| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network. |
| Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. |
| Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. |
| Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. |
| Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network. |
| Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network. |
| Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. |
| Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network. |
| Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. |
| Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network. |
| Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. |
| Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network. |
| Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. |
| '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. |
| Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. |
| Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. |
| Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. |
| Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network. |
| Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unauthorized attacker to perform spoofing over a network. |
| Azure Entra ID Elevation of Privilege Vulnerability |