Search Results (367 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-0996 1 Microsoft 1 Azure Devops Server 2025-05-20 N/A
A spoofing vulnerability exists in Azure DevOps Server when it improperly handles requests to authorize applications, resulting in a cross-site request forgery. An attacker who successfully exploited this vulnerability could bypass OAuth protections and register an application on behalf of the targeted user. To exploit this vulnerability, an attacker would need to create a page specifically designed to cause a cross-site request. The attacker would then need to convince a targeted user to click a link to the malicious page. The update addresses the vulnerability by modifying how Azure DevOps Server protects application registration requests.
CVE-2024-21403 1 Microsoft 1 Azure Kubernetes Service 2025-05-09 9 Critical
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
CVE-2024-20667 1 Microsoft 1 Azure Devops Server 2025-05-09 7.5 High
Azure DevOps Server Remote Code Execution Vulnerability
CVE-2024-21376 1 Microsoft 1 Azure Kubernetes Service 2025-05-08 9 Critical
Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability
CVE-2024-20676 1 Microsoft 1 Azure Storage Mover 2025-05-03 8 High
Azure Storage Mover Remote Code Execution Vulnerability
CVE-2024-21397 1 Microsoft 1 Azure File Sync 2025-05-03 5.3 Medium
Microsoft Azure File Sync Elevation of Privilege Vulnerability
CVE-2024-21364 1 Microsoft 1 Azure Site Recovery 2025-05-03 9.3 Critical
Microsoft Azure Site Recovery Elevation of Privilege Vulnerability
CVE-2024-20679 1 Microsoft 1 Azure Stack Hub 2025-05-03 6.5 Medium
Azure Stack Hub Spoofing Vulnerability
CVE-2024-21381 1 Microsoft 1 Azure Active Directory 2025-05-03 6.8 Medium
Microsoft Azure Active Directory B2C Spoofing Vulnerability
CVE-2024-21329 1 Microsoft 1 Azure Connected Machine Agent 2025-05-03 7.3 High
Azure Connected Machine Agent Elevation of Privilege Vulnerability
CVE-2024-21330 1 Microsoft 8 Azure Automation, Azure Automation Update Management, Azure Security Center and 5 more 2025-05-03 7.8 High
Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability
CVE-2024-26203 1 Microsoft 1 Azure Data Studio 2025-05-03 7.3 High
Azure Data Studio Elevation of Privilege Vulnerability
CVE-2024-21421 1 Microsoft 1 Azure Software Development Kit 2025-05-03 7.5 High
Azure SDK Spoofing Vulnerability
CVE-2024-29993 1 Microsoft 1 Azure Cyclecloud 2025-05-03 8.8 High
Azure CycleCloud Elevation of Privilege Vulnerability
CVE-2024-29992 1 Microsoft 1 Azure Identity Library For .net 2025-05-03 5.5 Medium
Azure Identity Library for .NET Information Disclosure Vulnerability
CVE-2024-29989 1 Microsoft 2 Azure Monitor, Azure Monitor Agent 2025-05-03 8.4 High
Azure Monitor Agent Elevation of Privilege Vulnerability
CVE-2024-28917 1 Microsoft 7 Azure Arc Extension Microsoft.azstackhci.operator, Azure Arc Extension Microsoft.azure.hybridnetwork, Azure Arc Extension Microsoft.azurekeyvaultsecretsprovider and 4 more 2025-05-03 6.2 Medium
Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability
CVE-2024-29990 1 Microsoft 1 Azure Kubernetes Service Confidential Containers 2025-05-03 9 Critical
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
CVE-2024-20685 1 Microsoft 1 Azure Private 5g Core 2025-05-03 5.9 Medium
Azure Private 5G Core Denial of Service Vulnerability
CVE-2024-29063 1 Microsoft 1 Azure Ai Search 2025-05-03 7.3 High
Azure AI Search Information Disclosure Vulnerability