Common Vulnerabilities and Exposures (CVE)

CVE-2025-59245

Nov 22, 2025 04:55:18 UTC

Microsoft SharePoint Online Elevation of Privilege Vulnerability

CVE-2025-64660

Nov 22, 2025 04:55:17 UTC

Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature over a network.

CVE-2025-62207

Nov 22, 2025 04:55:16 UTC

Azure Monitor Elevation of Privilege Vulnerability

CVE-2025-61757

Nov 22, 2025 04:55:15 UTC

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker ...

CVE-2025-60711

Nov 22, 2025 04:09:59 UTC

Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVE-2025-59501

Nov 22, 2025 04:09:58 UTC

Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attacker to perform spoofing over an adjacent network.

CVE-2025-59500

Nov 22, 2025 04:09:58 UTC

Improper access control in Azure Notification Service allows an authorized attacker to elevate privileges over a network.

CVE-2025-59503

Nov 22, 2025 04:09:57 UTC

Server-side request forgery (ssrf) in Azure Compute Gallery allows an unauthorized attacker to elevate privileges over a network.

CVE-2025-59273

Nov 22, 2025 04:09:56 UTC

Improper access control in Azure Event Grid allows an unauthorized attacker to elevate privileges over a network.

CVE-2025-59286

Nov 22, 2025 04:09:56 UTC

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform spoofing over a network.

CVE-2025-55321

Nov 22, 2025 04:09:55 UTC

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthorized attacker to perform spoofing over a network.

CVE-2025-59272

Nov 22, 2025 04:09:55 UTC

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform spoofing over a network.

CVE-2025-59271

Nov 22, 2025 04:09:54 UTC

Redis Enterprise Elevation of Privilege Vulnerability

CVE-2025-59252

Nov 22, 2025 04:09:53 UTC

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform spoofing over a network.

CVE-2025-59247

Nov 22, 2025 04:09:53 UTC

Azure PlayFab Elevation of Privilege Vulnerability