Vulnerabilities

Summary — last 7 days

New vulnerabilities3,081▲ 625 vs. last week
Critical / high1,483▲ 317 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)393▲ 186 vs. last week
–

45 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
Awaiting AnalysisHigh (8.7)0.43%—RenovateAIMicrosoft Azure DevopsAI8/19/20269/8/2026
Renovate versions >=19.180.0 and <23.25.1, when used with Azure DevOps, may expose the bot's authorization token in server or pipeline logs because the git http.extraheader=AUTHORIZATION parameter is logged without redaction. Anyone with access to saved logs could obtain the bot credentials. Fixed in 23.25.1; Azure…
AnalyzedHigh (7.5)1.2%—Microsoft Azure Devops5/7/20266/17/2026
Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network.
AnalyzedCritical (9.8)0.78%—Microsoft Azure Devops3/19/20266/17/2026
Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
AnalyzedMedium (6.5)1.0%—Microsoft Azure Devops Server2/10/20266/17/2026
Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform spoofing over a network.
AnalyzedCritical (9)0.70%—Microsoft Azure Devops7/18/20256/17/2026
Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
ModifiedCritical (9.8)1.7%—Microsoft Azure Devops5/8/20256/17/2026
Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
ModifiedHigh (7.6)1.6%—Microsoft Azure Devops Server7/9/20246/17/2026
Azure DevOps Server Spoofing Vulnerability
ModifiedHigh (7.6)1.6%—Microsoft Azure Devops Server7/9/20246/17/2026
Azure DevOps Server Spoofing Vulnerability
ModifiedHigh (7.5)1.4%—Microsoft Azure Devops Server2/13/20248/10/2026
Azure DevOps Server Remote Code Execution Vulnerability
ModifiedMedium (6.5)0.98%—Microsoft Azure Devops Server12/14/20236/17/2026
Azure DevOps Server Spoofing Vulnerability
ModifiedHigh (7.3)0.87%—Microsoft Azure Devops Server10/10/20236/17/2026
Azure DevOps Server Elevation of Privilege Vulnerability
ModifiedHigh (8.1)1.3%—Microsoft Azure Devops Server9/12/20236/17/2026
Azure DevOps Server Remote Code Execution Vulnerability
ModifiedHigh (8.8)1.7%—Microsoft Azure Devops Server9/12/20236/17/2026
Azure DevOps Server Remote Code Execution Vulnerability
ModifiedMedium (6.3)0.69%—Microsoft Azure Devops Server8/8/20238/10/2026
Azure DevOps Server Spoofing Vulnerability
ModifiedMedium (5.5)0.68%—Microsoft Azure Devops Server6/14/20236/17/2026
Azure DevOps Server Spoofing Vulnerability
ModifiedHigh (7.1)0.93%—Microsoft Azure Devops Server6/14/20236/17/2026
Azure DevOps Server Spoofing Vulnerability
ModifiedHigh (7.5)1.4%—Microsoft Azure Devops Server2/14/20238/19/2026
Azure DevOps Server Remote Code Execution Vulnerability
ModifiedHigh (7.1)0.89%—Microsoft Azure Devops Server2/14/20238/19/2026
Azure DevOps Server Cross-Site Scripting Vulnerability
ModifiedMedium (6.1)2.3%—Microsoft Azure Devops Server4/13/20216/17/2026
Azure DevOps Server Spoofing Vulnerability
ModifiedMedium (6.5)2.6%—Microsoft Team Foundation ServerMicrosoft Azure Devops Server4/13/20216/17/2026
Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability
ModifiedMedium (5.4)1.5%—Microsoft Team Foundation ServerMicrosoft Azure Devops Server12/10/20206/17/2026
Azure DevOps Server and Team Foundation Services Spoofing Vulnerability
ModifiedMedium (5.4)1.3%—Microsoft Azure Devops Server12/10/20206/17/2026
Azure DevOps Server Spoofing Vulnerability
ModifiedMedium (5.4)1.6%—Microsoft Azure Devops Server11/11/20206/17/2026
Azure DevOps Server and Team Foundation Services Spoofing Vulnerability
ModifiedMedium (5.4)1.6%—Microsoft Azure Devops Server7/14/20206/17/2026
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerability'.
ModifiedMedium (6.1)1.8%—Microsoft Azure Devops Server6/9/20206/17/2026
A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azure DevOps Server HTML Injection Vulnerability'.