CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.
NOTE: This CVE affects only End Of Life (EOL) software components. The vendor, Microsoft, has indicated there will be no future updates nor support provided upon inquiry. |
Multiple vulnerabilities in the update process of Cisco ThousandEyes Endpoint Agent for Windows could allow an authenticated, local attacker to delete arbitrary files on an affected device.
These vulnerabilities are due to improper access controls on files that are in the local file system. An attacker could exploit these vulnerabilities by using a symbolic link to perform an agent upgrade that redirects the delete operation of any protected file. A successful exploit could allow the attacker to delete arbitrary files from the file system of the affected device. |
Memory corruption while processing command message in WLAN Host. |
Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network. |
Adobe Connect versions 24.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could lead to arbitrary code execution by an attacker. Exploitation of this issue does require user interaction and scope is changed. |
Improper input validation in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally. |
No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. |
Microsoft Edge (Chromium-based) Spoofing Vulnerability |
Exposure of private personal information to an unauthorized actor in Dynamics 365 FastTrack Implementation Assets allows an unauthorized attacker to disclose information over a network. |
A remote code execution vulnerability exists in PowerShell Editor Services, aka "PowerShell Editor Services Remote Code Execution Vulnerability." This affects PowerShell Editor, PowerShell Extension. |
Visual Studio Code npm-script Extension Remote Code Execution Vulnerability |
Microsoft Edge (Chromium-based) Spoofing Vulnerability |
Visual Studio Remote Code Execution Vulnerability |
Microsoft Edge for iOS Spoofing Vulnerability |
Azure Science Virtual Machine (DSVM) Elevation of Privilege Vulnerability |
Windows Perception Service Elevation of Privilege Vulnerability |
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability |
Azure Monitor Agent Elevation of Privilege Vulnerability |
Microsoft Azure File Sync Elevation of Privilege Vulnerability |
Azure Storage Movement Client Library Denial of Service Vulnerability |