vciy

CVEs we hold for Azure

Records whose assigning authority named Azure as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-42316KQL injection via kusto.tables.topics.mapping in kafka-sink-azure-kustoAzure kafka-sink-azure-kusto
CVE-2026-32952go-ntlmssp NTLM challenges can panic on malformed payloadsAzure go-ntlmssp
CVE-2025-8398azurecurve BBCode <= 2.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via url Shortcodeazurecurve BBCode
CVE-2025-32016Microsoft Identity Web Exposes Client Secrets and Certificate Information in Service LogsAzureAD microsoft-identity-web
CVE-2025-2809azurecurve Shortcodes in Comments <= 2.0.2 - Unauthenticated Arbitrary Shortcode Executionazurecurve Shortcodes in Comments
CVE-2025-23482WordPress azurecurve Floating Featured Image plugin <= 2.2.0 - Reflected Cross Site Scripting (XSS) vulnerabilityazurecurve Floating Featured Image
CVE-2025-12603/etc/timezone can be Arbitrarily WrittenAzure Access Technology BLU-IC4
CVE-2025-12602/etc/avahi/services/z9.service can be Arbitrarily WrittenAzure Access Technology BLU-IC4
CVE-2025-12601Denial of Service Due to SlowLorisAzure Access Technology BLU-IC4
CVE-2025-12600Web UI MalfunctionAzure Access Technology BLU-IC4
CVE-2025-12599Multiple Devices are Sharing the Same Secrets for SDKSocket (TCP/5000)Azure Access Technology BLU-IC4
CVE-2025-12554Missing Security HeadersAzure Access Technology BLU-IC4
CVE-2025-12553Server Certificate Verification DisabledAzure Access Technology BLU-IC4
CVE-2025-12552Insufficient Password PolicyAzure Access Technology BLU-IC4
CVE-2025-12517Credits Page not Matching Versions in Use in the FirmwareAzure Access Technology BLU-IC4
CVE-2025-12516Lack of Graceful Error Handling - HTTP 5xx ErrorAzure Access Technology BLU-IC4
CVE-2025-12515Systemic Internal Server Errors - HTTP 500 ResponseAzure Access Technology BLU-IC4
CVE-2025-12479Systemic Lack of Cross-Site Request Forgery (CSRF) Token ImplementationAzure Access Technology BLU-IC4
CVE-2025-12478Non-Compliant TLS ConfigurationAzure Access Technology BLU-IC4
CVE-2025-12477Server Version DisclosureAzure Access Technology BLU-IC4
CVE-2025-12476Resource Lacking AuthNAzure Access Technology BLU-IC4
CVE-2025-12425Local Privilege EscalationAzure Access Technology BLU-IC4
CVE-2025-12424Privilege Escalation through SUID-bit BinaryAzure Access Technology BLU-IC4
CVE-2025-12423Denial of Service - Protocol ManipulationAzure Access Technology BLU-IC4
CVE-2025-12422Vulnerable Upgrade Feature (Arbitrary File Write)Azure Access Technology BLU-IC4
CVE-2025-12365Error Messages Wrapped In HTTP HeaderAzure Access Technology BLU-IC4
CVE-2025-12364Weak Password PolicyAzure Access Technology BLU-IC4
CVE-2025-12363Email Password DisclosureAzure Access Technology BLU-IC4
CVE-2025-12285Missing Initial Password ChangeAzure Access Technology BLU-IC4
CVE-2025-12284Lack of Input ValidationAzure Access Technology BLU-IC4
CVE-2025-12278Logout Functionality not WorkingAzure Access Technology BLU-IC4
CVE-2025-12275Mail Configuration File Manipulation + Command ExecutionAzure Access Technology BLU-IC4
CVE-2025-12221CSRF Token not Properly ImplementedAzure Access Technology BLU-IC4
CVE-2025-12220Busybox 1.31.1 - Multiple Known VulnerabilitiesAzure Access Technology BLU-IC4
CVE-2025-12219Vulnerable Components in Azure Access OSAzure Access Technology BLU-IC4
CVE-2025-12218Weak Default CredentialsAzure Access Technology BLU-IC4
CVE-2025-12217SNMP Default Community String (public)Azure Access Technology BLU-IC4
CVE-2025-12216Malicious / Malformed App can be Installed but not UninstalledAzure Access Technology BLU-IC4
CVE-2025-12176Undocumented Administrative AccountsAzure Access Technology BLU-IC4
CVE-2025-12114Serial Console EnabledAzure Access Technology BLU-IC4
CVE-2025-12104Incorrect Content-Type HeaderAzure Access Technology BLU-IC4
CVE-2025-12031HTTP Security Misconfiguration - Lacking Secure and HTTPOnly AttributeAzure Access Technology BLU-IC4
CVE-2025-12001Incorrect Content-Type HeaderAzure Access Technology BLU-IC4
CVE-2025-11925Incorrect Content-Type HeaderAzure Access Technology BLU-IC4
CVE-2025-11832APIs Lack Rate LimitingAzure Access Technology BLU-IC4
CVE-2024-43961WordPress azurecurve Toggle Show/Hide plugin <= 2.1.3 - Cross Site Scripting (XSS) vulnerabilityazurecurve Toggle Show/Hide
CVE-2024-29195Azure C SDK Integer Wraparound Vulnerabilityazure-c-shared-utility
CVE-2024-27099Azure IoT Platform Device SDK Double Free Vulnerabilityazure-uamqp-c
CVE-2024-27086MSAL.NET applications targeting Xamarin Android and .NET Android (MAUI) susceptible to local denial of serviceAzureAD microsoft-authentication-library-for-dotnet
CVE-2024-25110Azure IoT Platform Device SDK Remote Code Execution Vulnerabilityazure-uamqp-c
CVE-2024-21646Azure IoT Platform Device SDK Remote Code Execution Vulnerabilityazure-uamqp-c
CVE-2024-21643Microsoft.IdentityModel.Protocols.SignedHttpRequest remote code execution vulnerabilityAzureAD azure-activedirectory-identitymodel-extensions-for-d…
CVE-2024-21638Azure IPAM solution Elevation of Privilege VulnerabilityAzure ipam
CVE-2023-48698Azure RTOS USBX Remote Code Execution Vulnerabilityazure-rtos usbx
CVE-2023-48697Azure RTOS USBX Remote Code Execution Vulnerabilityazure-rtos usbx
CVE-2023-48696Azure RTOS USBX Remote Code Execution Vulnerabilityazure-rtos usbx
CVE-2023-48695Azure RTOS USBX Remote Code Execution Vulnerabilityazure-rtos usbx
CVE-2023-48694Azure RTOS USBX Remote Code Execution Vulnerabilityazure-rtos usbx
CVE-2023-48693Azure RTOS ThreadX Remote Code Execution Vulnerabilityazure-rtos threadx
CVE-2023-48692Azure RTOS NetX Duo Remote Code Execution Vulnerabilityazure-rtos netxduo
CVE-2023-48691Azure RTOS NetX Duo Remote Code Execution Vulnerabilityazure-rtos netxduo
CVE-2023-48316Azure RTOS NetX Duo Remote Code Execution Vulnerabilityazure-rtos netxduo
CVE-2023-48315Azure RTOS NetX Duo Remote Code Execution Vulnerabilityazure-rtos netxduo
CVE-2023-23939Azure/setup-kubectl: Escalation of privilege vulnerability for v3 and lowerAzure setup-kubectl
CVE-2022-39344Azure RTOS USBX vulnerable to buffer overflowazure-rtos usbx
CVE-2022-39343Azure RTOS FileX vulnerable to Buffer Offerflowazure-rtos filex
CVE-2022-39327Improper Control of Generation of Code ('Code Injection') in Azure CLIazure-cli
CVE-2022-39293Azure RTOS USBX Host PIMA vulnerable to read integer underflow with buffer overflowazure-rtos usbx
CVE-2022-36063USBX Host CDC ECM integer underflow with buffer overflowazure-rtos usbx
CVE-2022-29246Potential buffer overflow in function DFU upload in Azure RTOS USBXazure-rtos usbx
CVE-2022-29223Buffer overflow on HUB descriptor in Azure RTOS USBXazure-rtos usbx
CVE-2022-23551AAD Pod Identity obtaining token with backslashAzure aad-pod-identity

72 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.