Skip to main content

Vendor/product archive

microsoft / azure_devops_server CVEs

Beta · best-effort

40 CVEs tagged to microsoft / azure_devops_server2 Critical, 12 High, 26 Medium, 0 Low, 0 Unrated.

CVE-2026-21512

Published Feb 10, 2026

Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform spoofing over a network.

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2020-1326

Published Jul 14, 2020

A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerabil…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-1327

Published Jun 9, 2020

A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azure DevOps Server HTML Injection Vulnerability'.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-0815

Published Mar 12, 2020

An elevation of privilege vulnerability exists when Azure DevOps Server and Team Foundation Services improperly handle pipeline job tokens, aka 'Azure DevOps Server and Team Found…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 40 CVEsPage 1 of 2