Vulnerabilities
Vulnerable Software
Security Vulnerabilities
IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.
CVSS Score
8.8
EPSS Score
0.004
Published
2026-09-18
vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the engine by submitting negative token IDs. A single request with a negative token ID triggers a CUDA device-side assertion that poisons the GPU context, causing all subsequent requests to fail until the process restarts.
CVSS Score
8.7
EPSS Score
0.005
Published
2026-09-18
Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.
CVSS Score
9.9
EPSS Score
0.008
Published
2026-09-18
Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network.
CVSS Score
7.7
EPSS Score
0.009
Published
2026-09-18
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthorized attacker to perform spoofing over a network.
CVSS Score
8.2
EPSS Score
0.003
Published
2026-09-18
Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
10.0
EPSS Score
0.009
Published
2026-09-18
vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode disaggregated deployments. Remote attackers can submit requests with max_tokens=0 to exhaust decode-worker memory without bound until the worker restarts.
CVSS Score
8.7
EPSS Score
0.008
Published
2026-09-17
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.
CVSS Score
9.9
EPSS Score
0.007
Published
2026-09-17
Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
10.0
EPSS Score
0.007
Published
2026-09-17
Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
7.5
EPSS Score
0.01
Published
2026-09-17


Contact Us

Shodan ® - All rights reserved