Vulnerabilities
Vulnerable Software
Security Vulnerabilities
Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.
CVSS Score
8.8
EPSS Score
0.005
Published
2026-07-14
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
CVSS Score
7.5
EPSS Score
0.01
Published
2026-07-14
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVSS Score
8.8
EPSS Score
0.007
Published
2026-07-14
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVSS Score
8.1
EPSS Score
0.002
Published
2026-07-14
Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally.
CVSS Score
7.8
EPSS Score
0.003
Published
2026-07-14
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Yaml\Parser resolved YAML collection aliases recursively, allowing a small untrusted YAML input to expand into a multi-gigabyte structure and exhaust memory. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
CVSS Score
8.7
EPSS Score
0.008
Published
2026-07-14
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Yaml\Parser::cleanup() used regular expressions with overlapping quantifiers for YAML directive, comment, and document marker cleanup, allowing crafted input to make parsing hang for an arbitrarily long time. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
CVSS Score
8.7
EPSS Score
0.008
Published
2026-07-14
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, UrlAttributeSanitizer::getSupportedAttributes() omits URL-valued attributes including action, formaction, poster, and cite, so configurations that admit those attributes can leave javascript: URIs unsanitized and enable XSS when the resulting HTML is rendered or a victim submits a form or clicks a button. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.
CVSS Score
2.1
EPSS Score
0.003
Published
2026-07-14
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, the Mailjet mailer bridge and LOX24 notifier bridge webhook parsers received configured webhook secrets but did not verify them, allowing unauthenticated POST requests to inject forged Mailjet and LOX24 event payloads. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.
CVSS Score
6.9
EPSS Score
0.003
Published
2026-07-14
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, MailtrapRequestParser::doParse() received the configured webhook secret but ignored the X-Mt-Signature HMAC header, allowing unauthenticated POST requests to inject forged Mailtrap delivery, bounce, open, click, or spam events. This issue is fixed in versions 7.4.12 and 8.0.12.
CVSS Score
6.9
EPSS Score
0.002
Published
2026-07-14


Contact Us

Shodan ® - All rights reserved