|
1881
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to ce…
|
CWE-36
Absolute Path Traversal
|
CVE-2026-32175
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1882
|
7.3 |
HIGH
Local
|
-
|
-
|
Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.
|
CWE-20 CWE-122
Improper Input Validation Heap-based Buffer Overflow
|
CVE-2026-32177
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1883
|
7.8 |
HIGH
Local
|
-
|
-
|
External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
|
CWE-73
External Control of File Name or Path
|
CVE-2026-32204
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1884
|
8.2 |
HIGH
Network
|
-
|
-
|
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network.
|
CWE-74
Injection
|
CVE-2026-33833
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1885
|
7.3 |
HIGH
Local
|
-
|
-
|
Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.
|
CWE-20 CWE-190
Improper Input Validation Integer Overflow or Wraparound
|
CVE-2026-35433
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1886
|
8.3 |
HIGH
Network
|
-
|
-
|
Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
|
CWE-862
Missing Authorization
|
CVE-2026-35438
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1887
|
8.8 |
HIGH
Network
|
-
|
-
|
External control of file name or path in SQL Server allows an authorized attacker to execute code over a network.
|
CWE-73
External Control of File Name or Path
|
CVE-2026-40370
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1888
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.
|
CWE-200
Information Exposure
|
CVE-2026-40379
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1889
|
7.8 |
HIGH
Local
|
-
|
-
|
Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally.
|
CWE-1390
Weak Authentication
|
CVE-2026-40417
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1890
|
7.2 |
HIGH
Network
|
-
|
-
|
An administrative user with access to configure webhooks can execute arbitrary commands by configuring and then triggering webhooks containing specific FreeMarker template syntax.
This issue affe…
|
CWE-77
Command Injection
|
CVE-2026-8431
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|