24h | 7d | 30d

Overview

  • SysAid
  • SysAid On-Prem

07 May 2025
Published
08 May 2025
Updated

CVSS v3.1
CRITICAL (9.3)
EPSS
0.05%

KEV

Description

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality, allowing for administrator account takeover and file read primitives.

Statistics

  • 1 Post
  • 2 Interactions

Fediverse

Profile picture

Critical vulnerabilities discovered in SysAid's on-premise IT support software

💥 Vulnerability: XML External Entity (XXE) injections that can lead to RCE

⚠️ Impact: Retrieval of sensitive files, full admin access, and arbitrary code execution, risking data breaches and system compromises.

🔍 CVEs: CVE-2025-2775, CVE-2025-2776, CVE-2025-2777, CVE-2025-2778

🔧 Remediation: Update to SysAid version 24.4.60 b16

#cybersecurity #SysAid #vulnerabilitymanagement

thehackernews.com/2025/05/sysa

  • 1
  • 1
  • 19 hours ago

Overview

  • Microsoft
  • Microsoft Power Apps

08 May 2025
Published
08 May 2025
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
Pending

KEV

Description

Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network

Statistics

  • 1 Post
  • 3 Interactions

Fediverse

Profile picture

Microsoft published six sev:CRIT vulns in cloud services. No public exploits, no exploitation indicated.

This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.

msrc.microsoft.com/update-guid

msrc.microsoft.com/update-guid

msrc.microsoft.com/update-guid

msrc.microsoft.com/update-guid

msrc.microsoft.com/update-guid

msrc.microsoft.com/update-guid

  • 1
  • 2
  • 8 hours ago

Overview

  • Microsoft
  • Microsoft msagsfeedback.azurewebsites.net

08 May 2025
Published
08 May 2025
Updated

CVSS v3.1
HIGH (8.1)
EPSS
Pending

KEV

Description

Improper access control in Azure allows an unauthorized attacker to disclose information over a network.

Statistics

  • 1 Post
  • 3 Interactions

Fediverse

Profile picture

Microsoft published six sev:CRIT vulns in cloud services. No public exploits, no exploitation indicated.

This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.

msrc.microsoft.com/update-guid

msrc.microsoft.com/update-guid

msrc.microsoft.com/update-guid

msrc.microsoft.com/update-guid

msrc.microsoft.com/update-guid

msrc.microsoft.com/update-guid

  • 1
  • 2
  • 8 hours ago

Overview

  • Microsoft
  • Azure Storage Resource Provider (SRP)

08 May 2025
Published
08 May 2025
Updated

CVSS v3.1
CRITICAL (9.9)
EPSS
Pending

KEV

Description

Server-Side Request Forgery (SSRF) in Azure allows an authorized attacker to perform spoofing over a network.

Statistics

  • 1 Post
  • 3 Interactions

Fediverse

Profile picture

Microsoft published six sev:CRIT vulns in cloud services. No public exploits, no exploitation indicated.

This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.

msrc.microsoft.com/update-guid

msrc.microsoft.com/update-guid

msrc.microsoft.com/update-guid

msrc.microsoft.com/update-guid

msrc.microsoft.com/update-guid

msrc.microsoft.com/update-guid

  • 1
  • 2
  • 8 hours ago

Overview

  • Microsoft
  • Azure Automation

08 May 2025
Published
08 May 2025
Updated

CVSS v3.1
CRITICAL (9.9)
EPSS
Pending

KEV

Description

Improper Authorization in Azure Automation allows an authorized attacker to elevate privileges over a network.

Statistics

  • 1 Post
  • 3 Interactions

Fediverse

Profile picture

Microsoft published six sev:CRIT vulns in cloud services. No public exploits, no exploitation indicated.

This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.

msrc.microsoft.com/update-guid

msrc.microsoft.com/update-guid

msrc.microsoft.com/update-guid

msrc.microsoft.com/update-guid

msrc.microsoft.com/update-guid

msrc.microsoft.com/update-guid

  • 1
  • 2
  • 8 hours ago

Overview

  • Microsoft
  • Microsoft Dataverse

08 May 2025
Published
08 May 2025
Updated

CVSS v3.1
HIGH (8.7)
EPSS
Pending

KEV

Description

Microsoft Dataverse Remote Code Execution Vulnerability

Statistics

  • 1 Post
  • 3 Interactions

Fediverse

Profile picture

Microsoft published six sev:CRIT vulns in cloud services. No public exploits, no exploitation indicated.

This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.

msrc.microsoft.com/update-guid

msrc.microsoft.com/update-guid

msrc.microsoft.com/update-guid

msrc.microsoft.com/update-guid

msrc.microsoft.com/update-guid

msrc.microsoft.com/update-guid

  • 1
  • 2
  • 8 hours ago

Overview

  • Microsoft
  • Azure DevOps

08 May 2025
Published
08 May 2025
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
Pending

KEV

Description

An elevation of privilege vulnerability exists when Visual Studio improperly handles pipeline job tokens. An attacker who successfully exploited this vulnerability could extend their access to a project. To exploit this vulnerability, an attacker would first have to have access to the project and swap the short-term token for a long-term one. The update addresses the vulnerability by correcting how the Visual Studio updater handles these tokens.

Statistics

  • 1 Post
  • 3 Interactions

Fediverse

Profile picture

Microsoft published six sev:CRIT vulns in cloud services. No public exploits, no exploitation indicated.

This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.

msrc.microsoft.com/update-guid

msrc.microsoft.com/update-guid

msrc.microsoft.com/update-guid

msrc.microsoft.com/update-guid

msrc.microsoft.com/update-guid

msrc.microsoft.com/update-guid

  • 1
  • 2
  • 8 hours ago
Showing 31 to 37 of 37 CVEs