2.1
CVE-2024-47784 - Unverified Password Change
Unverified Password Change for ANC software that allows an authenticated attacker to bypass the old Password check in the password change form via a web HMI This issue affects ANC software version 1.1.4 and earlier.
5.3
CVE-2025-4135 - Netgear WG302v2 ui_get_input_value command injection
A vulnerability was found in Netgear WG302v2 up to 5.2.9 and classified as critical. Affected by this issue is the function ui_get_input_value. The manipulation of the argument host leads to command injection. The attack may be launched remotely. The vendor was contacted early about this disclosureβ¦
5.5
CVE-2025-24091 - App Can Impersonate System Notifications and Cause Denial of Service
An app could impersonate system notifications. Sensitive notifications now require restricted entitlements. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.3. An app may be able to cause a denial-of-service.
4.3
CVE-2025-39413 - WordPress Simple Sitemap β Create a Responsive HTML Sitemap plugin <= 3.6.0 - Broken Access Controlβ¦
Missing Authorization vulnerability in David Gwyer Simple Sitemap β Create a Responsive HTML Sitemap simple-sitemap.This issue affects Simple Sitemap β Create a Responsive HTML Sitemap: from n/a through <= 3.6.0.
8.5
CVE-2025-21416 - Azure Virtual Desktop Elevation of Privilege Vulnerability
Missing authorization in Azure Virtual Desktop allows an authorized attacker to elevate privileges over a network.
9.8
CVE-2025-30392 - Azure AI Bot Elevation of Privilege Vulnerability
Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.
9.9
CVE-2025-30390 - Azure ML Compute Elevation of Privilege Vulnerability
Improper authorization in Azure allows an authorized attacker to elevate privileges over a network.
7.5
CVE-2025-33074 - Azure Functions Remote Code Execution Vulnerability
Improper verification of cryptographic signature in Microsoft Azure Functions allows an authorized attacker to execute code over a network.
8.7
CVE-2025-30389 - Azure Bot Framework SDK Elevation of Privilege Vulnerability
Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.
8.1
CVE-2025-30391 - Microsoft Dynamics Information Disclosure Vulnerability
Improper input validation in Microsoft Dynamics allows an unauthorized attacker to disclose information over a network.