Kategorie: Allgemein

[UPDATE] [mittel] Node.js: Mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Node.js ausnutzen, um Sicherheitsvorkehrungen zu umgehen und um einen Denial-of-Service-Zustand zu verursachen.

[UPDATE] [kritisch] Fortinet FortiWeb: Schwachstelle ermöglicht SQL Injection

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Fortinet FortiWeb ausnutzen, um eine SQL Injection durchzuführen.

CVE-2025-53771 Microsoft SharePoint Server Spoofing Vulnerability

Improper limitation of a pathname to a restricted directory (‚path traversal‘) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CVE-2025-53770 Microsoft SharePoint Server Remote Code Execution Vulnerability

The security update is avaialble for Microsoft SharePoint Server Subscription Edition. Microsoft strongly encourages customers running this version of SharePoint to install this update as soon as possible.

Microsoft: Angriffe auf neue Sharepoint-Lücke – bislang kein Patch verfügbar

Microsoft warnt vor aktiven Angriffen auf eine bislang unbekannte Lücke in Sharepoint-Servern und benennt Erste-Hilfe-Maßnahmen für Verteidiger.

CVE-2025-49747 Azure Machine Learning Elevation of Privilege Vulnerability

Missing authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.

CVE-2025-49746 Azure Machine Learning Elevation of Privilege Vulnerability

Improper authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.

CVE-2025-47995 Azure Machine Learning Elevation of Privilege Vulnerability

Weak authentication in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.

CVE-2025-53762 Microsoft Purview Elevation of Privilege Vulnerability

Permissive list of allowed inputs in Microsoft Purview allows an authorized attacker to elevate privileges over a network.

CVE-2025-47158 Azure DevOps Server Elevation of Privilege Vulnerability

Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.