Vulnerabilities
Vulnerable Software
Security Vulnerabilities
M365 Copilot Spoofing Vulnerability
CVSS Score
6.5
EPSS Score
0.001
Published
2025-10-09
Redis Enterprise Elevation of Privilege Vulnerability
CVSS Score
8.7
EPSS Score
0.001
Published
2025-10-09
Copilot Spoofing Vulnerability
CVSS Score
6.5
EPSS Score
0.001
Published
2025-10-09
Newforma Info Exchange (NIX) '/DownloadWeb/hyperlinkredirect.aspx' provides an unauthenticated URL redirect via the 'nhl' parameter.
CVSS Score
4.3
EPSS Score
0.0
Published
2025-10-09
Newforma Info Exchange (NIX) provides a 'Send a File Transfer' feature that allows a remote, authenticated attacker to upload SVG files that contain JavaScript or other content that may be executed or rendered by a web browser using a mobile user agent.
CVSS Score
5.5
EPSS Score
0.0
Published
2025-10-09
Newforma Info Exchange (NIX) '/NPCSRemoteWeb/LegacyIntegrationServices.asmx' allows a remote, unauthenticated attacker to cause NIX to make an SMB connection to an attacker-controlled system. The attacker can capture the NTLMv2 hash of the user-configured NIX service account.
CVSS Score
5.9
EPSS Score
0.0
Published
2025-10-09
Newforma Info Exchange (NIX) before version 2023.1 by default allows anonymous authentication which allows an unauthenticated attacker to exploit additional vulnerabilities that require authentication.
CVSS Score
5.3
EPSS Score
0.001
Published
2025-10-09
A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26. An app may bypass Gatekeeper checks.
CVSS Score
5.5
EPSS Score
0.0
Published
2025-10-09
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthorized attacker to perform spoofing over a network.
CVSS Score
9.3
EPSS Score
0.001
Published
2025-10-09
Newforma Info Exchange (NIX) uses a hard-coded key to encrypt certain query parameters. Some encrypted parameter values can specify paths to download files, potentially bypassing authentication and authorization, for example, the 'qs' parameter used in '/DownloadWeb/download.aspx'. This key is shared across NIX installations. NIX 2023.3 and 2024.1 limit the use of hard-coded keys.
CVSS Score
5.3
EPSS Score
0.001
Published
2025-10-09


Contact Us

Shodan ® - All rights reserved