot 2026-07-24 9.9 Critical
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
CVE-2026-56160 1 Microsoft 1 Azure Red Hat Openshift 2026-07-24 9.1 Critical
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.
CVE-2026-54120 1 Microsoft 1 Surface Management Services 2026-07-24 9.9 Critical
Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
CVE-2026-56165 1 Microsoft 2 Account, Microsoft Account 2026-07-24 9.8 Critical
Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
CVE-2026-56163 1 Microsoft 1 Azure Kubernetes Service 2026-07-24 10 Critical
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-54733 1 Microsoft 1 O365-moodle 2026-07-23 N/A
The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0.5, and 5.1.1, the Microsoft Office 365 Integration plugin local_o365 Teams SSO endpoint sso_login.php base64-decodes a JWT payload and authenticates users from the upn claim without verifying the JWT signature, allowing an unauthenticated attacker to forge a token and obtain a Moodle session as an O365-authenticated user. This issue is fixed in versions 4.5.6, 5.0.5, and 5.1.1.
CVE-2026-57205 1 Microsoft 1 Simplechat 2026-07-23 4.3 Medium
SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.203, the authenticated GET /api/user/info/<user_id> and GET /api/user/profile-image/<user_id> endpoints in application/single_app/route_backend_users.py accepted a caller-supplied user_id and read the matching Cosmos DB user-settings document without object-level authorization, allowing a low-privilege authenticated user to retrieve another user's email address, display name, and profile image. This issue is fixed in version 0.241.203.
CVE-2026-57206 1 Microsoft 1 Simplechat 2026-07-23 8.6 High
SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.206, several plugin validation routes in application/single_app/plugin_validation_endpoint.py, including `POST /api/admin/plugins/test-instantiation`, `GET /api/admin/plugins/health-check/<plugin_name>`, `POST /api/admin/plugins/repair/<plugin_name>`, and `POST /api/plugins/validate`, relied on @swagger_route(security=get_auth_security()) documentation without enforcing @login_required, @user_required, or @admin_required at runtime, allowing unauthenticated or unauthorized clients to invoke plugin validation, health, and repair behavior. This issue is fixed in version 0.241.206.
CVE-2026-50522 1 Microsoft 3 Sharepoint Server, Sharepoint Server 2016, Sharepoint Server 2019 2026-07-22 9.8 Critical
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.