Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.
CVSSv3.1 8.8 (HIGH)
CWECWE 94TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 18:20Z
HIGH
CVE-2026-77907 — Heap: Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over
Animate is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
CVSSv3.1 8.2 (HIGH)
CWECWE 94VNDAnimateTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
5d ago
2026-09-08 18:20Z
HIGH
CVE-2026-73028 — SQL: Improper access control in SQL Server allows an authorized attacker to elevate privileges over