Export limit exceeded: 401101 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (511 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-69855 | 1 Microsoft | 2 Azure Copilot, Microsoft Copilot In Azure | 2026-09-08 | 7.7 High |
| Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network. | ||||
| CVE-2026-83711 | 1 Microsoft | 2 Azure Active Directory B2c, Entra Id | 2026-09-05 | 10 Critical |
| Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-70352 | 1 Microsoft | 1 Azure Ai Language Authoring | 2026-09-05 | 10 Critical |
| Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-69502 | 1 Microsoft | 1 Azure Sql Database | 2026-09-04 | 10 Critical |
| Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-69419 | 1 Microsoft | 1 Azure Data Manager For Energy | 2026-09-04 | 8.5 High |
| Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network. | ||||
| CVE-2026-69555 | 1 Microsoft | 1 Azure Arc | 2026-08-29 | 10 Critical |
| Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-69543 | 1 Microsoft | 2 Azure Virtual Machine, Azure Virtual Machines | 2026-08-26 | 8.5 High |
| Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-69519 | 1 Microsoft | 1 Azure Stack Hci | 2026-08-25 | 8.6 High |
| Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-65770 | 1 Microsoft | 1 Azure Managed Instance For Apache Cassandra | 2026-08-25 | 10 Critical |
| Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network. | ||||
| CVE-2026-65816 | 1 Microsoft | 1 Azure Web Apps | 2026-08-24 | 10 Critical |
| Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-69400 | 1 Microsoft | 1 Azure Logic Apps | 2026-08-24 | 9.6 Critical |
| Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-68789 | 1 Microsoft | 1 Azure Sql Database | 2026-08-24 | 9.9 Critical |
| Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-68782 | 1 Microsoft | 1 Azure Sql Database | 2026-08-24 | 9.9 Critical |
| Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-66309 | 1 Microsoft | 1 Azure Sql Database | 2026-08-24 | 9.1 Critical |
| Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | ||||
| CVE-2026-66800 | 1 Microsoft | 1 Azure Data Factory | 2026-08-24 | 8.6 High |
| Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network. | ||||
| CVE-2026-62834 | 1 Microsoft | 1 Azure Data Factory | 2026-08-24 | 9.3 Critical |
| Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2026-48567 | 1 Microsoft | 2 .azure Horizondb, Azure Horizondb | 2026-08-24 | 10 Critical |
| Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network. | ||||
| CVE-2021-27080 | 1 Microsoft | 1 Azure Sphere | 2026-08-19 | 9.3 Critical |
| Azure Sphere Unsigned Code Execution Vulnerability | ||||
| CVE-2021-27075 | 1 Microsoft | 6 Azure Container Instance, Azure Container Instances, Azure Container Registry and 3 more | 2026-08-19 | 6.8 Medium |
| Azure Virtual Machine Information Disclosure Vulnerability | ||||
| CVE-2021-27074 | 1 Microsoft | 1 Azure Sphere | 2026-08-19 | 6.2 Medium |
| Azure Sphere Unsigned Code Execution Vulnerability | ||||