Vulnerabilities
Vulnerable Software
Security Vulnerabilities
Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-bounds heap read in the tagged integer fast-path deserializer, potentially causing information disclosure or denial of service. Users are recommended to upgrade to Apache Fory 1.5.0, which fixes this issue. Applications that do not use Apache Fory C++ or do not use tagged integer fields are not affected.
CVSS Score
9.1
EPSS Score
0.006
Published
2026-08-07
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
CVSS Score
9.6
EPSS Score
0.005
Published
2026-08-07
Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network.
CVSS Score
9.1
EPSS Score
0.005
Published
2026-08-07
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
10.0
EPSS Score
0.004
Published
2026-08-07
Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network.
CVSS Score
8.8
EPSS Score
0.004
Published
2026-08-07
Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
9.8
EPSS Score
0.003
Published
2026-08-07
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
CVSS Score
9.6
EPSS Score
0.004
Published
2026-08-07
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.
CVSS Score
7.5
EPSS Score
0.003
Published
2026-08-07
Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
10.0
EPSS Score
0.004
Published
2026-08-07
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
CVSS Score
9.9
EPSS Score
0.004
Published
2026-08-07


Contact Us

Shodan ® - All rights reserved