CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-73298 - The Microsoft Container Migration Solution Accelerator is a multi-service application that provides
CVE-2026-71331 - Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attestation
CVE-2026-70340 - Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a
CVE-2026-66802 - Concurrent execution using shared resource with improper synchronization ('race condition') in Micro
CVE-2026-65806 - Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over
CVE-2026-63522 - Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized att
CVE-2026-62869 - Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to pe
CVE-2026-57104 - Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storag
CVE-2026-50516 - Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unautho
CVE-2026-47299 - Improper neutralization of special elements used in a command ('command injection') in Azure Monitor
CVE-2026-18348 - Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an a
CVE-2026-68870 - The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-sco
CVE-2026-68823 - Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to e
CVE-2026-62836 - Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance al
CVE-2026-62830 - Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a
CVE-2026-56162 - Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges
CVE-2026-56161 - Improper access control in Azure Logic Apps allows an authorized attacker to disclose information ov
CVE-2026-50515 - Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code
CVE-2026-50481 - Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacke
CVE-2026-66803 - Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a ne
CVE-2026-59243 - The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID
CVE-2026-62835 - Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over
CVE-2026-58630 - Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges o
CVE-2026-56163 - Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unautho
CVE-2026-62825 - Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges ove
CVE-2026-58275 - Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a netw
CVE-2026-56167 - Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privi
CVE-2026-56160 - Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate pri
CVE-2026-35425 - Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code
CVE-2025-66390 - In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Ba
CVE-2026-54733 - The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Dire
CVE-2026-15642 - Insertion of sensitive information into a file in the Recovery Kit response file generation feature
CVE-2026-58279 - Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a
CVE-2026-57969 - Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to el
CVE-2026-50653 - Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthori
CVE-2026-50652 - Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny
CVE-2026-50338 - Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges ove
CVE-2026-47632 - Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elevate pr
CVE-2026-61448 - Parse Server is affected by a stored cross-site scripting (XSS) vulnerability in versions >= 9.0.0,
CVE-2026-46354 - Coder allows organizations to provision remote development environments via Terraform. In versions p
CVE-2026-45796 - Coder allows organizations to provision remote development environments via Terraform. Versions prio
CVE-2026-55726 - The Azure Blob Storage container used for Gardyn device logs is publicly listable without authentica
CVE-2026-45499 - Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileg
CVE-2026-26145 - Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a
CVE-2026-52783 - OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, OpenP
CVE-2026-55412 - ToolJet is the open-source foundation am AI-native platform for building and deploying internal tool
CVE-2026-56270 - Flowise before 3.1.0 (versions 3.0.13 and earlier) contains a missing authentication vulnerability i
CVE-2026-56425 - The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its
CVE-2026-48584 - Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate priv
CVE-2026-45480 - Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privile
CVE-2026-32174 - Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges ove
CVE-2026-47643 - External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute
CVE-2026-45642 - Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Servi
CVE-2026-41098 - Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack
CVE-2026-32193 - Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Ku
CVE-2026-48567 - Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate priv
CVE-2026-31942 - LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and in
CVE-2026-48501 - GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly incl
CVE-2026-41185 - When Calico is configured with the Azure IPAM plugin, the Calico CNI binary mutates the incoming CNI
CVE-2026-45108 - Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 2.0.0 to befor
CVE-2026-47280 - Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate p
CVE-2026-40412 - Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attac
CVE-2026-40411 - Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute
CVE-2026-35430 - Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allow
CVE-2026-33843 - Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C all
CVE-2026-26147 - Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose informa
CVE-2026-23663 - Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privilege
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.