9.1

CVSS3.1

CVE-2026-32211 - Azure MCP Server Information Disclosure Vulnerability

Missing authentication for critical function in Azure MCP Server allows an unauthorized attacker to disclose information over a network.

πŸ“… Published: April 2, 2026, 11:27 p.m. πŸ”„ Last Modified: April 3, 2026, 12:16 a.m.

8.6

CVSS3.1

CVE-2026-32173 - Azure SRE Agent Information Disclosure Vulnerability

Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network.

πŸ“… Published: April 2, 2026, 11:27 p.m. πŸ”„ Last Modified: April 3, 2026, 12:16 a.m.

10

CVSS3.1

CVE-2026-33105 - Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability

Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

πŸ“… Published: April 2, 2026, 11:26 p.m. πŸ”„ Last Modified: April 3, 2026, 12:16 a.m.

9.6

CVSS3.1

CVE-2026-26135 - Azure Custom Locations Resource Provider (RP) Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a network.

πŸ“… Published: April 2, 2026, 11:26 p.m. πŸ”„ Last Modified: April 3, 2026, 12:16 a.m.

10

CVSS3.1

CVE-2026-33107 - Azure Databricks Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.

πŸ“… Published: April 2, 2026, 11:26 p.m. πŸ”„ Last Modified: April 3, 2026, 12:16 a.m.

10

CVSS3.1

CVE-2026-32213 - Azure AI Foundry Elevation of Privilege Vulnerability

Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

πŸ“… Published: April 2, 2026, 11:26 p.m. πŸ”„ Last Modified: April 3, 2026, 12:16 a.m.

7.1

CVSS4.0

CVE-2022-4986 - Hirschmann EagleSDV Denial of Service via TLS

Hirschmann EagleSDV contains a denial-of-service vulnerability that causes the device to crash during session establishment when using TLS 1.0 or TLS 1.1. Attackers can trigger a crash by initiating TLS connections with these protocol versions to disrupt service availability.

πŸ“… Published: April 2, 2026, 9:52 p.m. πŸ”„ Last Modified: April 2, 2026, 9:52 p.m.

8.7

CVSS4.0

CVE-2024-14033 - Hirschmann Industrial IT HiLCOS Heap Overflow DoS

Hirschmann Industrial IT products contain a heap overflow vulnerability in the HiLCOS web interface that allows unauthenticated remote attackers to trigger a denial-of-service condition by sending specially crafted requests to the web interface. Attackers can exploit this heap overflow to crash the…

πŸ“… Published: April 2, 2026, 8:40 p.m. πŸ”„ Last Modified: April 2, 2026, 9:16 p.m.

9.2

CVSS4.0

CVE-2025-15620 - HiOS Switch Platform Denial-of-Service via Web Interface

HiOS Switch Platform contains a denial-of-service vulnerability in the web interface that allows remote attackers to reboot the affected device by sending a malicious HTTP GET request to a specific endpoint. Attackers can trigger an uncontrolled reboot condition through crafted HTTP requests to cau…

πŸ“… Published: April 2, 2026, 8:28 p.m. πŸ”„ Last Modified: April 2, 2026, 9:16 p.m.

9.3

CVSS4.0

CVE-2024-14034 - Hirschmann HiEOS Authentication Bypass via HTTP Management Module

Hirschmann HiEOS devices versions prior to 01.1.00 contain an authentication bypass vulnerability in the HTTP(S) management module that allows unauthenticated remote attackers to gain administrative access by sending specially crafted HTTP(S) requests. Attackers can exploit improper authentication …

πŸ“… Published: April 2, 2026, 8:01 p.m. πŸ”„ Last Modified: April 2, 2026, 10:25 p.m.
Total resulsts: 341937
Page 1 of 34,194
Β» next page
Filters