9.1
CVE-2026-32211 - Azure MCP Server Information Disclosure Vulnerability
Missing authentication for critical function in Azure MCP Server allows an unauthorized attacker to disclose information over a network.
8.6
CVE-2026-32173 - Azure SRE Agent Information Disclosure Vulnerability
Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network.
10
CVE-2026-33105 - Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
9.6
CVE-2026-26135 - Azure Custom Locations Resource Provider (RP) Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a network.
10
CVE-2026-33107 - Azure Databricks Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.
10
CVE-2026-32213 - Azure AI Foundry Elevation of Privilege Vulnerability
Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
7.1
CVE-2022-4986 - Hirschmann EagleSDV Denial of Service via TLS
Hirschmann EagleSDV contains a denial-of-service vulnerability that causes the device to crash during session establishment when using TLS 1.0 or TLS 1.1. Attackers can trigger a crash by initiating TLS connections with these protocol versions to disrupt service availability.
8.7
CVE-2024-14033 - Hirschmann Industrial IT HiLCOS Heap Overflow DoS
Hirschmann Industrial IT products contain a heap overflow vulnerability in the HiLCOS web interface that allows unauthenticated remote attackers to trigger a denial-of-service condition by sending specially crafted requests to the web interface. Attackers can exploit this heap overflow to crash theβ¦
9.2
CVE-2025-15620 - HiOS Switch Platform Denial-of-Service via Web Interface
HiOS Switch Platform contains a denial-of-service vulnerability in the web interface that allows remote attackers to reboot the affected device by sending a malicious HTTP GET request to a specific endpoint. Attackers can trigger an uncontrolled reboot condition through crafted HTTP requests to cauβ¦
9.3
CVE-2024-14034 - Hirschmann HiEOS Authentication Bypass via HTTP Management Module
Hirschmann HiEOS devices versions prior to 01.1.00 contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers to gain administrative access by sending specially crafted HTTP(S) requests. Attackers can exploit improper authentication β¦