8.7
CVE-2025-27578 - Pixmeo OsiriX MD Use After Free
Pixmeo OsiriX MD is vulnerable to a use after free scenario, which could allow an attacker to upload a crafted DICOM file and cause memory corruption leading to a denial-of-service condition.
8.7
CVE-2025-47732 - Microsoft Dataverse Remote Code Execution Vulnerability
Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.
9.1
CVE-2025-47733 - Microsoft Power Apps Information Disclosure Vulnerability
Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network
10
CVE-2025-29813 - Azure DevOps Elevation of Privilege Vulnerability
Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
9.9
CVE-2025-29827 - Azure Automation Elevation of Privilege Vulnerability
Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network.
9.9
CVE-2025-29972 - Azure Storage Resource Provider Spoofing Vulnerability
Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network.
8.1
CVE-2025-33072 - Microsoft msagsfeedback.azurewebsites.net Information Disclosure Vulnerability
Improper access control in Azure allows an unauthorized attacker to disclose information over a network.
7.8
CVE-2025-1331 - IBM CICS TX code execution
IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1ย could allow a local user to execute arbitrary code on the system due to the use of unsafe use of the gets function.
7.8
CVE-2025-1330 - IBM CICS TX code execution
IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1ย could allow a local user to execute arbitrary code on the system due to failure to handle DNS return requests by the gethostbyname function.
7.8
CVE-2025-1329 - IBM CICS TX code execution
IBM CICS TX Standard 11.1 and IBM CICS TX Advanced 10.1 and 11.1 could allow a local user to execute arbitrary code on the system due to failure to handle DNS return requests by the gethostbyaddr function.