Vulnerabilities
Vulnerable Software
Security Vulnerabilities
IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a stored cross-site scripting vulnerability in the Playground chat interface.
CVSS Score
6.1
EPSS Score
0.002
Published
2026-09-04
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 SAP Adapter is vulnerable to an XML external entity (XXE) attack.
CVSS Score
7.7
EPSS Score
0.003
Published
2026-09-04
Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
9.3
EPSS Score
0.003
Published
2026-09-03
Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
9.1
EPSS Score
0.006
Published
2026-09-03
Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.
CVSS Score
8.5
EPSS Score
0.003
Published
2026-09-03
IBM Netezza Software 11.3.0.3 through Interim Fix 002 has credentials that are hardcoded in the application source code, allowing unauthorized access to the container registry. The exposed secret enables attackers to pull private container images, potentially revealing proprietary code, configuration details, and other sensitive information.
CVSS Score
7.5
EPSS Score
0.002
Published
2026-09-03
IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.
CVSS Score
5.9
EPSS Score
0.001
Published
2026-09-03
IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.
CVSS Score
5.3
EPSS Score
0.002
Published
2026-09-03
IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.
CVSS Score
5.3
EPSS Score
0.001
Published
2026-09-03
IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This omission may allow a remote attacker to exploit misconfigurations or naming collisions to redirect application requests to an unintended S3 bucket under their control.
CVSS Score
6.5
EPSS Score
0.002
Published
2026-09-03


Contact Us

Shodan ® - All rights reserved