Vulnerabilities
Vulnerable Software
Security Vulnerabilities
IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
CVSS Score
7.5
EPSS Score
0.005
Published
2026-09-18
IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.
CVSS Score
8.8
EPSS Score
0.004
Published
2026-09-18
vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the engine by submitting negative token IDs. A single request with a negative token ID triggers a CUDA device-side assertion that poisons the GPU context, causing all subsequent requests to fail until the process restarts.
CVSS Score
8.7
EPSS Score
0.005
Published
2026-09-18
HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system details, as well as manipulate request values to gain unauthorized access to full personal profile data and PII across different organizations.
CVSS Score
9.8
EPSS Score
0.005
Published
2026-09-18
HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send requests to internal systems that are not accessible from the internet.
CVSS Score
9.3
EPSS Score
0.003
Published
2026-09-18
HCL BigFix Service Management is affected by a high-severity Broken Access Control vulnerability, which could allow a low-privileged user to gain unauthorized access to administrative screens and functions reserved for higher-privileged roles.
CVSS Score
8.1
EPSS Score
0.004
Published
2026-09-18
HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject unsanitized malicious scripts that execute in a victim's browser, enabling session hijacking, account takeover, and unauthorized actions on behalf of affected users.
CVSS Score
7.6
EPSS Score
0.002
Published
2026-09-18
Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.
CVSS Score
9.9
EPSS Score
0.008
Published
2026-09-18
Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network.
CVSS Score
7.7
EPSS Score
0.008
Published
2026-09-18
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthorized attacker to perform spoofing over a network.
CVSS Score
8.2
EPSS Score
0.003
Published
2026-09-18


Contact Us

Shodan ® - All rights reserved