Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …
Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a securit…
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.
Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.
Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information l…
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a netwo…
Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to ex…
Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.
Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate p…
Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.
Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose…
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…
Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network.
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network.
Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.
Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileg…
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.
Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elev…
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over…