| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network. |
| Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network. |
| Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. |
| Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. |
| Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. |
| Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network. |
| Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network. |
| Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network. |
| Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network. |
| Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network. |
| Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network. |
| Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network. |
| Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network. |
| Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. |
| Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. |
| Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network. |
| Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. |
| Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network. |
| Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. |
| Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. |