CVE Notify
19.4K subscribers
4 photos
223K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
๐Ÿšจ CVE-2024-35248
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-35249
Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-35250
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-35252
Azure Storage Movement Client Library Denial of Service Vulnerability

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-35253
Microsoft Azure File Sync Elevation of Privilege Vulnerability

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-35255
Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-35263
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-35265
Windows Perception Service Elevation of Privilege Vulnerability

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-37325
Azure Science Virtual Machine (DSVM) Elevation of Privilege Vulnerability

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-30057
Microsoft Edge for iOS Spoofing Vulnerability

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-30058
Microsoft Edge (Chromium-based) Spoofing Vulnerability

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-38083
Microsoft Edge (Chromium-based) Spoofing Vulnerability

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-38082
Microsoft Edge (Chromium-based) Spoofing Vulnerability

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-38093
Microsoft Edge (Chromium-based) Spoofing Vulnerability

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-35260
An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-57956
SigNoz before 0.133.0 contains a broken access control vulnerability that allows authenticated users to access other organizations' alert rules by supplying a target rule UUID, as the alert rule store predicates fail to filter by organization ID. Attackers can read, edit, and delete alert rules belonging to other organizations by exploiting the missing tenant isolation check, bypassing multi-tenant access controls.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-0487
SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location, allowing them to execute malicious code on the system. This could enable the attacker to hijack the DLL loading process and achieve arbitrary code execution. This has high impact on confidentiality, integrity and availability of the system.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-50337
Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-50339
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-50346
Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-45806
Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot's remote image import passed the user-controlled url from frontend/src/app/main/data/workspace/media.cljs into the backend RPC method :create-file-media-object-from-url in backend/src/app/rpc/commands/media.clj, where media/download-image in backend/src/app/media.clj used the shared HTTP client without destination filtering, allowing an authenticated file editor to reach internal-only endpoints. This issue is fixed in version 2.15.0.

๐ŸŽ–@cveNotify