๐จ CVE-2024-35248
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
๐@cveNotify
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
๐@cveNotify
๐จ CVE-2024-35249
Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability
๐@cveNotify
Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability
๐@cveNotify
๐จ CVE-2024-35252
Azure Storage Movement Client Library Denial of Service Vulnerability
๐@cveNotify
Azure Storage Movement Client Library Denial of Service Vulnerability
๐@cveNotify
๐จ CVE-2024-35255
Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability
๐@cveNotify
Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability
๐@cveNotify
๐จ CVE-2024-35263
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
๐@cveNotify
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
๐@cveNotify
๐จ CVE-2024-37325
Azure Science Virtual Machine (DSVM) Elevation of Privilege Vulnerability
๐@cveNotify
Azure Science Virtual Machine (DSVM) Elevation of Privilege Vulnerability
๐@cveNotify
๐จ CVE-2024-35260
An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network.
๐@cveNotify
An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network.
๐@cveNotify
๐จ CVE-2026-57956
SigNoz before 0.133.0 contains a broken access control vulnerability that allows authenticated users to access other organizations' alert rules by supplying a target rule UUID, as the alert rule store predicates fail to filter by organization ID. Attackers can read, edit, and delete alert rules belonging to other organizations by exploiting the missing tenant isolation check, bypassing multi-tenant access controls.
๐@cveNotify
SigNoz before 0.133.0 contains a broken access control vulnerability that allows authenticated users to access other organizations' alert rules by supplying a target rule UUID, as the alert rule store predicates fail to filter by organization ID. Attackers can read, edit, and delete alert rules belonging to other organizations by exploiting the missing tenant isolation check, bypassing multi-tenant access controls.
๐@cveNotify
GitHub
[security] cross-organization IDOR on alert rules (read/edit/delete by UUID, no org scoping) ยท Issue #11830 ยท SigNoz/signoz
(I've reported the following cross-org IDOR via email on 13 June 2026 with no response) The rule store predicates (pkg/ruler/rulestore/sqlrulestore/rule.go) filter on id only: GetStoredRule (~1...
๐จ CVE-2026-0487
SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location, allowing them to execute malicious code on the system. This could enable the attacker to hijack the DLL loading process and achieve arbitrary code execution. This has high impact on confidentiality, integrity and availability of the system.
๐@cveNotify
SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location, allowing them to execute malicious code on the system. This could enable the attacker to hijack the DLL loading process and achieve arbitrary code execution. This has high impact on confidentiality, integrity and availability of the system.
๐@cveNotify
๐จ CVE-2026-50337
Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Incorrect type conversion or cast in Windows Notification allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-50339
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.
๐@cveNotify
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.
๐@cveNotify
๐จ CVE-2026-50346
Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Improper authorization in RPC Runtime allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-45806
Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot's remote image import passed the user-controlled url from frontend/src/app/main/data/workspace/media.cljs into the backend RPC method :create-file-media-object-from-url in backend/src/app/rpc/commands/media.clj, where media/download-image in backend/src/app/media.clj used the shared HTTP client without destination filtering, allowing an authenticated file editor to reach internal-only endpoints. This issue is fixed in version 2.15.0.
๐@cveNotify
Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot's remote image import passed the user-controlled url from frontend/src/app/main/data/workspace/media.cljs into the backend RPC method :create-file-media-object-from-url in backend/src/app/rpc/commands/media.clj, where media/download-image in backend/src/app/media.clj used the shared HTTP client without destination filtering, allowing an authenticated file editor to reach internal-only endpoints. This issue is fixed in version 2.15.0.
๐@cveNotify
GitHub
Release 2.15.0 ยท penpot/penpot
โจ New features & Enhancements
Add MCP server integration Github #9174
Add chunked upload API for large media and binary files (removes previous upload size limits) Github #9516
Add anonymous t...
Add MCP server integration Github #9174
Add chunked upload API for large media and binary files (removes previous upload size limits) Github #9516
Add anonymous t...