Recent Advisories

Severity ID Title Vendor Product Date Type
NONE MS:CVE-2026-42827

M365 Copilot Information Disclosure Vulnerability_MS:CVE-2026-42827

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose inf...

N/A N/A MSCVE
NONE MS:CVE-2026-23663

Microsoft Global Secure Access (GSA) Information Disclosure Vulnerability_MS:CVE-2026-23663

Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network.

N/A N/A MSCVE
NONE MS:CVE-2026-23652

Microsoft Power Pages Remote Code Execution Vulnerability_MS:CVE-2026-23652

Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to exe...

N/A N/A MSCVE
NONE MS:CVE-2026-33843

Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability_MS:CVE-2026-33843

Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privile...

N/A N/A MSCVE
NONE MS:CVE-2026-40411

Azure Virtual Network Gateway Remote Code Execution Vulnerability_MS:CVE-2026-40411

Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network.

N/A N/A MSCVE
NONE MS:CVE-2026-41104

Microsoft Planetary Computer Pro Information Disclosure Vulnerability_MS:CVE-2026-41104

Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a network.

N/A N/A MSCVE
NONE 3401ECFA-1BF5-

autopenx_3401ECFA-1BF5-560B-BA4E-CECDE5B4E76E

AutoPenX — LLM 驱动的全自动 CTF Web 解题 & 渗透测试系统 三阶段混合求解架构:确定性多智能体路线状态机 → 并行 LLM 竞速 → 顺序 ReAct 推理,实现零 API ...

N/A N/A GITHUBEXPLOIT
NONE AKAMAIBLOG:E327...

Decentralized Threat: Stealthy P2P Cryptominer Targeting Ollama Endpoints_AKAMAIBLOG:E327040385169CA2A84E7C6F11F4A0BB

The Akamai SIRT uncovered a custom P2P Trojan masquerading as system activity. Learn how to detect and mitigate this stealthy Go-based cryptominer.

N/A N/A AKAMAIBLOG
NONE 903165D4-D8A1-

pocx_903165D4-D8A1-56AE-A379-4B960FF5AFD5

pocx 一个完善的 yaml poc 引擎,poc 定义在wiki中 使用方法参考 example/main.go 未实现 - 部分表达式函数 - toUintString // expression/expr.go - TCP/UDP...

N/A N/A GITHUBEXPLOIT
NONE 766CBBCA-5E44-

rgui-3.4.4-seh-bof-exploit_766CBBCA-5E44-5A8D-8F94-04765D58A815

Exploração de Buffer Overflow SEH Overwrite no RGui 3.4.4 Visão Geral do Projeto Este projeto documenta uma análise completa de Engenharia Reversa ...

N/A N/A GITHUBEXPLOIT