Vulnerabilities
Vulnerable Software
Security Vulnerabilities
Azure Entra ID Elevation of Privilege Vulnerability
CVSS Score
9.6
EPSS Score
0.001
Published
2025-10-09
Azure Entra ID Elevation of Privilege Vulnerability
CVSS Score
9.8
EPSS Score
0.001
Published
2025-10-09
Azure PlayFab Elevation of Privilege Vulnerability
CVSS Score
8.8
EPSS Score
0.001
Published
2025-10-09
M365 Copilot Spoofing Vulnerability
CVSS Score
6.5
EPSS Score
0.001
Published
2025-10-09
Redis Enterprise Elevation of Privilege Vulnerability
CVSS Score
8.7
EPSS Score
0.001
Published
2025-10-09
Copilot Spoofing Vulnerability
CVSS Score
6.5
EPSS Score
0.001
Published
2025-10-09
Newforma Info Exchange (NIX) '/DownloadWeb/hyperlinkredirect.aspx' provides an unauthenticated URL redirect via the 'nhl' parameter.
CVSS Score
4.3
EPSS Score
0.0
Published
2025-10-09
Newforma Info Exchange (NIX) provides a 'Send a File Transfer' feature that allows a remote, authenticated attacker to upload SVG files that contain JavaScript or other content that may be executed or rendered by a web browser using a mobile user agent.
CVSS Score
5.5
EPSS Score
0.0
Published
2025-10-09
Newforma Info Exchange (NIX) '/NPCSRemoteWeb/LegacyIntegrationServices.asmx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can capture the NTLMv2 hash of the user-configured NIX service account.
CVSS Score
5.9
EPSS Score
0.0
Published
2025-10-09
Newforma Info Exchange (NIX) before version 2023.1 by default allows anonymous authentication which allows an unauthenticated attacker to exploit additional vulnerabilities that require authentication.
CVSS Score
5.3
EPSS Score
0.002
Published
2025-10-09


Contact Us

Shodan ® - All rights reserved