VulnSea

CWE-923

CVEs classified under CWE-923, newest first.

6 CVEsRSS

CVE-2026-78501High· 7.4
4d ago

Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network.

Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network.

TwilightMicrosoft · Microsoft 365 Copilot's Business ChatEPSS 0.49%via NVD
CVE-2026-81871Medium· 6.3
5d ago

OpenTelemetry-Go is the Go implementation of OpenTelemetry

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the exporters/otlp/otlplog/otlploggrpc package loads OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE, OTEL_EXPORTER_OTLP_CERTIFICATE, and related client certificate…

Sunlitopen-telemetry · opentelemetry-goEPSS 0.20%via NVD
CVE-2026-90461Medium· 6.3
1w ago

OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.

OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.

SunlitOpenStack · IronicEPSS 0.21%via NVD
CVE-2026-87734High· 7.5PoC
1w ago

An issue was discovered in the utcp package before 0.0.6 for OCaml

An issue was discovered in the utcp package before 0.0.6 for OCaml. Out-of-order segment reassembly allows remote denial of service.

MidnightOCaml · utcpEPSS 0.29%via CVEORG
CVE-2026-13608High· 7.4PoC⚖ disputed
2w ago

A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification

A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a …

Midnighthaxx · curlEPSS 0.64%via NVD
CVE-2026-62836High· 8.7
1mo ago

Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.

Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.

Twilightmicrosoft · azure_sql_managed_instanceEPSS 0.43%via NVD
CWE-923 vulnerabilities (CVEs) · VulnSea