Known Vulnerabilities for 365 Apps by Microsoft
Listed below are 10 of the newest known vulnerabilities associated with "365 Apps" by "Microsoft".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-56325 json | Capgo before 12.128.2 uses ILIKE pattern matching instead of exact matching for app_id lookup in the preview subdomain resolv... | Not Provided | 2026-06-20 | 2026-06-20 |
| CVE-2026-56319 json | Capgo before 12.128.2 contains an information disclosure vulnerability in the GET /statistics/app/:app_id endpoint that allow... | Not Provided | 2026-06-20 | 2026-06-20 |
| CVE-2026-56229 json | Capgo before 12.128.2 contains an authorization bypass vulnerability in the /build/status and /build/logs endpoints that allo... | Not Provided | 2026-06-21 | 2026-06-21 |
| CVE-2026-53725 json | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. From version 9.8.0 to... | Not Provided | 2026-06-12 | 2026-06-13 |
| CVE-2026-50211 json | Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps... | Not Provided | 2026-06-04 | 2026-06-04 |
| CVE-2026-50131 json | Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Fedify previously addressed SSRF/in... | Not Provided | 2026-06-10 | 2026-06-11 |
| CVE-2026-48988 json | markdown-it is a Markdown parser. Versions 14.1.1 and below contain a denial-of-service vulnerability when typographer: true ... | Not Provided | 2026-06-17 | 2026-06-18 |
| CVE-2026-48772 json | ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 2.0.0 through 3.0.8, the ProxySQL MySQL front... | Not Provided | 2026-06-19 | 2026-06-19 |
| CVE-2026-48713 json | Versions prior to 2.6.6 are vulnerable to prototype pollution via crafted missing-key strings when used to persist missing tr... | Not Provided | 2026-06-15 | 2026-06-16 |
| CVE-2026-48150 json | Budibase is an open-source low-code platform. Prior to 3.39.0, /api/public/v1/roles/assign is guarded by the builderOrAdmin m... | Not Provided | 2026-05-27 | 2026-05-27 |