6.5

CVSS3.1

CVE-2026-26120 - Microsoft Bing Tampering Vulnerability

Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network.

πŸ“… Published: March 19, 2026, 9:06 p.m. πŸ”„ Last Modified: April 14, 2026, 4:36 p.m.

8.6

CVSS3.1

CVE-2026-23658 - Azure DevOps: msazure Elevation of Privilege Vulnerability

Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.

πŸ“… Published: March 19, 2026, 9:06 p.m. πŸ”„ Last Modified: April 14, 2026, 4:36 p.m.

9.8

CVSS3.1

CVE-2026-32191 - Microsoft Bing Images Remote Code Execution Vulnerability

Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.

πŸ“… Published: March 19, 2026, 9:06 p.m. πŸ”„ Last Modified: April 15, 2026, 4:45 p.m.

8.6

CVSS3.1

CVE-2026-26138 - Microsoft Purview Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

πŸ“… Published: March 19, 2026, 9:06 p.m. πŸ”„ Last Modified: April 14, 2026, 4:36 p.m.

8.6

CVSS3.1

CVE-2026-26139 - Microsoft Purview Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

πŸ“… Published: March 19, 2026, 9:06 p.m. πŸ”„ Last Modified: April 14, 2026, 4:36 p.m.

10

CVSS3.1

CVE-2026-32169 - Azure Cloud Shell Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network.

πŸ“… Published: March 19, 2026, 9:06 p.m. πŸ”„ Last Modified: April 15, 2026, 4:45 p.m.

6.8

CVSS3.1

CVE-2026-32747 - SiYuan: Incomplete sensitive path blocklist in globalCopyFiles allows reading /proc and Docker secr…

SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the globalCopyFiles API eads source files using filepath.Abs() with no workspace boundary check, relying solely on util.IsSensitivePath() whose blocklist omits /proc/, /run/secrets/, and home directory dotfiles. An admi…

πŸ“… Published: March 19, 2026, 9:02 p.m. πŸ”„ Last Modified: March 25, 2026, 11:54 a.m.

1.2

CVSS4.0

CVE-2026-3230 - Improper key_share validation in TLS 1.3 HelloRetryRequest

Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead to a compromise in the confidentiality of TLS-protected communications via a crafted HelloRetryRequest followed by a ServerHello message that omits the required key_share extension, res…

πŸ“… Published: March 19, 2026, 8:59 p.m. πŸ”„ Last Modified: March 27, 2026, 9:21 a.m.

5.1

CVSS4.0

CVE-2026-27740 - Discourse has Stored XSS in AI Triage Automation

Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a cross-site scripting vulnerability that arises because the system trusts the raw output from an AI Large Language Model (LLM) and renders it using htmlSafe in the Review Queue interfa…

πŸ“… Published: March 19, 2026, 8:56 p.m. πŸ”„ Last Modified: March 25, 2026, 11:54 a.m.

8.6

CVSS4.0

CVE-2026-32622 - SQLBot: Remote Code Execution via Terminology Poisoning

SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a Stored Prompt Injection vulnerability that chains three flaws: a missing permission check on the Excel upload API allowing any authenticated user to upload malicious terminology, u…

πŸ“… Published: March 19, 2026, 8:55 p.m. πŸ”„ Last Modified: March 25, 2026, 11:54 a.m.
Total resulsts: 349182
Page 1043 of 34,919
Β« previous page Β» next page
Filters