Home / CVEs we hold for Azure CVEs we hold for Azure Records whose assigning authority named Azure as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-42316 KQL injection via kusto.tables.topics.mapping in kafka-sink-azure-kusto Azure kafka-sink-azure-kusto CVE-2026-32952 go-ntlmssp NTLM challenges can panic on malformed payloads Azure go-ntlmssp CVE-2025-8398 azurecurve BBCode <= 2.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via url Shortcode azurecurve BBCode CVE-2025-32016 Microsoft Identity Web Exposes Client Secrets and Certificate Information in Service Logs AzureAD microsoft-identity-web CVE-2025-2809 azurecurve Shortcodes in Comments <= 2.0.2 - Unauthenticated Arbitrary Shortcode Execution azurecurve Shortcodes in Comments CVE-2025-23482 WordPress azurecurve Floating Featured Image plugin <= 2.2.0 - Reflected Cross Site Scripting (XSS) vulnerability azurecurve Floating Featured Image CVE-2025-12603 /etc/timezone can be Arbitrarily Written Azure Access Technology BLU-IC4 CVE-2025-12602 /etc/avahi/services/z9.service can be Arbitrarily Written Azure Access Technology BLU-IC4 CVE-2025-12601 Denial of Service Due to SlowLoris Azure Access Technology BLU-IC4 CVE-2025-12599 Multiple Devices are Sharing the Same Secrets for SDKSocket (TCP/5000) Azure Access Technology BLU-IC4 CVE-2025-12553 Server Certificate Verification Disabled Azure Access Technology BLU-IC4 CVE-2025-12552 Insufficient Password Policy Azure Access Technology BLU-IC4 CVE-2025-12517 Credits Page not Matching Versions in Use in the Firmware Azure Access Technology BLU-IC4 CVE-2025-12516 Lack of Graceful Error Handling - HTTP 5xx Error Azure Access Technology BLU-IC4 CVE-2025-12515 Systemic Internal Server Errors - HTTP 500 Response Azure Access Technology BLU-IC4 CVE-2025-12479 Systemic Lack of Cross-Site Request Forgery (CSRF) Token Implementation Azure Access Technology BLU-IC4 CVE-2025-12478 Non-Compliant TLS Configuration Azure Access Technology BLU-IC4 CVE-2025-12477 Server Version Disclosure Azure Access Technology BLU-IC4 CVE-2025-12425 Local Privilege Escalation Azure Access Technology BLU-IC4 CVE-2025-12424 Privilege Escalation through SUID-bit Binary Azure Access Technology BLU-IC4 CVE-2025-12423 Denial of Service - Protocol Manipulation Azure Access Technology BLU-IC4 CVE-2025-12422 Vulnerable Upgrade Feature (Arbitrary File Write) Azure Access Technology BLU-IC4 CVE-2025-12365 Error Messages Wrapped In HTTP Header Azure Access Technology BLU-IC4 CVE-2025-12363 Email Password Disclosure Azure Access Technology BLU-IC4 CVE-2025-12285 Missing Initial Password Change Azure Access Technology BLU-IC4 CVE-2025-12278 Logout Functionality not Working Azure Access Technology BLU-IC4 CVE-2025-12275 Mail Configuration File Manipulation + Command Execution Azure Access Technology BLU-IC4 CVE-2025-12221 CSRF Token not Properly Implemented Azure Access Technology BLU-IC4 CVE-2025-12220 Busybox 1.31.1 - Multiple Known Vulnerabilities Azure Access Technology BLU-IC4 CVE-2025-12219 Vulnerable Components in Azure Access OS Azure Access Technology BLU-IC4 CVE-2025-12217 SNMP Default Community String (public) Azure Access Technology BLU-IC4 CVE-2025-12216 Malicious / Malformed App can be Installed but not Uninstalled Azure Access Technology BLU-IC4 CVE-2025-12176 Undocumented Administrative Accounts Azure Access Technology BLU-IC4 CVE-2025-12104 Incorrect Content-Type Header Azure Access Technology BLU-IC4 CVE-2025-12031 HTTP Security Misconfiguration - Lacking Secure and HTTPOnly Attribute Azure Access Technology BLU-IC4 CVE-2025-12001 Incorrect Content-Type Header Azure Access Technology BLU-IC4 CVE-2025-11925 Incorrect Content-Type Header Azure Access Technology BLU-IC4 CVE-2024-43961 WordPress azurecurve Toggle Show/Hide plugin <= 2.1.3 - Cross Site Scripting (XSS) vulnerability azurecurve Toggle Show/Hide CVE-2024-29195 Azure C SDK Integer Wraparound Vulnerability azure-c-shared-utility CVE-2024-27099 Azure IoT Platform Device SDK Double Free Vulnerability azure-uamqp-c CVE-2024-27086 MSAL.NET applications targeting Xamarin Android and .NET Android (MAUI) susceptible to local denial of service AzureAD microsoft-authentication-library-for-dotnet CVE-2024-25110 Azure IoT Platform Device SDK Remote Code Execution Vulnerability azure-uamqp-c CVE-2024-21646 Azure IoT Platform Device SDK Remote Code Execution Vulnerability azure-uamqp-c CVE-2024-21643 Microsoft.IdentityModel.Protocols.SignedHttpRequest remote code execution vulnerability AzureAD azure-activedirectory-identitymodel-extensions-for-d… CVE-2024-21638 Azure IPAM solution Elevation of Privilege Vulnerability Azure ipam CVE-2023-48698 Azure RTOS USBX Remote Code Execution Vulnerability azure-rtos usbx CVE-2023-48697 Azure RTOS USBX Remote Code Execution Vulnerability azure-rtos usbx CVE-2023-48696 Azure RTOS USBX Remote Code Execution Vulnerability azure-rtos usbx CVE-2023-48695 Azure RTOS USBX Remote Code Execution Vulnerability azure-rtos usbx CVE-2023-48694 Azure RTOS USBX Remote Code Execution Vulnerability azure-rtos usbx CVE-2023-48693 Azure RTOS ThreadX Remote Code Execution Vulnerability azure-rtos threadx CVE-2023-48692 Azure RTOS NetX Duo Remote Code Execution Vulnerability azure-rtos netxduo CVE-2023-48691 Azure RTOS NetX Duo Remote Code Execution Vulnerability azure-rtos netxduo CVE-2023-48316 Azure RTOS NetX Duo Remote Code Execution Vulnerability azure-rtos netxduo CVE-2023-48315 Azure RTOS NetX Duo Remote Code Execution Vulnerability azure-rtos netxduo CVE-2023-23939 Azure/setup-kubectl: Escalation of privilege vulnerability for v3 and lower Azure setup-kubectl CVE-2022-39344 Azure RTOS USBX vulnerable to buffer overflow azure-rtos usbx CVE-2022-39343 Azure RTOS FileX vulnerable to Buffer Offerflow azure-rtos filex CVE-2022-39327 Improper Control of Generation of Code ('Code Injection') in Azure CLI azure-cli CVE-2022-39293 Azure RTOS USBX Host PIMA vulnerable to read integer underflow with buffer overflow azure-rtos usbx CVE-2022-36063 USBX Host CDC ECM integer underflow with buffer overflow azure-rtos usbx CVE-2022-29246 Potential buffer overflow in function DFU upload in Azure RTOS USBX azure-rtos usbx CVE-2022-29223 Buffer overflow on HUB descriptor in Azure RTOS USBX azure-rtos usbx CVE-2022-23551 AAD Pod Identity obtaining token with backslash Azure aad-pod-identity 72 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.