Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
618 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6) | 0.36% | — | Microsoft Azure Service Fabric | 8/7/2025 | 17/6/2026 | Improper link resolution before file access ('link following') in Service Fabric allows an authorized attacker to elevate privileges locally. | |
| Aplazada | Media (5.2) | 0.23% | — | Microsoft Azure Entra IDAIMicrosoft IntuneAIHimmelblau-idm HimmelblauAI | 26/6/2025 | 17/6/2026 | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. A vulnerability present in versions 0.9.10 through 0.9.16 allows a user to authenticate to a Linux host via Himmelblau using an *invalid* Linux Hello PIN, provided the host is offline. While the user gains access to the local system,… | |
| Aplazada | Media (5.4) | 0.34% | — | Microsoft Azure Entra IDAIMicrosoft IntuneAIHimmelblau-idm HimmelblauAI | 5/6/2025 | 17/6/2026 | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Himmelblau versions 0.9.0 through 0.9.14 and 1.00-alpha are vulnerable to a privilege escalation issue when Entra ID group-based access restrictions are configured using group display names instead of object IDs. Starting in version… | |
| Analizada | Crítica (9.8) | 1.2% | — | Microsoft Azure AI Document Intelligence Studio | 13/5/2025 | 17/6/2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7) | 0.30% | — | Microsoft Azure File Sync | 13/5/2025 | 17/6/2026 | Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.5) | 1.8% | — | Microsoft Msagsfeedback.azurewebsites.net | 8/5/2025 | 17/6/2026 | Improper access control in Azure allows an unauthorized attacker to disclose information over a network. | |
| Modificada | Crítica (9.8) | 3.5% | 💥 PoC | Microsoft Azure Storage Resource Provider | 8/5/2025 | 17/6/2026 | Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Alta (8.8) | 1.7% | — | Microsoft Azure Automation | 8/5/2025 | 17/6/2026 | Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network. | |
| Modificada | Crítica (9.8) | 1.8% | — | Microsoft Azure Devops | 8/5/2025 | 17/6/2026 | Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 0.58% | — | Microsoft Azure Functions | 30/4/2025 | 17/6/2026 | Improper verification of cryptographic signature in Microsoft Azure Functions allows an authorized attacker to execute code over a network. | |
| Analizada | Crítica (9.8) | 1.1% | — | Microsoft Azure AI BOT Service | 30/4/2025 | 17/6/2026 | Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 0.97% | — | Microsoft Azure Machine Learning | 30/4/2025 | 17/6/2026 | Improper authorization in Azure allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 0.88% | — | Microsoft Azure AI BOT Service | 30/4/2025 | 17/6/2026 | Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Azure Virtual Desktop | 30/4/2025 | 17/6/2026 | Missing authorization in Azure Virtual Desktop allows an authorized attacker to elevate privileges over a network. | |
| Aplazada | Alta (7.3) | 0.52% | — | Azurecurve Shortcodes IN CommentsAI | 10/4/2025 | 17/6/2026 | The azurecurve Shortcodes in Comments plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for… | |
| Analizada | Alta (7.8) | 0.61% | — | Microsoft Azure Stack HCI 22h2Microsoft Azure Stack HCI 23h2 | 8/4/2025 | 17/6/2026 | Improper input validation in Azure Local allows an authorized attacker to elevate privileges locally. | |
| Analizada | Media (5.5) | 1.4% | — | Microsoft Azure Local Cluster | 8/4/2025 | 17/6/2026 | Insufficiently protected credentials in Azure Local Cluster allows an authorized attacker to disclose information locally. | |
| Analizada | Media (5.7) | 1.1% | — | Microsoft Azure Local Cluster | 8/4/2025 | 17/6/2026 | Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose information over an adjacent network. | |
| Aplazada | Crítica (9.3) | 0.41% | — | Conda-forge InfrastructureAIMicrosoft AzureAIAnaconda.orgAI | 2/4/2025 | 17/6/2026 | conda-forge infrastructure holds common configurations and settings for key pieces of the conda-forge infrastructure. Between 2025-02-10 and 2025-04-01, conda-forge infrastructure used the wrong token for Azure's cf-staging access. This bug meant that any feedstock maintainer could upload a package to the conda-forge… | |
| Analizada | Alta (8.8) | 0.69% | — | Microsoft Azure Health BOT | 1/4/2025 | 17/6/2026 | An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 0.68% | — | Microsoft Azure Playwright | 31/3/2025 | 17/6/2026 | Improper authorization in Azure Playwright allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Alta (7.1) | 0.24% | — | Promact WP Azure OffloadAI | 28/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in promact WP Azure offload wp-azure-offload allows Reflected XSS.This issue affects WP Azure offload: from n/a through <= 2.0. | |
| Analizada | Alta (7) | 0.90% | — | Microsoft Azure ARC | 11/3/2025 | 17/6/2026 | Improper neutralization of special elements used in a command ('command injection') in Azure Arc allows an authorized attacker to elevate privileges locally. | |
| Analizada | Media (6.5) | 0.54% | — | Microsoft Azure Promptflow CoreMicrosoft Azure Promptflow Tools | 11/3/2025 | 17/6/2026 | Improper isolation or compartmentalization in Azure PromptFlow allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.4) | 0.43% | — | Microsoft Azure Command-line Interface | 11/3/2025 | 17/6/2026 | Improper neutralization of special elements used in a command ('command injection') in Azure Command Line Integration (CLI) allows an unauthorized attacker to elevate privileges locally. |