6.5

CVSS3.1

CVE-2026-26136 - Microsoft Copilot Information Disclosure Vulnerability

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.

๐Ÿ“… Published: March 19, 2026, 9:06 p.m. ๐Ÿ”„ Last Modified: March 21, 2026, 4:01 a.m.

5.3

CVSS3.1

CVE-2026-24299 - M365 Copilot Information Disclosure Vulnerability

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

๐Ÿ“… Published: March 19, 2026, 9:06 p.m. ๐Ÿ”„ Last Modified: March 21, 2026, 4:01 a.m.

8.6

CVSS3.1

CVE-2026-23659 - Azure Data Factory Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disclose information over a network.

๐Ÿ“… Published: March 19, 2026, 9:06 p.m. ๐Ÿ”„ Last Modified: March 20, 2026, 3:23 p.m.

6.5

CVSS3.1

CVE-2026-26120 - Microsoft Bing Tampering Vulnerability

Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network.

๐Ÿ“… Published: March 19, 2026, 9:06 p.m. ๐Ÿ”„ Last Modified: March 21, 2026, 3:28 a.m.

8.6

CVSS3.1

CVE-2026-23658 - Azure DevOps: msazure Elevation of Privilege Vulnerability

Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.

๐Ÿ“… Published: March 19, 2026, 9:06 p.m. ๐Ÿ”„ Last Modified: March 21, 2026, 4:01 a.m.

9.8

CVSS3.1

CVE-2026-32191 - Microsoft Bing Images Remote Code Execution Vulnerability

Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.

๐Ÿ“… Published: March 19, 2026, 9:06 p.m. ๐Ÿ”„ Last Modified: March 21, 2026, 4:01 a.m.

8.6

CVSS3.1

CVE-2026-26138 - Microsoft Purview Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

๐Ÿ“… Published: March 19, 2026, 9:06 p.m. ๐Ÿ”„ Last Modified: March 21, 2026, 4:01 a.m.

8.6

CVSS3.1

CVE-2026-26139 - Microsoft Purview Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

๐Ÿ“… Published: March 19, 2026, 9:06 p.m. ๐Ÿ”„ Last Modified: March 21, 2026, 4:01 a.m.

10

CVSS3.1

CVE-2026-32169 - Azure Cloud Shell Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network.

๐Ÿ“… Published: March 19, 2026, 9:06 p.m. ๐Ÿ”„ Last Modified: March 21, 2026, 4:01 a.m.

6.8

CVSS3.1

CVE-2026-32747 - SiYuan: Incomplete sensitive path blocklist in globalCopyFiles allows reading /proc and Docker secrโ€ฆ

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the globalCopyFiles API eads source files using filepath.Abs() with no workspace boundary check, relying solely on util.IsSensitivePath() whose blocklist omits /proc/, /run/secrets/, and home directory dotfiles. An admiโ€ฆ

๐Ÿ“… Published: March 19, 2026, 9:02 p.m. ๐Ÿ”„ Last Modified: March 20, 2026, 5:08 p.m.
Total resulsts: 339296
Page 58 of 33,930
ยซ previous page ยป next page
Filters