Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
618 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.7) | 0.45% | — | Microsoft Azure Agent | 11/3/2025 | 17/6/2026 | Improper privilege management in Azure Agent Installer allows an authorized attacker to elevate privileges locally. | |
| Aplazada | Alta (7.1) | 0.28% | — | Azurecurve Floating Featured ImageAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in azurecurve azurecurve Floating Featured Image azurecurve-floating-featured-image allows Reflected XSS.This issue affects azurecurve Floating Featured Image: from n/a through <= 2.2.0. | |
| Analizada | Media (6) | 0.71% | — | Microsoft Azure Network Watcher | 11/2/2025 | 17/6/2026 | Azure Network Watcher VM Extension Elevation of Privilege Vulnerability | |
| Analizada | Alta (8.8) | 0.94% | — | Microsoft Azure AI Face Service | 29/1/2025 | 17/6/2026 | Authentication bypass by spoofing in Azure AI Face Service allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Media (4.3) | 0.30% | — | Jenkins Azure Service Fabric | 22/1/2025 | 17/6/2026 | A missing permission check in Jenkins Azure Service Fabric Plugin 1.6 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of Azure credentials stored in Jenkins. | |
| Analizada | Media (4.3) | 0.22% | — | Jenkins Azure Service Fabric | 22/1/2025 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Azure Service Fabric Plugin 1.6 and earlier allows attackers to connect to a Service Fabric URL using attacker-specified credentials IDs obtained through another method. | |
| Analizada | Media (6.5) | 1.5% | — | Microsoft Azure Marketplace | 9/1/2025 | 17/6/2026 | Improper access control in Azure SaaS Resources allows an authorized attacker to disclose information over a network. | |
| Analizada | Crítica (9.8) | 0.70% | — | Microsoft Azure Functions | 26/11/2024 | 17/6/2026 | Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 0.37% | — | Microsoft Azure Stack HCI | 15/11/2024 | 17/6/2026 | Azure Stack HCI Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.2) | 1.2% | — | Microsoft Azure Database FOR Postgresql Flexible Server | 12/11/2024 | 17/6/2026 | Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.2) | 1.2% | — | Microsoft Azure Database FOR Postgresql Flexible Server | 12/11/2024 | 17/6/2026 | Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability | |
| Analizada | Crítica (9.9) | 2.3% | — | Microsoft Azure Cyclecloud | 12/11/2024 | 17/6/2026 | Azure CycleCloud Remote Code Execution Vulnerability | |
| Analizada | Media (6.5) | 0.94% | — | Microsoft Azure Functions | 15/10/2024 | 17/6/2026 | Improper access control in Imagine Cup allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.1) | 1.6% | — | Microsoft Azure Command-line InterfaceMicrosoft Azure Service Connector | 8/10/2024 | 17/6/2026 | Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability | |
| Analizada | Media (6.6) | 1.1% | — | Microsoft Azure Service Fabric | 8/10/2024 | 17/6/2026 | Azure Service Fabric for Linux Remote Code Execution Vulnerability | |
| Analizada | Alta (8.8) | 0.44% | — | Microsoft Azure Stack HCI | 8/10/2024 | 17/6/2026 | Azure Stack Hyperconverged Infrastructure (HCI) Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.1) | 0.65% | — | Microsoft Azure Monitor Agent | 8/10/2024 | 17/6/2026 | Azure Monitor Agent Elevation of Privilege Vulnerability | |
| Analizada | Media (5.5) | 0.14% | — | Opentext Identity Manager Azuread Driver | 12/9/2024 | 17/6/2026 | A vulnerability identified in OpenText™ Identity Manager AzureAD Driver that allows logging of sensitive information into log file. This impacts all versions before 5.1.4.0 | |
| Analizada | Alta (7.3) | 0.85% | — | Microsoft Azure Network Watcher Agent | 10/9/2024 | 10/8/2026 | Azure Network Watcher VM Agent Elevation of Privilege Vulnerability | |
| Analizada | Alta (8.8) | 1.6% | — | Microsoft Azure Cyclecloud | 10/9/2024 | 10/8/2026 | Azure CycleCloud Remote Code Execution Vulnerability | |
| Analizada | Crítica (9) | 1.0% | — | Microsoft Azure Stack HUB | 10/9/2024 | 10/8/2026 | Azure Stack Hub Elevation of Privilege Vulnerability | |
| Analizada | Crítica (9) | 0.92% | — | Microsoft Azure Stack HUB | 10/9/2024 | 10/8/2026 | Azure Stack Hub Elevation of Privilege Vulnerability | |
| Analizada | Crítica (9.9) | 1.3% | — | Microsoft Azure WEB Apps | 10/9/2024 | 10/8/2026 | An authenticated attacker can exploit an improper authorization vulnerability in Azure Web Apps to elevate privileges over a network. | |
| Analizada | Alta (7.1) | 0.58% | — | Microsoft Azure Network Watcher Agent | 10/9/2024 | 10/8/2026 | Azure Network Watcher VM Agent Elevation of Privilege Vulnerability | |
| Analizada | Media (4.3) | 1.7% | — | Microsoft SQL 2016 Azure Connect Feature PackMicrosoft SQL Server 2016Microsoft SQL Server 2017Microsoft SQL Server 2019+1 | 10/9/2024 | 10/8/2026 | Microsoft SQL Server Native Scoring Information Disclosure Vulnerability |