CVE Datenbank

Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.

Zurücksetzen
54 CVEs gefunden (Seite 1/1)

CVE-2026-33107 - Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate pr

🏢 Azure 📅 3.4.2026 📊 CVSS: 10.0
10.0

CVE-2026-33105 - Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elev

🏢 Azure 📅 3.4.2026 📊 CVSS: 10.0
10.0

CVE-2026-32213 - Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges ove

🏢 Azure 📅 3.4.2026 📊 CVSS: 10.0
10.0

CVE-2026-32211 - Missing authentication for critical function in Azure MCP Server allows an unauthorized attacker to

🏢 Azure 📅 3.4.2026 📊 CVSS: 9.1
9.1

CVE-2026-32173 - Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information o

🏢 Azure 📅 3.4.2026 📊 CVSS: 8.6
8.6

CVE-2026-26135 - Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an author

🏢 Azure 📅 3.4.2026 📊 CVSS: 9.6
9.6

CVE-2026-34750 - Payload is a free and open source headless content management system. Prior to version 3.78.0 in @pa

🏢 Azure 📅 1.4.2026 📊 CVSS: 6.5
6.5

CVE-2026-34397 - Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From versions 2.0.0

🏢 Azure 📅 1.4.2026 📊 CVSS: 6.3
6.3

CVE-2026-33980 - Azure Data Explorer MCP Server is a Model Context Protocol (MCP) server that enables AI assistants t

🏢 Azure 📅 27.3.2026 📊 CVSS: 8.3
8.3

CVE-2026-33726 - Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to

🏢 Azure 📅 27.3.2026 📊 CVSS: 5.4
5.4

CVE-2026-32169 - Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate p

🏢 Azure 📅 19.3.2026 📊 CVSS: 10.0
10.0

CVE-2026-23659 - Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthori

🏢 Azure 📅 19.3.2026 📊 CVSS: 8.6
8.6

CVE-2026-23658 - Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate priv

🏢 Azure 📅 19.3.2026 📊 CVSS: 8.6
8.6

CVE-2026-2559 - The Post SMTP plugin for WordPress is vulnerable to unauthorized modification of data due to a missi

🏢 Azure 📅 18.3.2026 📊 CVSS: 5.3
5.3

CVE-2026-32268 - The Azure Blob Storage for Craft CMS plugin provides an Azure Blob Storage integration for Craft CMS

🏢 Azure 📅 18.3.2026 📊 CVSS: 0.0
0.0

CVE-2026-31979 - Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Prior to 3.1.0 and

🏢 Azure 📅 11.3.2026 📊 CVSS: 8.8
8.8

CVE-2026-31957 - Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 3.0.0 to befor

🏢 Azure 📅 11.3.2026 📊 CVSS: 10.0
10.0

CVE-2026-31813 - Supabase Auth is a JWT based API for managing users and issuing JWT tokens. Prior to 2.185.0, a vuln

🏢 Azure 📅 11.3.2026 📊 CVSS: 4.8
4.8

CVE-2026-26148 - External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized

🏢 Azure 📅 10.3.2026 📊 CVSS: 8.1
8.1

CVE-2026-26141 - Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.

🏢 Azure 📅 10.3.2026 📊 CVSS: 7.8
7.8

CVE-2026-26121 - Server-side request forgery (ssrf) in Azure IoT Explorer allows an unauthorized attacker to perform

🏢 Azure 📅 10.3.2026 📊 CVSS: 7.5
7.5

CVE-2026-26118 - Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate priv

🏢 Azure 📅 10.3.2026 📊 CVSS: 8.8
8.8

CVE-2026-26117 - Authentication bypass using an alternate path or channel in Azure Windows Virtual Machine Agent allo

🏢 Azure 📅 10.3.2026 📊 CVSS: 7.8
7.8

CVE-2026-23665 - Heap-based buffer overflow in Azure Linux Virtual Machines allows an authorized attacker to elevate

🏢 Azure 📅 10.3.2026 📊 CVSS: 7.8
7.8

CVE-2026-23664 - Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an

🏢 Azure 📅 10.3.2026 📊 CVSS: 7.5
7.5

CVE-2026-23662 - Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker t

🏢 Azure 📅 10.3.2026 📊 CVSS: 7.5
7.5

CVE-2026-23661 - Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacke

🏢 Azure 📅 10.3.2026 📊 CVSS: 7.5
7.5

CVE-2026-23660 - Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevat

🏢 Azure 📅 10.3.2026 📊 CVSS: 7.8
7.8

CVE-2026-26124 - '.../...//' in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.

🏢 Azure 📅 5.3.2026 📊 CVSS: 6.7
6.7

CVE-2026-26122 - Initialization of a resource with an insecure default in Azure Compute Gallery allows an authorized

🏢 Azure 📅 5.3.2026 📊 CVSS: 6.5
6.5

CVE-2026-23651 - Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate priv

🏢 Azure 📅 5.3.2026 📊 CVSS: 6.7
6.7

CVE-2026-3224 - Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server

🏢 Azure 📅 3.3.2026 📊 CVSS: 9.8
9.8

CVE-2026-2628 - The All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login plugin for WordPress is vulnerable to a

🏢 Azure 📅 3.3.2026 📊 CVSS: 9.8
9.8

CVE-2026-27640 - tfplan2md is software for converting Terraform plan JSON files into human-readable Markdown reports.

🏢 Azure 📅 25.2.2026 📊 CVSS: 7.5
7.5

CVE-2026-22048 - StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.12 and 12.0.0.4 with Single Sig

🏢 Azure 📅 18.2.2026 📊 CVSS: 7.1
7.1

CVE-2026-23655 - Cleartext storage of sensitive information in Azure Compute Gallery allows an authorized attacker to

🏢 Azure 📅 10.2.2026 📊 CVSS: 6.5
6.5

CVE-2026-21531 - Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over

🏢 Azure 📅 10.2.2026 📊 CVSS: 9.8
9.8

CVE-2026-21529 - Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsi

🏢 Azure 📅 10.2.2026 📊 CVSS: 5.7
5.7

CVE-2026-21528 - Binding to an unrestricted ip address in Azure IoT Explorer allows an unauthorized attacker to discl

🏢 Azure 📅 10.2.2026 📊 CVSS: 6.5
6.5

CVE-2026-21522 - Improper neutralization of special elements used in a command ('command injection') in Azure Compute

🏢 Azure 📅 10.2.2026 📊 CVSS: 6.7
6.7

CVE-2026-21512 - Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform s

🏢 Azure 📅 10.2.2026 📊 CVSS: 6.5
6.5

CVE-2026-21228 - Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over

🏢 Azure 📅 10.2.2026 📊 CVSS: 8.1
8.1

CVE-2026-24302 - Azure Arc Elevation of Privilege Vulnerability

🏢 Azure 📅 5.2.2026 📊 CVSS: 8.6
8.6

CVE-2026-24300 - Azure Front Door Elevation of Privilege Vulnerability

🏢 Azure 📅 5.2.2026 📊 CVSS: 9.8
9.8

CVE-2026-21532 - Azure Function Information Disclosure Vulnerability

🏢 Azure 📅 5.2.2026 📊 CVSS: 8.2
8.2

CVE-2026-23889 - pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's tarbal

🏢 Azure 📅 26.1.2026 📊 CVSS: 6.5
6.5

CVE-2026-24304 - Improper access control in Azure Resource Manager allows an authorized attacker to elevate privilege

🏢 Azure 📅 23.1.2026 📊 CVSS: 9.9
9.9

CVE-2026-24306 - Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privile

🏢 Azure 📅 22.1.2026 📊 CVSS: 9.8
9.8

CVE-2026-24305 - Azure Entra ID Elevation of Privilege Vulnerability

🏢 Azure 📅 22.1.2026 📊 CVSS: 9.3
9.3

CVE-2026-21524 - Exposure of sensitive information to an unauthorized actor in Azure Data Explorer allows an unauthor

🏢 Azure 📅 22.1.2026 📊 CVSS: 7.4
7.4

CVE-2026-21227 - Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps a

🏢 Azure 📅 22.1.2026 📊 CVSS: 8.2
8.2

CVE-2026-23518 - Fleet is open source device management software. In versions prior to 4.78.3, 4.77.1, 4.76.2, 4.75.2

🏢 Azure 📅 21.1.2026 📊 CVSS: 9.8
9.8

CVE-2026-21226 - Deserialization of untrusted data in Azure Core shared client library for Python allows an authorize

🏢 Azure 📅 13.1.2026 📊 CVSS: 7.5
7.5

CVE-2026-21224 - Stack-based buffer overflow in Azure Connected Machine Agent allows an authorized attacker to elevat

🏢 Azure 📅 13.1.2026 📊 CVSS: 7.8
7.8

🏢 CVE nach Hersteller

Empfohlene Sicherheitstools

Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.