CVE-2016-2568 pkexec, when used with --user nonpriv, allows local users to escape to the parent session
Information published.
Categories: Microsoft
CVE-2007-3205 The parse_str function in (1) PHP, (2) Hardened-PHP, and (3) Suhosin, when called without a second parameter, might allow remote attackers to overwrite arbitrary variables by specifying variable names and values in the string to be parsed...
Information published.
Categories: Microsoft
New - Citrix Virtual Apps and Desktops 7 2402 LTSR CU4 Update 1
New downloads are available for Citrix Virtual Apps and Desktops
Categories: Citrix
New - Citrix Virtual Apps and Desktops 7 2203 LTSR CU7 Update 4
New downloads are available for Citrix Virtual Apps and Desktops
Categories: Citrix
CVE-2026-62836 Azure SQL Managed Instance Elevation of Privilege Vulnerability
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-62896 Microsoft Teams Elevation of Privilege Vulnerability
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-65668 Microsoft Purview eDiscovery Elevation of Privilege Vulnerability
Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-59118 Microsoft Power Apps Elevation of Privilege Vulnerability
Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-50516 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-50481 Azure Active Directory Elevation of Privilege Vulnerability
Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-62918 Microsoft Teams Spoofing Vulnerability
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.
Categories: Microsoft
CVE-2026-59115 Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability
'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-49163 Application Insights Profiler Elevation of Privilege Vulnerability
Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-68823 Azure Confidential Ledger Remote Code Execution Vulnerability
Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network.
Categories: Microsoft
CVE-2026-70332 Microsoft Office SharePoint Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Categories: Microsoft
CVE-2026-56161 Azure Logic Apps Information Disclosure Vulnerability
Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.
Categories: Microsoft
CVE-2026-62830 Azure SRE Agent Elevation of Privilege Vulnerability
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-65667 Microsoft Teams Elevation of Privilege Vulnerability
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-56162 Azure SQL Database Elevation of Privilege Vulnerability
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
Categories: Microsoft
CVE-2026-50515 Azure Service Bus Remote Code Execution Vulnerability
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
Categories: Microsoft


