CVEs (40)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform spoofing over a network. |
Azure DevOps Server Spoofing Vulnerability |
Azure DevOps Server Spoofing Vulnerability |
Azure DevOps Server Remote Code Execution Vulnerability |
Azure DevOps Server Spoofing Vulnerability |
Azure DevOps Server Elevation of Privilege Vulnerability |
Azure DevOps Server Remote Code Execution Vulnerability |
Azure DevOps Server Remote Code Execution Vulnerability |
Azure DevOps Server Spoofing Vulnerability |
Azure DevOps Server Spoofing Vulnerability |
Azure DevOps Server Spoofing Vulnerability |
Azure DevOps Server Remote Code Execution Vulnerability |
Azure DevOps Server Cross-Site Scripting Vulnerability |
1Microsoft 1Azure Devops Server Nov 21, 2024 Apr 13, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Azure DevOps Server Spoofing Vulnerability |
1Microsoft 2Azure Devops Server Team Foundation ServerNov 21, 2024 Apr 13, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability |
1Microsoft 2Azure Devops Server Team Foundation ServerAug 28, 2025 Dec 10, 2020 N/A· v4 5.4 MEDIUM· v3 4.9 MEDIUM· v2 Azure DevOps Server and Team Foundation Services Spoofing Vulnerability |
1Microsoft 1Azure Devops Server Aug 28, 2025 Dec 10, 2020 N/A· v4 5.4 MEDIUM· v3 4.9 MEDIUM· v2 Azure DevOps Server Spoofing Vulnerability |
1Microsoft 1Azure Devops Server Nov 21, 2024 Nov 11, 2020 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 Azure DevOps Server and Team Foundation Services Spoofing Vulnerability |
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerability'. |
1Microsoft 1Azure Devops Server Nov 21, 2024 Jun 9, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azure DevOps Server HTML Injection Vulnerability'. |