Vulnerabilities
Vulnerable Software
Security Vulnerabilities
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
CVSS Score
9.9
EPSS Score
0.005
Published
2026-08-07
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
8.7
EPSS Score
0.004
Published
2026-08-07
'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
CVSS Score
9.9
EPSS Score
0.008
Published
2026-08-07
Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
9.3
EPSS Score
0.005
Published
2026-08-07
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
CVSS Score
9.9
EPSS Score
0.011
Published
2026-08-07
Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.
CVSS Score
9.6
EPSS Score
0.005
Published
2026-08-07
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
10.0
EPSS Score
0.007
Published
2026-08-07
Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network.
CVSS Score
8.8
EPSS Score
0.008
Published
2026-08-07
Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
CVSS Score
9.9
EPSS Score
0.006
Published
2026-08-07
TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability that allows authenticated attackers to cause query-result integrity failures or backend crashes by supplying a crafted Simple8b selector-11 value, which is stored in the signed int16 Arrow dictionary-index type and bypasses index validation checks in bulk text dictionary decompression. Attackers with direct DML access to a non-frozen physical compressed hypertable relation can trigger an out-of-bounds read before the base of the live offsets array through the VectorAgg single-text hashing strategy, resulting in incorrect aggregation output, backend SIGSEGV, or PostgreSQL crash recovery depending on build configuration.
CVSS Score
7.1
EPSS Score
0.004
Published
2026-08-06


Contact Us

Shodan ® - All rights reserved