Export limit exceeded: 15647 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (27500 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-69851 1 Microsoft 2 Entra Id, Microsoft Entra Id 2026-08-25 9.9 Critical
Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
CVE-2026-69558 1 Microsoft 1 Partner Center 2026-08-25 8.6 High
Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.
CVE-2026-69519 1 Microsoft 1 Azure Stack Hci 2026-08-25 8.6 High
Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.
CVE-2026-65770 1 Microsoft 1 Azure Managed Instance For Apache Cassandra 2026-08-25 10 Critical
Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.
CVE-2026-62316 1 Microsoft 1 Ufo 2026-08-25 8.8 High
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, ufo/client/mcp/http_servers/linux_mcp_server.py binds a FastMCP streamable HTTP server to localhost:8010 but does not validate the Host, Origin, or Sec-Fetch-Site headers. An attacker-controlled web page can use DNS rebinding to reach the local /mcp endpoint, enumerate tool schemas through tools/list, and invoke execute_command with a valid UFO_MCP_API_KEY to read files or execute allowed operating system commands as the victim's user. This issue is fixed in version 3.0.8.
CVE-2025-34290 2 Microsoft, Versa-networks 2 Windows, Sase Client 2026-08-25 7.8 High
Versa SASE Client for Windows versions released between 7.8.7 and 7.9.4 contain a local privilege escalation vulnerability in the audit log export functionality. The client communicates user-controlled file paths to a privileged service, which performs file system operations without impersonating the requesting user. Due to improper privilege handling and a time-of-check time-of-use race condition combined with symbolic link and mount point manipulation, a local authenticated attacker can coerce the service into deleting arbitrary directories with SYSTEM privileges. This can be exploited to delete protected system folders such as C:\\Config.msi and subsequently achieve execution as NT AUTHORITY\\SYSTEM via MSI rollback techniques.
CVE-2021-21009 3 Adobe, Linux, Microsoft 3 Campaign, Linux Kernel, Windows 2026-08-24 8.6 High
Adobe Campaign Classic Gold Standard 10 (and earlier), 20.3.1 (and earlier), 20.2.3 (and earlier), 20.1.3 (and earlier), 19.2.3 (and earlier) and 19.1.7 (and earlier) are affected by a server-side request forgery (SSRF) vulnerability. Successful exploitation could allow an attacker to use the Campaign instance to issue unauthorized requests to internal or external resources.
CVE-2020-9666 3 Adobe, Linux, Microsoft 3 Campaign, Linux Kernel, Windows 2026-08-24 5.5 Medium
Adobe Campaign Classic before 20.2 have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
CVE-2026-65816 1 Microsoft 1 Azure Web Apps 2026-08-24 10 Critical
Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-69400 1 Microsoft 1 Azure Logic Apps 2026-08-24 9.6 Critical
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-68789 1 Microsoft 1 Azure Sql Database 2026-08-24 9.9 Critical
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
CVE-2026-68782 1 Microsoft 1 Azure Sql Database 2026-08-24 9.9 Critical
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
CVE-2026-66309 1 Microsoft 1 Azure Sql Database 2026-08-24 9.1 Critical
Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
CVE-2026-65801 1 Microsoft 1 Exchange Online 2026-08-24 10 Critical
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-66800 1 Microsoft 1 Azure Data Factory 2026-08-24 8.6 High
Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.
CVE-2026-62834 1 Microsoft 1 Azure Data Factory 2026-08-24 9.3 Critical
Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-48567 1 Microsoft 2 .azure Horizondb, Azure Horizondb 2026-08-24 10 Critical
Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-65795 1 Microsoft 21 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 18 more 2026-08-22 6.7 Medium
Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-76037 2 Google, Microsoft 2 Chrome, Windows 2026-08-20 8.4 High
Link following in CredentialProvider in Google Chrome on on Windows prior to 151.0.7922.169 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)
CVE-2026-54117 1 Microsoft 7 Microsoft Sql Server 2025 (cu 2), Microsoft Sql Server 2025 For X64-based Systems (gdr), Sql Server 2016 and 4 more 2026-08-20 9.8 Critical
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.