Lucene search

K

Azure Security Vulnerabilities

cve
cve

CVE-2021-38647

Open Management Infrastructure Remote Code Execution...

9.8CVSS

7.1AI Score

0.975EPSS

2021-09-15 12:15 PM
1045
In Wild
8
cve
cve

CVE-2021-38648

Open Management Infrastructure Elevation of Privilege...

7.8CVSS

8.4AI Score

0.963EPSS

2021-09-15 12:15 PM
932
In Wild
cve
cve

CVE-2021-38649

Open Management Infrastructure Elevation of Privilege...

7CVSS

8AI Score

0.001EPSS

2021-09-15 12:15 PM
902
In Wild
cve
cve

CVE-2021-38645

Open Management Infrastructure Elevation of Privilege...

7.8CVSS

8.4AI Score

0.001EPSS

2021-09-15 12:15 PM
941
In Wild
cve
cve

CVE-2021-36956

Azure Sphere Information Disclosure...

4.4CVSS

5.7AI Score

0.0004EPSS

2021-09-15 12:15 PM
45
cve
cve

CVE-2021-21679

Jenkins Azure AD Plugin 179.vf6841393099e and earlier allows attackers to craft URLs that would bypass the CSRF protection of any target URL in...

8.8CVSS

8.6AI Score

0.001EPSS

2021-08-31 02:15 PM
41
cve
cve

CVE-2021-36943

Azure CycleCloud Elevation of Privilege...

4CVSS

5.1AI Score

0.001EPSS

2021-08-12 06:15 PM
72
5
cve
cve

CVE-2021-36949

Microsoft Azure Active Directory Connect Authentication Bypass...

7.1CVSS

6.7AI Score

0.0004EPSS

2021-08-12 06:15 PM
112
3
cve
cve

CVE-2021-33762

Azure CycleCloud Elevation of Privilege...

7CVSS

7AI Score

0.0004EPSS

2021-08-12 06:15 PM
76
6
cve
cve

CVE-2021-26430

Azure Sphere Denial of Service...

6CVSS

6.2AI Score

0.0004EPSS

2021-08-12 06:15 PM
61
cve
cve

CVE-2021-26429

Azure Sphere Elevation of Privilege...

7.7CVSS

7.5AI Score

0.0004EPSS

2021-08-12 06:15 PM
66
2
cve
cve

CVE-2021-26428

Azure Sphere Information Disclosure...

4.4CVSS

5.2AI Score

0.0004EPSS

2021-08-12 06:15 PM
60
4
cve
cve

CVE-2021-21505

Dell EMC Integrated System for Microsoft Azure Stack Hub, versions 1906 – 2011, contain an undocumented default iDRAC account. A remote unauthenticated attacker, with the knowledge of the default credentials, could potentially exploit this to log in to the system to gain root...

9.8CVSS

9.5AI Score

0.005EPSS

2021-05-06 01:15 PM
25
4
cve
cve

CVE-2021-28460

Azure Sphere Unsigned Code Execution...

8.1CVSS

8.1AI Score

0.001EPSS

2021-04-13 08:15 PM
52
4
cve
cve

CVE-2021-28459

Azure DevOps Server Spoofing...

6.1CVSS

6.4AI Score

0.004EPSS

2021-04-13 08:15 PM
88
4
cve
cve

CVE-2021-28458

Azure ms-rest-nodeauth Library Elevation of Privilege...

7.8CVSS

7.7AI Score

0.0004EPSS

2021-04-13 08:15 PM
52
4
cve
cve

CVE-2021-27067

Azure DevOps Server and Team Foundation Server Information Disclosure...

6.5CVSS

6.3AI Score

0.014EPSS

2021-04-13 08:15 PM
63
3
cve
cve

CVE-2021-27075

Azure Virtual Machine Information Disclosure...

6.8CVSS

6.9AI Score

0.0004EPSS

2021-03-11 04:15 PM
49
15
cve
cve

CVE-2021-27080

Azure Sphere Unsigned Code Execution...

9.3CVSS

9.3AI Score

0.001EPSS

2021-03-11 04:15 PM
46
7
cve
cve

CVE-2021-27074

Azure Sphere Unsigned Code Execution...

6.2CVSS

6.6AI Score

0.002EPSS

2021-03-11 04:15 PM
46
7
cve
cve

CVE-2021-24109

Microsoft Azure Kubernetes Service Elevation of Privilege...

6.8CVSS

6.6AI Score

0.002EPSS

2021-02-25 11:15 PM
47
4
cve
cve

CVE-2021-24087

Azure IoT CLI extension Elevation of Privilege...

7CVSS

6.8AI Score

0.0004EPSS

2021-02-25 11:15 PM
52
cve
cve

CVE-2020-8567

Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass objects to write to arbitrary file paths on the host filesystem, including...

6.5CVSS

6.4AI Score

0.001EPSS

2021-01-21 05:15 PM
38
2
cve
cve

CVE-2021-1677

Azure Active Directory Pod Identity Spoofing...

5.5CVSS

5.3AI Score

0.001EPSS

2021-01-12 08:15 PM
57
1
cve
cve

CVE-2020-35608

A code execution vulnerability exists in the normal world’s signed code execution functionality of Microsoft Azure Sphere 20.07. A specially crafted AF_PACKET socket can cause a process to create an executable memory mapping with controllable content. An attacker can execute a shellcode that uses.....

7.8CVSS

7.7AI Score

0.001EPSS

2020-12-22 08:15 PM
52
3
cve
cve

CVE-2020-35609

A denial-of-service vulnerability exists in the asynchronous ioctl functionality of Microsoft Azure Sphere 20.05. A sequence of specially crafted ioctl calls can cause a denial of service. An attacker can write shellcode to trigger this...

5.5CVSS

5.3AI Score

0.0004EPSS

2020-12-22 08:15 PM
49
3
cve
cve

CVE-2020-17145

Azure DevOps Server and Team Foundation Services Spoofing...

5.4CVSS

6AI Score

0.001EPSS

2020-12-10 12:15 AM
69
cve
cve

CVE-2020-17135

Azure DevOps Server Spoofing...

6.4CVSS

5.9AI Score

0.001EPSS

2020-12-10 12:15 AM
65
cve
cve

CVE-2020-17002

Azure SDK for C Security Feature Bypass...

7.4CVSS

7.3AI Score

0.002EPSS

2020-12-10 12:15 AM
171
2
cve
cve

CVE-2020-16971

Azure SDK for Java Security Feature Bypass...

7.4CVSS

7.4AI Score

0.002EPSS

2020-12-10 12:15 AM
60
cve
cve

CVE-2020-1325

Azure DevOps Server and Team Foundation Services Spoofing...

5.4CVSS

6AI Score

0.001EPSS

2020-11-11 07:15 AM
60
cve
cve

CVE-2020-16994

Azure Sphere Unsigned Code Execution...

7.3CVSS

7.4AI Score

0.001EPSS

2020-11-11 07:15 AM
42
cve
cve

CVE-2020-16989

Azure Sphere Elevation of Privilege...

5.4CVSS

6.2AI Score

0.0004EPSS

2020-11-11 07:15 AM
44
cve
cve

CVE-2020-16993

Azure Sphere Elevation of Privilege...

5.4CVSS

5.9AI Score

0.001EPSS

2020-11-11 07:15 AM
42
cve
cve

CVE-2020-16991

Azure Sphere Unsigned Code Execution...

7.3CVSS

7.4AI Score

0.001EPSS

2020-11-11 07:15 AM
47
cve
cve

CVE-2020-16992

Azure Sphere Elevation of Privilege...

7.5CVSS

7.7AI Score

0.001EPSS

2020-11-11 07:15 AM
46
cve
cve

CVE-2020-16990

Azure Sphere Information Disclosure...

6.2CVSS

6.3AI Score

0.001EPSS

2020-11-11 07:15 AM
55
cve
cve

CVE-2020-16988

Azure Sphere Elevation of Privilege...

6.9CVSS

7.2AI Score

0.0004EPSS

2020-11-11 07:15 AM
46
cve
cve

CVE-2020-16984

Azure Sphere Unsigned Code Execution...

7.3CVSS

7.4AI Score

0.001EPSS

2020-11-11 07:15 AM
49
cve
cve

CVE-2020-16987

Azure Sphere Unsigned Code Execution...

7.3CVSS

7.4AI Score

0.004EPSS

2020-11-11 07:15 AM
44
cve
cve

CVE-2020-16981

Azure Sphere Elevation of Privilege...

6.1CVSS

6.7AI Score

0.0004EPSS

2020-11-11 07:15 AM
50
cve
cve

CVE-2020-16982

Azure Sphere Unsigned Code Execution...

6.1CVSS

6.7AI Score

0.002EPSS

2020-11-11 07:15 AM
51
cve
cve

CVE-2020-16983

Azure Sphere Tampering...

5.7CVSS

6.2AI Score

0.0004EPSS

2020-11-11 07:15 AM
43
cve
cve

CVE-2020-16970

Azure Sphere Unsigned Code Execution...

8.1CVSS

8.1AI Score

0.002EPSS

2020-11-11 07:15 AM
50
cve
cve

CVE-2020-16985

Azure Sphere Information Disclosure...

6.2CVSS

6.4AI Score

0.002EPSS

2020-11-11 07:15 AM
47
cve
cve

CVE-2020-16986

Azure Sphere Denial of Service...

6.2CVSS

6.5AI Score

0.001EPSS

2020-11-11 07:15 AM
52
cve
cve

CVE-2020-2313

A missing permission check in Jenkins Azure Key Vault Plugin 2.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in...

4.3CVSS

4.4AI Score

0.001EPSS

2020-11-04 03:15 PM
37
cve
cve

CVE-2020-16904

An elevation of privilege vulnerability exists in the way Azure Functions validate access keys. An unauthenticated attacker who successfully exploited this vulnerability could invoke an HTTP Function without proper authorization. This security update addresses the vulnerability by correctly...

5.3CVSS

6AI Score

0.002EPSS

2020-10-16 11:15 PM
48
cve
cve

CVE-2020-26511

The wpo365-login plugin before v11.7 for WordPress allows use of a symmetric algorithm to decrypt a JWT token. This leads to authentication...

7.5CVSS

7.6AI Score

0.001EPSS

2020-10-02 05:15 AM
36
cve
cve

CVE-2020-1416

An elevation of privilege vulnerability exists in Visual Studio and Visual Studio Code when they load software dependencies, aka 'Visual Studio and Visual Studio Code Elevation of Privilege...

8.8CVSS

8.7AI Score

0.006EPSS

2020-07-14 11:15 PM
180
4
Total number of security vulnerabilities354