Microsoft Azure Key Vault
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
The CVSS severity warrants an early asset and exposure review.Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.
NVD data is used under its public data terms. This service is not endorsed or certified by NVD.Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
The CVSS severity warrants an early asset and exposure review.Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
The CVSS severity warrants an early asset and exposure review.Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.
The CVSS severity warrants an early asset and exposure review.Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.
The CVSS severity warrants an early asset and exposure review.Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
The CVSS severity warrants an early asset and exposure review.Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.
The CVSS severity warrants an early asset and exposure review.Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
The CVSS severity warrants an early asset and exposure review.Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
The CVSS severity warrants an early asset and exposure review.Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.
The CVSS severity warrants an early asset and exposure review.Pronetiqs IntraVUE versions 3.2.1a14 and prior have an inadequate encryption strength vulnerability which could allow an attacker to steal admin credentials via weak hash or a pass-the-hash attack.
The CVSS severity warrants an early asset and exposure review.Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active proxy, which would bypass OT segmentation.
The CVSS severity warrants an early asset and exposure review.Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cleartext credentials through the API.
The CVSS severity warrants an early asset and exposure review.Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could expose the underlying host/share filesystem.
The CVSS severity warrants an early asset and exposure review.Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows unauthenticated remote attackers to read arbitrary files by supplying directory traversal sequences in the path query parameter. Attackers can send a single unauthenticated HTTP GET request exploiting the failure of normalize_path() to strip traversal sequences, disclosing sensitive files such as environment configuration files containing credentials and system files.
The CVSS severity warrants an early asset and exposure review.Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies. When a request body exceeds the configured maxBodyBytes limit, Skipper forwards the full payload to the upstream service while OPA evaluates against an empty parsed_body, so policies that deny requests based on body content are not enforced and forbidden actions proceed. No fixed version is available; v0.27.26 adds documentation guidance only.
The CVSS severity warrants an early asset and exposure review.