Vulnerabilities
Vulnerable Software
Security Vulnerabilities
Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack with AsyncJob storage in the database. This issue affects Apache CloudStack: from 4.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.
CVSS Score
7.5
EPSS Score
0.002
Published
2026-08-21
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's LDAP authentication plugin while listing LDAP providers. LDAP configurations can be listed by any authenticated user with access to the listLdapConfigurations API. By default, this API is available to all default roles. This issue affects Apache CloudStack: from 4.2.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.
CVSS Score
7.5
EPSS Score
0.003
Published
2026-08-21
Improper Privilege Management vulnerability in Apache CloudStack's Two-factor authentication plugin allowing bypass of the two-factor authentication disable flow. This issue affects Apache CloudStack: from 4.18.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or 4.22.1.1 or later, which fixes the issue.
CVSS Score
8.8
EPSS Score
0.003
Published
2026-08-21
This issue was addressed with improved permissions checking. This issue is fixed in watchOS 26.4. An attacker with physical access to a locked Apple Watch may be able to view user contacts.
CVSS Score
2.4
EPSS Score
0.001
Published
2026-08-21
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. Processing a maliciously crafted file may lead to unexpected app termination.
CVSS Score
4.3
EPSS Score
0.002
Published
2026-08-21
Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.
CVSS Score
8.6
EPSS Score
0.006
Published
2026-08-20
Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.
CVSS Score
8.5
EPSS Score
0.003
Published
2026-08-20
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
10.0
EPSS Score
0.004
Published
2026-08-20
Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.
CVSS Score
8.6
EPSS Score
0.005
Published
2026-08-20
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
CVSS Score
10.0
EPSS Score
0.016
Published
2026-08-20


Contact Us

Shodan ® - All rights reserved