Vulnerabilities
Vulnerable Software
Security Vulnerabilities
Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
9.1
EPSS Score
0.006
Published
2026-09-03
Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.
CVSS Score
8.5
EPSS Score
0.003
Published
2026-09-03
Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network.
CVSS Score
8.5
EPSS Score
0.004
Published
2026-09-03
There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated data structure. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
CVSS Score
8.5
EPSS Score
0.001
Published
2026-09-03
There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read a few bytes past the end of an allocated heap buffer during file handling.  Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
CVSS Score
8.5
EPSS Score
0.001
Published
2026-09-03
There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read outside the bounds of an allocated data structure.  Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
CVSS Score
8.6
EPSS Score
0.001
Published
2026-09-03
There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read a past the end of an allocated heap buffer during string conversion.  Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
CVSS Score
8.5
EPSS Score
0.001
Published
2026-09-03
There is an out-of-bounds write vulnerability in DASYLab due to lack of proper validation of user-supplied data. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
CVSS Score
8.5
EPSS Score
0.001
Published
2026-09-03
There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated heap. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
CVSS Score
8.5
EPSS Score
0.001
Published
2026-09-03
IBM Netezza Software 11.3.0.3 through Interim Fix 002 has credentials that are hardcoded in the application source code, allowing unauthorized access to the container registry. The exposed secret enables attackers to pull private container images, potentially revealing proprietary code, configuration details, and other sensitive information.
CVSS Score
7.5
EPSS Score
0.002
Published
2026-09-03


Contact Us

Shodan ® - All rights reserved