Vulnerabilities
Vulnerable Software
Security Vulnerabilities
Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network.
CVSS Score
8.8
EPSS Score
0.001
Published
2026-05-12
Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
CVSS Score
6.3
EPSS Score
0.0
Published
2026-05-12
Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthorized attacker to execute code locally.
CVSS Score
7.8
EPSS Score
0.0
Published
2026-05-12
Use after free in Data Deduplication allows an authorized attacker to elevate privileges locally.
CVSS Score
7.8
EPSS Score
0.0
Published
2026-05-12
Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network.
CVSS Score
9.8
EPSS Score
0.0
Published
2026-05-12
Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
CVSS Score
6.7
EPSS Score
0.003
Published
2026-05-12
Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally.
CVSS Score
4.4
EPSS Score
0.0
Published
2026-05-12
Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally.
CVSS Score
7.1
EPSS Score
0.0
Published
2026-05-12
Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally.
CVSS Score
7.1
EPSS Score
0.0
Published
2026-05-12
Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
9.1
EPSS Score
0.002
Published
2026-05-12


Contact Us

Shodan ® - All rights reserved