Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
618 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.83% | — | Microsoft Authentication LibraryMicrosoft Azure Identity SDK | 11/6/2024 | 20/7/2026 | Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.1) | 0.83% | — | Microsoft Azure Monitor Agent | 11/6/2024 | 20/7/2026 | Azure Monitor Agent Elevation of Privilege Vulnerability | |
| Modificada | Media (4.4) | 0.74% | — | Microsoft Azure File Sync | 11/6/2024 | 20/7/2026 | Microsoft Azure File Sync Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.5) | 2.5% | — | Microsoft Azure Storage Data Movement Library | 11/6/2024 | 20/7/2026 | Azure Storage Movement Client Library Denial of Service Vulnerability | |
| Aplazada | Media (6.4) | 0.27% | — | Miniorange Wordpress Office 365 Azure AD LoginAI | 23/5/2024 | 17/6/2026 | The WordPress + Microsoft Office 365 / Azure AD | LOGIN plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pintra' shortcode in all versions up to, and including, 27.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Analizada | Alta (7.8) | 0.49% | — | Microsoft Azure Monitor Agent | 16/5/2024 | 17/6/2026 | Azure Monitor Agent Elevation of Privilege Vulnerability | |
| Aplazada | Media (6.5) | 0.27% | — | Microsoft Azure File CSI DriverAI | 15/5/2024 | 17/6/2026 | A security issue was discovered in azure-file-csi-driver where an actor with access to the driver logs could observe service account tokens. These tokens could then potentially be exchanged with external cloud providers to access secrets stored in cloud vault solutions. Tokens are only logged when TokenRequests is… | |
| Analizada | Media (5.4) | 0.95% | — | Microsoft Azure Migrate | 14/5/2024 | 17/6/2026 | Azure Migrate Cross-Site Scripting Vulnerability | |
| Analizada | Alta (8.8) | 2.0% | — | Microsoft Azure Cyclecloud | 9/4/2024 | 17/6/2026 | Azure CycleCloud Elevation of Privilege Vulnerability | |
| Analizada | Crítica (9) | 18% | — | Microsoft Azure Kubernetes Service Confidential Containers | 9/4/2024 | 17/6/2026 | Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability | |
| Analizada | Alta (8.4) | 0.75% | — | Microsoft Azure Monitor Agent | 9/4/2024 | 17/6/2026 | Azure Monitor Agent Elevation of Privilege Vulnerability | |
| Analizada | Media (5.5) | 0.78% | — | Microsoft Azure AI Search | 9/4/2024 | 17/6/2026 | Azure AI Search Information Disclosure Vulnerability | |
| Analizada | Media (6.2) | 0.89% | — | Azure ARC Extension Microsoft.azstackhci.operatorAzure ARC Extension Microsoft.azure.hybridnetworkAzure ARC Extension Microsoft.azurekeyvaultsecretsproviderAzure ARC Extension Microsoft.iotoperations.mq+3 | 9/4/2024 | 17/6/2026 | Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability | |
| Analizada | Media (6.4) | 0.85% | — | Microsoft Azure Migrate | 9/4/2024 | 17/6/2026 | Azure Migrate Remote Code Execution Vulnerability | |
| Analizada | Media (6.5) | 1.9% | — | Microsoft Azure Compute Gallery | 9/4/2024 | 17/6/2026 | Azure Compute Gallery Elevation of Privilege Vulnerability | |
| Analizada | Media (5.9) | 5.5% | — | Microsoft Azure Private 5G Core | 9/4/2024 | 17/6/2026 | Azure Private 5G Core Denial of Service Vulnerability | |
| Analizada | Media (5.5) | 0.72% | — | Microsoft Azure Identity | 9/4/2024 | 24/9/2026 | Azure Identity Library for .NET Information Disclosure Vulnerability | |
| Analizada | Alta (8.1) | 5.0% | — | Microsoft Azure C Shared Utility | 26/3/2024 | 17/6/2026 | The azure-c-shared-utility is a C library for AMQP/MQTT communication to Azure Cloud Services. This library may be used by the Azure IoT C SDK for communication between IoT Hub and IoT Hub devices. An attacker can cause an integer wraparound or under-allocation or heap buffer overflow due to vulnerabilities in… | |
| Analizada | Alta (7.3) | 0.94% | — | Microsoft Azure Data Studio | 12/3/2024 | 17/6/2026 | Azure Data Studio Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.5) | 1.8% | — | Microsoft Azure Software Development KIT | 12/3/2024 | 17/6/2026 | Azure SDK Spoofing Vulnerability | |
| Analizada | Alta (7.8) | 0.99% | — | Microsoft Azure AutomationMicrosoft Azure Automation Update ManagementMicrosoft Azure Security CenterMicrosoft Azure Sentinel+4 | 12/3/2024 | 17/6/2026 | Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability | |
| Analizada | Crítica (9.8) | 1.4% | — | Microsoft Azure Uamqp | 27/2/2024 | 17/6/2026 | The uAMQP is a C library for AMQP 1.0 communication to Azure Cloud Services. When processing an incorrect `AMQP_VALUE` failed state, may cause a double free problem. This may cause a RCE. Update submodule with commit 2ca42b6e4e098af2d17e487814a91d05f6ae4987. | |
| Modificada | Crítica (9) | 1.3% | — | Microsoft Azure Kubernetes Service | 13/2/2024 | 10/8/2026 | Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability | |
| Modificada | Media (5.3) | 0.50% | — | Microsoft Azure File Sync | 13/2/2024 | 10/8/2026 | Microsoft Azure File Sync Elevation of Privilege Vulnerability | |
| Modificada | Media (6.8) | 0.42% | — | Microsoft Azure Active Directory | 13/2/2024 | 10/8/2026 | Microsoft Azure Active Directory B2C Spoofing Vulnerability |