Medium · CVSS 5.4
A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malicious code. This code could be executed when deserialized by a web browser, causing Cross-site scripting (XSS) attacks. This issue is critical in environments where serialized data is sent to web clients, potentially compromising the security of the website or web application using this package.
Published Feb 10, 2025 · Updated Aug 23, 2026
High · CVSS 7.7
An authorization bypass vulnerability was discovered in GitLab affecting versions 15.1 prior to 16.7.6, 16.8 prior to 16.8.3, and 16.9 prior to 16.9.1. A developer could bypass CODEOWNERS approvals by creating a merge conflict.
Published Feb 21, 2024 · Updated Aug 14, 2026
High · CVSS 8
Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
High · CVSS 7.5
.NET Denial of Service Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
High · CVSS 7.5
.NET Denial of Service Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
High · CVSS 8.1 · CISA KEV
Internet Shortcut Files Security Feature Bypass Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
High · CVSS 7.5
Windows Printing Service Spoofing Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
High · CVSS 7
Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
Critical · CVSS 9
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
High · CVSS 8.3
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Published Feb 2, 2024 · Updated Aug 10, 2026
Medium · CVSS 5.3
Microsoft Azure File Sync Elevation of Privilege Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
High · CVSS 8.2
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
High · CVSS 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
High · CVSS 7.8
Microsoft Office OneNote Remote Code Execution Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
High · CVSS 8.8
Microsoft Outlook Remote Code Execution Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
Medium · CVSS 5.5
Windows DNS Information Disclosure Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
Critical · CVSS 9
Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
Medium · CVSS 5
Microsoft Teams for Android Information Disclosure Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
High · CVSS 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
High · CVSS 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
High · CVSS 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
High · CVSS 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
Critical · CVSS 9.3
Microsoft Azure Site Recovery Elevation of Privilege Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
High · CVSS 7.8
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
Medium · CVSS 5.5
Windows Kernel Security Feature Bypass Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
High · CVSS 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
Medium · CVSS 6.5
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
High · CVSS 7
Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
High · CVSS 8.8
Microsoft WDAC ODBC Driver Remote Code Execution Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
High · CVSS 7.5
Internet Connection Sharing (ICS) Denial of Service Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
High · CVSS 7.5
Microsoft ODBC Driver Remote Code Execution Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
High · CVSS 7.8
Win32k Elevation of Privilege Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
High · CVSS 8.8
Windows Kernel Elevation of Privilege Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
Medium · CVSS 5.9
Windows Network Address Translation (NAT) Denial of Service Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
Medium · CVSS 5.9
Windows Network Address Translation (NAT) Denial of Service Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
High · CVSS 7.5
Windows DNS Client Denial of Service Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
Medium · CVSS 6.8
Windows Kernel Remote Code Execution Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
Medium · CVSS 6.4
Windows USB Generic Parent Driver Remote Code Execution Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
High · CVSS 7.6
Dynamics 365 Sales Spoofing Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
Medium · CVSS 6.5
Azure Stack Hub Spoofing Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
High · CVSS 7.5
Azure DevOps Server Remote Code Execution Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
Medium · CVSS 4.1
Trusted Compute Base Elevation of Privilege Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
Medium · CVSS 5.7
Skype for Business Information Disclosure Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
High · CVSS 7.8
Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
Medium · CVSS 4.3
Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability
Published Feb 29, 2024 · Updated Aug 10, 2026
High · CVSS 8.2
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Published Feb 23, 2024 · Updated Aug 10, 2026
Medium · CVSS 4.3
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Published Feb 23, 2024 · Updated Aug 10, 2026
Medium · CVSS 4.8
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Published Feb 23, 2024 · Updated Aug 10, 2026
High · CVSS 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026
Critical · CVSS 9.8 · CISA KEV
Microsoft Outlook Remote Code Execution Vulnerability
Published Feb 13, 2024 · Updated Aug 10, 2026