Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
618 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 2.2% | — | Microsoft Azure Identity SDK | 10/10/2023 | 17/6/2026 | Azure Identity SDK Remote Code Execution Vulnerability | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Alta (7.2) | 2.0% | — | Microsoft Azure Hdinsight | 12/9/2023 | 17/6/2026 | Azure HDInsight Apache Ambari JDBC Injection Elevation of Privilege Vulnerability | |
| Modificada | Alta (8.1) | 1.3% | — | Microsoft Azure Devops Server | 12/9/2023 | 17/6/2026 | Azure DevOps Server Remote Code Execution Vulnerability | |
| Modificada | Alta (8.8) | 1.7% | — | Microsoft Azure Devops Server | 12/9/2023 | 17/6/2026 | Azure DevOps Server Remote Code Execution Vulnerability | |
| Modificada | Crítica (9.8) | 2.7% | — | Microsoft Azure Kubernetes Service | 12/9/2023 | 17/6/2026 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.5) | 0.81% | — | Jenkins Azure AD | 6/9/2023 | 17/6/2026 | Jenkins Azure AD Plugin 396.v86ce29279947 and earlier, except 378.380.v545b_1154b_3fb_, uses a non-constant time comparison function when checking whether the provided and expected CSRF protection nonce are equal, potentially allowing attackers to use statistical methods to obtain a valid nonce. | |
| Modificada | Media (5.4) | 0.38% | — | Wpazure Upfrontwp | 10/8/2023 | 17/6/2026 | Auth. (subscriber+) Reflected Cross-site Scripting (XSS) vulnerability in Wpazure Themes Upfrontwp theme <= 1.1 versions. | |
| Modificada | Media (4.5) | 1.0% | — | Microsoft Azure Hdinsight | 8/8/2023 | 10/8/2026 | Azure Apache Hadoop Spoofing Vulnerability | |
| Modificada | Alta (7) | 0.39% | — | Microsoft Azure Arc-enabled Servers | 8/8/2023 | 10/8/2026 | Azure Arc-Enabled Servers Elevation of Privilege Vulnerability | |
| Modificada | Media (4.5) | 1.0% | — | Microsoft Azure Hdinsight | 8/8/2023 | 10/8/2026 | Azure Apache Ambari Spoofing Vulnerability | |
| Modificada | Media (4.5) | 1.0% | — | Microsoft Azure Hdinsight | 8/8/2023 | 10/8/2026 | Azure Apache Oozie Spoofing Vulnerability | |
| Modificada | Media (6.3) | 0.69% | — | Microsoft Azure Devops Server | 8/8/2023 | 10/8/2026 | Azure DevOps Server Spoofing Vulnerability | |
| Modificada | Media (4.6) | 0.97% | — | Microsoft Azure Hdinsight | 8/8/2023 | 10/8/2026 | Azure HDInsight Jupyter Notebook Spoofing Vulnerability | |
| Modificada | Media (4.5) | 1.4% | — | Microsoft Azure Hdinsight | 8/8/2023 | 10/8/2026 | Azure Apache Hive Spoofing Vulnerability | |
| Modificada | Media (6.5) | 0.69% | — | Microsoft Azure Service Fabric | 11/7/2023 | 17/6/2026 | Azure Service Fabric on Windows Information Disclosure Vulnerability | |
| Modificada | Media (5.5) | 0.68% | — | Microsoft Azure Devops Server | 14/6/2023 | 17/6/2026 | Azure DevOps Server Spoofing Vulnerability | |
| Modificada | Alta (7.1) | 0.93% | — | Microsoft Azure Devops Server | 14/6/2023 | 17/6/2026 | Azure DevOps Server Spoofing Vulnerability | |
| Modificada | Baja (3.3) | 0.49% | — | Microsoft Azure ARC Jumpstart | 18/5/2023 | 17/6/2026 | Azure Arc Jumpstart Information Disclosure Vulnerability | |
| Modificada | Media (6.5) | 0.58% | — | Jenkins Azure VM Agents | 16/5/2023 | 17/6/2026 | A missing permission check in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified Azure Cloud server using attacker-specified credentials IDs obtained through another method. | |
| Modificada | Alta (8.8) | 0.45% | — | Jenkins Azure VM Agents | 16/5/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers to connect to an attacker-specified Azure Cloud server using attacker-specified credentials IDs obtained through another method. | |
| Modificada | Media (4.3) | 0.50% | — | Jenkins Azure VM Agents | 16/5/2023 | 17/6/2026 | A missing permission check in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Modificada | Alta (7.5) | 0.48% | — | Jenkins Azure KEY Vault | 12/4/2023 | 17/6/2026 | Jenkins Azure Key Vault Plugin 187.va_cd5fecd198a_ and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled. | |
| Modificada | Media (6.5) | 1.5% | — | Microsoft Azure Machine Learning | 11/4/2023 | 17/6/2026 | Azure Machine Learning Information Disclosure Vulnerability | |
| Modificada | Alta (7.5) | 0.98% | — | Microsoft Azure Service Connector | 11/4/2023 | 17/6/2026 | Azure Service Connector Security Feature Bypass Vulnerability |