VYPR

Entra ID

by Microsoft

CVEs (16)

  • CVE-2026-69836CriAug 20, 2026
    risk 0.65cvss 10.0epss 0.02

    Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

  • CVE-2026-42901CriMay 22, 2026
    risk 0.65cvss 10.0epss 0.00

    Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-35431CriApr 23, 2026
    risk 0.65cvss 10.0epss 0.01

    Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2025-55241CriSep 4, 2025
    risk 0.65cvss 10.0epss 0.02

    Azure Entra ID Elevation of Privilege Vulnerability

  • CVE-2026-83941CriSep 8, 2026
    risk 0.64cvss 9.9epss 0.01

    Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-59246CriOct 9, 2025
    risk 0.64cvss 9.8epss 0.08

    Azure Entra ID Elevation of Privilege Vulnerability

  • CVE-2024-21401CriFeb 13, 2024
    risk 0.64cvss 9.8epss 0.01

    Microsoft Entra Jira Single-Sign-On Plugin Elevation of Privilege Vulnerability

  • CVE-2025-59218CriOct 9, 2025
    risk 0.62cvss 9.6epss 0.01

    Azure Entra ID Elevation of Privilege Vulnerability

  • CVE-2026-40379CriMay 12, 2026
    risk 0.61cvss 9.3epss 0.01

    Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-24305CriJan 22, 2026
    risk 0.60cvss 9.3epss 0.01

    Azure Entra ID Elevation of Privilege Vulnerability

  • CVE-2026-62916CriSep 3, 2026
    risk 0.59cvss 9.1epss 0.01

    Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-33843CriMay 22, 2026
    risk 0.59cvss 9.1epss 0.01

    Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-62869HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.00

    Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-32208HigJun 19, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an authorized attacker to perform spoofing over a network.

  • CVE-2024-43477HigAug 23, 2024
    risk 0.49cvss 7.5epss 0.01

    Improper access control in Decentralized Identity Services resulted in a vulnerability that allows an unauthenticated attacker to disable Verifiable ID's on another tenant.

  • CVE-2024-21381MedFeb 13, 2024
    risk 0.44cvss 6.8epss 0.00

    Microsoft Azure Active Directory B2C Spoofing Vulnerability