Search Results (27489 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-85887 1 Microsoft 1 365 Copilot 2026-09-17 7.7 High
Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network.
CVE-2026-83946 1 Microsoft 1 Azure Portal 2026-09-17 8.2 High
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-69843 1 Microsoft 1 Microsoft Fabric 2026-09-17 10 Critical
Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-85878 1 Microsoft 1 Azure Horizondb 2026-09-17 9.9 Critical
Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.
CVE-2026-62874 1 Microsoft 1 Azure Billing 2026-09-17 10 Critical
Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-85917 1 Microsoft 1 Azure Ai Foundry 2026-09-17 7.5 High
Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-85889 1 Microsoft 1 Azure Ai Foundry 2026-09-17 10 Critical
Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-70200 1 Microsoft 1 Azure Logic Apps 2026-09-17 10 Critical
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-87701 1 Microsoft 1 Cosmos Db 2026-09-17 9.6 Critical
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.
CVE-2026-78501 1 Microsoft 1 365 Copilot Business Chat 2026-09-17 7.4 High
Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network.
CVE-2026-83944 1 Microsoft 1 Azure Logic Apps 2026-09-17 10 Critical
Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-85885 1 Microsoft 1 365 Copilot 2026-09-17 9.9 Critical
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.
CVE-2026-68791 1 Microsoft 1 Azure Machine Learning 2026-09-17 8.6 High
Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network.
CVE-2026-69399 1 Microsoft 1 Azure Arc 2026-09-17 10 Critical
Azure Arc Elevation of Privilege Vulnerability
CVE-2026-77903 1 Microsoft 1 Dataverse 2026-09-17 9 Critical
Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-69865 1 Microsoft 1 Azure Container Registry 2026-09-17 10 Critical
Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-70009 1 Microsoft 1 Azure Arc 2026-09-17 9.3 Critical
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-55946 1 Microsoft 1 Copilot 2026-09-17 6.1 Medium
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2026-79084 2 Google, Microsoft 2 Chrome, Windows 2026-09-17 4.3 Medium
Inadequate encryption strength in Notifications in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-78979 2 Google, Microsoft 2 Chrome, Windows 2026-09-17 4.3 Medium
Race condition in Core in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)