Vulnerabilities
Vulnerable Software
Security Vulnerabilities
Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
9.0
EPSS Score
0.004
Published
2026-09-17
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
10.0
EPSS Score
0.006
Published
2026-09-17
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
9.3
EPSS Score
0.005
Published
2026-09-17
Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
10.0
EPSS Score
0.008
Published
2026-09-17
Azure Arc Elevation of Privilege Vulnerability
CVSS Score
10.0
EPSS Score
0.005
Published
2026-09-17
Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network.
CVSS Score
8.6
EPSS Score
0.005
Published
2026-09-17
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.
CVSS Score
6.1
EPSS Score
0.004
Published
2026-09-17
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to versions 3.0.16.0 and 3.1.11.0, processing a crafted BMP file through oiiotool or an application linked to OpenImageIO can reach BMP palette handling in src/bmp.imageio/bmpinput.cpp with an empty color table. BmpInput::read_native_scanline then performs an invalid palette read while decoding an RLE-compressed scanline, causing a process crash and denial of service. This issue is fixed in versions 3.0.16.0 and 3.1.11.0.
CVSS Score
5.5
EPSS Score
0.002
Published
2026-09-17
Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
CVSS Score
4.3
EPSS Score
0.003
Published
2026-09-17
A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects to can cause the driver to write uncontrolled data outside the bounds of a heap allocation while processing incoming encrypted traffic after the TLS handshake completes. No authentication or user interaction is required, because the affected processing occurs before any application-level authentication completes. Triggering this issue may lead to memory corruption in the client process, disclosure of adjacent heap memory, or termination of the process.
CVSS Score
9.2
EPSS Score
0.005
Published
2026-09-17


Contact Us

Shodan ® - All rights reserved