Common Vulnerabilities and Exposures (CVE)

CVE-2026-24132

Jan 22, 2026 23:47:45 UTC

Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions 7.19.0 and below and 8.0.0-rc.0 through 8.0.2 allow untrusted OpenAPI specifications to inject arbitrary TypeScript/JavaScrip...

CVE-2025-7195

Jan 22, 2026 23:43:56 UTC

Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_setup, which modifies the permissions of the /etc/pass...

CVE-2025-54313

Jan 22, 2026 23:20:24 UTC

eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.

CVE-2025-31125

Jan 22, 2026 23:20:24 UTC

Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option)...

CVE-2025-34026

Jan 22, 2026 23:20:23 UTC

The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged ...

CVE-2025-68645

Jan 22, 2026 23:20:23 UTC

A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote at...

CVE-2025-9290

Jan 22, 2026 23:14:45 UTC

An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to i...

CVE-2026-24130

Jan 22, 2026 22:53:34 UTC

Moonraker is a Python web server providing API access to Klipper 3D printing firmware. In versions 0.9.3 and below, instances configured with the "ldap" component enabled are vulnerable to LDAP search filter injection techniques via the log...

CVE-2026-21264

Jan 22, 2026 22:47:38 UTC

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-21521

Jan 22, 2026 22:47:38 UTC

Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized attacker to disclose information over a network.

CVE-2026-21227

Jan 22, 2026 22:47:37 UTC

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-24307

Jan 22, 2026 22:47:36 UTC

Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network.

CVE-2026-24305

Jan 22, 2026 22:47:36 UTC

Azure Entra ID Elevation of Privilege Vulnerability

CVE-2026-21524

Jan 22, 2026 22:47:35 UTC

Exposure of sensitive information to an unauthorized actor in Azure Data Explorer allows an unauthorized attacker to disclose information over a network.

CVE-2026-24306

Jan 22, 2026 22:47:34 UTC

Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network.