Copilot
84 exploits
Active since Feb 2025
Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page
GitHub MCP Server: Nil Pointer Dereference DoS in completion/complete Handler
CVSS 7.5
Mongo-object < 3.0.3 - Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVSS 4.0
Pimcore: CustomReports Share Bypass
secure_headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
CVSS 4.7
Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader
Prompty: Arbitrary File Read via ${file:path} Reference Expansion
CVSS 7.5
Kiota: Code Generation Literal Injection in the PHP Generator
Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions
Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
CVSS 7.1
Qinglong: Incomplete fix for CVE-2026-3965: Improper Authentication
Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry
CVSS 9.6
CoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe / net.uds framing handshake
CVSS 7.5
CoreWCF: WS-Security signature substitution via document-wide Signature lookup
CVSS 5.9
CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate
CVSS 7.4
CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.
CVSS 6.5
CoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgrade
CVSS 4.4
CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution
CVSS 6.2
CoreWCF: SAML token replay protection is inoperative
CVSS 5.9
CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass
CVSS 3.7
CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforced
CVSS 7.4
CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation
CVSS 10.0
CoreWCF WS-Security - SOAP Message Replay
CVSS 7.4
CoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe / net.uds framing handshake
CVSS 7.5
CoreWCF: WS-Security signature substitution via document-wide Signature lookup
CVSS 5.9