Vulnerabilities
Vulnerable Software
Security Vulnerabilities
Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
CVSS Score
8.5
EPSS Score
0.004
Published
2026-09-03
Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
9.3
EPSS Score
0.003
Published
2026-09-03
Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
9.1
EPSS Score
0.006
Published
2026-09-03
Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.
CVSS Score
8.5
EPSS Score
0.003
Published
2026-09-03
Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network.
CVSS Score
8.5
EPSS Score
0.004
Published
2026-09-03
There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated data structure. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
CVSS Score
8.5
EPSS Score
0.001
Published
2026-09-03
There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read a few bytes past the end of an allocated heap buffer during file handling.  Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
CVSS Score
8.5
EPSS Score
0.001
Published
2026-09-03
There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read outside the bounds of an allocated data structure.  Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
CVSS Score
8.6
EPSS Score
0.001
Published
2026-09-03
There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read a past the end of an allocated heap buffer during string conversion.  Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
CVSS Score
8.5
EPSS Score
0.001
Published
2026-09-03
There is an out-of-bounds write vulnerability in DASYLab due to lack of proper validation of user-supplied data. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
CVSS Score
8.5
EPSS Score
0.001
Published
2026-09-03


Contact Us

Shodan ® - All rights reserved