Vulnerabilities
Vulnerable Software
Security Vulnerabilities
Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
10.0
EPSS Score
0.004
Published
2026-09-17
Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
9.0
EPSS Score
0.004
Published
2026-09-17
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
10.0
EPSS Score
0.006
Published
2026-09-17
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
9.3
EPSS Score
0.005
Published
2026-09-17
Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
10.0
EPSS Score
0.008
Published
2026-09-17
Azure Arc Elevation of Privilege Vulnerability
CVSS Score
10.0
EPSS Score
0.005
Published
2026-09-17
Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network.
CVSS Score
8.6
EPSS Score
0.005
Published
2026-09-17
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.
CVSS Score
6.1
EPSS Score
0.004
Published
2026-09-17
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to versions 3.0.16.0 and 3.1.11.0, processing a crafted BMP file through oiiotool or an application linked to OpenImageIO can reach BMP palette handling in src/bmp.imageio/bmpinput.cpp with an empty color table. BmpInput::read_native_scanline then performs an invalid palette read while decoding an RLE-compressed scanline, causing a process crash and denial of service. This issue is fixed in versions 3.0.16.0 and 3.1.11.0.
CVSS Score
5.5
EPSS Score
0.002
Published
2026-09-17
Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)
CVSS Score
4.3
EPSS Score
0.003
Published
2026-09-17


Contact Us

Shodan ® - All rights reserved