CVE-2025-24070

CVSS v3 Score
7.0
High

Vulnerability Description

Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.

CVSS:7.3(High)

Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability

CVSS:7.5(High)

A weak authentication vulnerability [CWE-1390] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in device registrat...

CVSS:6.5(Medium)

Microsoft OneDrive for iOS Security Feature Bypass Vulnerability

CVSS:7.5(High)

An authentication bypass vulnerability was found in overt-engine. This flaw allows the creation of users in the system without authentication due to a flaw in the CreateUserSession command.

CVSS:6.5(Medium)

In the goTenna Pro ATAK Plugin there is a vulnerability that makes it possible to inject any custom message with any GID and Callsign using a software defined radio in existing goTenna mesh networks. ...