|
551
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.
|
CWE-77
Command Injection
|
CVE-2026-42827
|
2026-05-23 08:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
552
|
- |
|
-
|
-
|
Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and prior, in addition to 11.0.0-alpha.1 through 11.12.0 are vulnerable to CSS …
|
CWE-94
Code Injection
|
CVE-2026-41148
|
2026-05-23 08:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
553
|
10.0 |
CRITICAL
Network
|
-
|
-
|
Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a network.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-41104
|
2026-05-23 08:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
554
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.
|
CWE-77
Command Injection
|
CVE-2026-41090
|
2026-05-23 08:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
555
|
10.0 |
CRITICAL
Network
|
-
|
-
|
Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-40412
|
2026-05-23 08:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
556
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network.
|
CWE-20
Improper Input Validation
|
CVE-2026-40411
|
2026-05-23 08:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
557
|
8.8 |
HIGH
Network
|
-
|
-
|
Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized attacker to elevate privileges over a network.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-35430
|
2026-05-23 08:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
558
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-33843
|
2026-05-23 08:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
559
|
7.7 |
HIGH
Network
|
-
|
-
|
Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network.
|
CWE-20
Improper Input Validation
|
CVE-2026-26147
|
2026-05-23 08:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
560
|
7.5 |
HIGH
Network
|
-
|
-
|
Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network.
|
CWE-269
Improper Privilege Management
|
CVE-2026-23663
|
2026-05-23 08:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|