CVE-2025-29923 go-redis allows potential out of order responses when `CLIENT SETINFO` times out during connection establishment
Information published.
EPSS 0.01 CVE-2025-29923 US
Information published.
EPSS 0.01 CVE-2025-29923 US
Information published.
EPSS 0.01 CVE-2025-0665 US
Information published.
EPSS 0.01 CVE-2025-1178 GNU US
Information published.
EPSS 0.01 CVE-2025-1176 GNU US
Information published.
EPSS 0.03 CVE-2023-27043 Python US
To comprehensively address this vulnerability Windows 11 Version 26H1 for ARM64-based Systems and Windows 11 Version 26H1 for64-based Systems have been added to the Security Updates table. Microsoft recommend updating to the June 2026 version of your Windows operating systems.
EPSS 0.02 CVE-2025-21330 Microsoft US
To comprehensively address this vulnerability Windows 11 Version 26H1 for ARM64-based Systems and Windows 11 Version 26H1 for64-based Systems have been added to the Security Updates table. Microsoft recommend updating to the June 2026 version of your Windows operating systems.
EPSS 0.01 CVE-2024-49123 Microsoft US
To comprehensively address this vulnerability Windows 11 Version 26H1 for ARM64-based Systems and Windows 11 Version 26H1 for64-based Systems have been added to the Security Updates table. Microsoft recommend updating to the June 2026 version of your Windows operating systems.
EPSS 0.03 CVE-2024-49075 Microsoft US
To comprehensively address this vulnerability Windows 11 Version 26H1 for ARM64-based Systems and Windows 11 Version 26H1 for64-based Systems have been added to the Security Updates table. Microsoft recommend updating to the June 2026 version of your Windows operating systems.
EPSS 0.01 CVE-2024-49132 Microsoft US
Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.
Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.
To comprehensively address this vulnerability Windows 11 Version 26H1 for ARM64-based Systems and Windows 11 Version 26H1 for64-based Systems have been added to the Security Updates table. Microsoft recommend updating to the June 2026 version of your Windows operating systems.
EPSS 0.03 CVE-2024-43582 Microsoft US
Updated the build numbers. This is an informational update only.
EPSS 0.01 CVE-2024-38225 Microsoft US
Updated the build numbers. This is an informational update only.
EPSS 0.01 CVE-2024-35248 Microsoft US
Updated the build numbers. This is an informational update only.
EPSS 0.02 CVE-2024-21380 Microsoft US
Information published.
EPSS 0.04 CVE-2023-5678 US
Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.
Updated the build numbers. This is an informational update only.
A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing HTML files is uploaded to the server and HTML files are accessed directly by the victim. Combining these 2 vulnerabilities together, an attacker is able to upload malicious Power BI templates files to the server using the victim's session and run scripts in the security context of the user and perform privilege escalation in case the victim has…
CVSS 7.6 CVE-2021-41372 US
Updated the build numbers. This is an informational update only.
EPSS 0.01 CVE-2021-40440 Microsoft US
Updated the build numbers. This is an informational update only.
EPSS 0.01 CVE-2021-36946 Microsoft US
Updated the build numbers. This is an informational update only.
EPSS 0.02 CVE-2021-34474 Microsoft US
Corrected the Power BI Report Server version in the Security Updates table to use the public release version instead of the internal build number. This is an informational change only.
To comprehensively address the vulnerability identified by CVE-2020-17103, Microsoft recommends installing the June 2026 updates for your Windows operating systems.
EPSS 0.27 CVE-2020-17103 Microsoft US
Information published.
EPSS 0.17 CVE-2019-6706 Lua US
A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded attachments. An authenticated attacker could exploit the vulnerability by uploading a specially crafted payload and sending it to the user. The attacker who successfully exploited this vulnerability could then perform actions and run scripts in the security context of the user. This security update addresses the vulnerability by ensuring Power BI Report Server properly…