Azure Cosmos Db
by Microsoft
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-64675 | Hig | 0.54 | 8.3 | 0.01 | Dec 19, 2025 | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-66803 | Cri | 0.00 | 10.0 | 0.01 | Jul 30, 2026 | Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. |
- risk 0.54cvss 8.3epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauthorized attacker to perform spoofing over a network.
- risk 0.00cvss 10.0epss 0.01
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.