8.2
CVE-2025-64677 - Office Out-of-Box Experience Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Office Out-of-Box Experience allows an unauthorized attacker to perform spoofing over a network.
7.2
CVE-2025-64676 - Microsoft Purview eDiscovery Remote Code Execution Vulnerability
'.../...//' in Microsoft Purview allows an authorized attacker to execute code over a network.
10
CVE-2025-65037 - Azure Container Apps Remote Code Execution Vulnerability
Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network.
10
CVE-2025-65041 - Microsoft Partner Center Elevation of Privilege Vulnerability
Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.
9.9
CVE-2025-64663 - Custom Question Answering Elevation of Privilege Vulnerability
Custom Question Answering Elevation of Privilege Vulnerability
3.1
CVE-2025-65046 - Microsoft Edge (Chromium-based) Spoofing Vulnerability
Microsoft Edge (Chromium-based) Spoofing Vulnerability
6.5
CVE-2025-68383 - Filebeat Improper Validation of Specified Index, Position, or Offset in Input
Improper Validation of Specified Index, Position, or Offset in Input (CWE-1285) in Filebeat Syslog parser and the Libbeat Dissect processor can allow a user to trigger a Buffer Overflow (CAPEC-100) and cause a denial of service (panic/crash) of the Filebeat process via either a malformed Syslog mesβ¦
6.9
CVE-2025-13427 - Authentication Bypass in Dialogflow CX Messenger
An authentication bypass vulnerability in Google Cloud Dialogflow CX Messenger allowed unauthenticated users to interact with restricted chat agents, gaining access to the agents' knowledge and the ability to trigger their intents, by manipulating initialization parameters or crafting specific API β¦
6.5
CVE-2025-68382 - Packetbeat Out-of-bounds Read
Out-of-bounds read (CWE-125) allows an unauthenticated remote attacker to perform a buffer overflow (CAPEC-100) via the NFS protocol dissector, leading to a denial-of-service (DoS) through a reliable process crash when handling truncated XDR-encoded RPC messages.
6.5
CVE-2025-68381 - Packetbeat Improper Bounds Check
Improper Bounds Check (CWE-787) in Packetbeat can allow a remote unauthenticated attacker to exploit a Buffer Overflow (CAPEC-100) and reliably crash the application or cause significant resource exhaustion via a single crafted UDP packet with an invalid fragment sequence number.