Vulnerabilities
Vulnerable Software
Security Vulnerabilities
HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject unsanitized malicious scripts that execute in a victim's browser, enabling session hijacking, account takeover, and unauthorized actions on behalf of affected users.
CVSS Score
7.6
EPSS Score
0.003
Published
2026-09-18
Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.
CVSS Score
9.9
EPSS Score
0.008
Published
2026-09-18
Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network.
CVSS Score
7.7
EPSS Score
0.008
Published
2026-09-18
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthorized attacker to perform spoofing over a network.
CVSS Score
8.2
EPSS Score
0.003
Published
2026-09-18
Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
10.0
EPSS Score
0.009
Published
2026-09-18
Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
10.0
EPSS Score
0.004
Published
2026-09-18
vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode disaggregated deployments. Remote attackers can submit requests with max_tokens=0 to exhaust decode-worker memory without bound until the worker restarts.
CVSS Score
8.7
EPSS Score
0.008
Published
2026-09-17
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.
CVSS Score
9.9
EPSS Score
0.007
Published
2026-09-17
Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
10.0
EPSS Score
0.007
Published
2026-09-17
Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
7.5
EPSS Score
0.01
Published
2026-09-17


Contact Us

Shodan ® - All rights reserved