Known Vulnerabilities for Web Applications by Microsoft
Listed below are 9 of the newest known vulnerabilities associated with "Web Applications" by "Microsoft".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-34876 | An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/... | Not Provided | 2026-04-02 | 2026-04-02 |
| CVE-2026-34452 | The Claude SDK for Python provides access to the Claude API from Python applications. From version 0.86.0 to before version 0... | Not Provided | 2026-03-31 | 2026-03-31 |
| CVE-2026-34451 | Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From vers... | Not Provided | 2026-03-31 | 2026-04-01 |
| CVE-2026-34450 | The Claude SDK for Python provides access to the Claude API from Python applications. From version 0.86.0 to before version 0... | Not Provided | 2026-03-31 | 2026-04-01 |
| CVE-2026-34240 | JOSE is a Javascript Object Signing and Encryption (JOSE) library. Prior to version 0.3.5+1, a vulnerability in jose could al... | Not Provided | 2026-03-31 | 2026-04-01 |
| CVE-2026-34236 | Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. From version 8.0.0 to before version 8.19.0, in applicat... | Not Provided | 2026-04-01 | 2026-04-01 |
| CVE-2026-34156 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to ver... | Not Provided | 2026-03-31 | 2026-03-31 |
| CVE-2026-34070 | LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in lan... | Not Provided | 2026-03-31 | 2026-03-31 |
| CVE-2026-33936 | The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Ellipti... | Not Provided | 2026-03-27 | 2026-04-01 |
| CVE-2026-33895 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0... | Not Provided | 2026-03-27 | 2026-03-31 |