Search Results (356 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-21638 1 Microsoft 1 Azure Ipam 2025-06-03 9.1 Critical
Azure IPAM (IP Address Management) is a lightweight solution developed on top of the Azure platform designed to help Azure customers manage their IP Address space easily and effectively. By design there is no write access to customers' Azure environments as the Service Principal used is only assigned the Reader role at the root Management Group level. Until recently, the solution lacked the validation of the passed in authentication token which may result in attacker impersonating any privileged user to access data stored within the IPAM instance and subsequently from Azure, causing an elevation of privilege. This vulnerability has been patched in version 3.0.0.
CVE-2022-35772 1 Microsoft 1 Azure Site Recovery Vmware To Azure 2025-05-29 7.2 High
Azure Site Recovery Remote Code Execution Vulnerability
CVE-2022-35782 1 Microsoft 1 Azure Site Recovery Vmware To Azure 2025-05-29 6.5 Medium
Azure Site Recovery Elevation of Privilege Vulnerability
CVE-2022-35781 1 Microsoft 1 Azure Site Recovery Vmware To Azure 2025-05-29 6.5 Medium
Azure Site Recovery Elevation of Privilege Vulnerability
CVE-2022-35780 1 Microsoft 1 Azure Site Recovery Vmware To Azure 2025-05-29 6.5 Medium
Azure Site Recovery Elevation of Privilege Vulnerability
CVE-2022-35779 1 Microsoft 1 Azure Real Time Operating System Guix Studio 2025-05-29 7.8 High
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
CVE-2022-35776 1 Microsoft 1 Azure Site Recovery Vmware To Azure 2025-05-29 6.2 Medium
Azure Site Recovery Denial of Service Vulnerability
CVE-2022-35775 1 Microsoft 1 Azure Site Recovery Vmware To Azure 2025-05-29 6.5 Medium
Azure Site Recovery Elevation of Privilege Vulnerability
CVE-2022-35774 1 Microsoft 1 Azure Site Recovery Vmware To Azure 2025-05-29 4.9 Medium
Azure Site Recovery Elevation of Privilege Vulnerability
CVE-2022-35773 1 Microsoft 1 Azure Real Time Operating System Guix Studio 2025-05-29 7.8 High
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
CVE-2023-48695 1 Microsoft 1 Azure Rtos Usbx 2025-05-29 7.2 High
Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. An attacker can cause remote code execution due to out of bounds write vulnerabilities in Azure RTOS USBX. The affected components include functions/processes in host and device classes, related to CDC ECM and RNDIS in RTOS v6.2.1 and below. The fixes have been included in USBX release 6.3.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVE-2019-0996 1 Microsoft 1 Azure Devops Server 2025-05-20 N/A
A spoofing vulnerability exists in Azure DevOps Server when it improperly handles requests to authorize applications, resulting in a cross-site request forgery. An attacker who successfully exploited this vulnerability could bypass OAuth protections and register an application on behalf of the targeted user. To exploit this vulnerability, an attacker would need to create a page specifically designed to cause a cross-site request. The attacker would then need to convince a targeted user to click a link to the malicious page. The update addresses the vulnerability by modifying how Azure DevOps Server protects application registration requests.
CVE-2024-21403 1 Microsoft 1 Azure Kubernetes Service 2025-05-09 9 Critical
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
CVE-2024-20667 1 Microsoft 1 Azure Devops Server 2025-05-09 7.5 High
Azure DevOps Server Remote Code Execution Vulnerability
CVE-2024-21376 1 Microsoft 1 Azure Kubernetes Service 2025-05-08 9 Critical
Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability
CVE-2024-38092 1 Microsoft 1 Azure Cyclecloud 2025-05-05 8.8 High
Azure CycleCloud Elevation of Privilege Vulnerability
CVE-2024-35267 1 Microsoft 1 Azure Devops Server 2025-05-05 7.6 High
Azure DevOps Server Spoofing Vulnerability
CVE-2024-35266 1 Microsoft 1 Azure Devops Server 2025-05-05 7.6 High
Azure DevOps Server Spoofing Vulnerability
CVE-2024-35261 1 Microsoft 1 Azure Network Watcher Agent 2025-05-05 7.8 High
Azure Network Watcher VM Extension Elevation of Privilege Vulnerability
CVE-2024-38086 1 Microsoft 1 Azure Kinect Software Development Kit 2025-05-05 6.4 Medium
Azure Kinect SDK Remote Code Execution Vulnerability