Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
618 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.5) | 4.0% | 💥 Exploit | Microsoft Azure Hdinsight | 14/3/2023 | 17/6/2026 | Azure Apache Ambari Spoofing Vulnerability | |
| Modificada | Media (4.7) | 12% | — | Microsoft Azure Service Fabric | 14/3/2023 | 17/6/2026 | Service Fabric Explorer Spoofing Vulnerability | |
| Modificada | Alta (7) | 0.36% | — | Microsoft Azure Setup Kubectl | 6/3/2023 | 17/6/2026 | Azure/setup-kubectl is a GitHub Action for installing Kubectl. This vulnerability only impacts versions before version 3. An insecure temporary creation of a file allows other actors on the Actions runner to replace the Kubectl binary created by this action because it is world writable. This Kubectl tool installer… | |
| Modificada | Media (6.5) | 0.64% | — | Jenkins Azure Credentials | 15/2/2023 | 17/6/2026 | A missing permission check in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers with Overall/Read permission to connect to an attacker-specified web server. | |
| Modificada | Alta (8.8) | 0.46% | — | Jenkins Azure Credentials | 15/2/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers to connect to an attacker-specified web server. | |
| Modificada | Media (4.3) | 0.51% | — | Jenkins Azure Credentials | 15/2/2023 | 17/6/2026 | A missing permission check in Jenkins Azure Credentials Plugin 253.v887e0f9e898b and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Modificada | Alta (7.5) | 1.4% | — | Microsoft Azure Devops Server | 14/2/2023 | 19/8/2026 | Azure DevOps Server Remote Code Execution Vulnerability | |
| Modificada | Media (6.5) | 2.7% | — | Microsoft Azure Machine Learning | 14/2/2023 | 19/8/2026 | Azure Machine Learning Compute Instance Information Disclosure Vulnerability | |
| Modificada | Alta (8.7) | 0.35% | — | Microsoft Azure APP Service ON Azure Stack | 14/2/2023 | 19/8/2026 | Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.2) | 1.5% | — | Microsoft Azure Data BOX GatewayMicrosoft Azure Stack Edge | 14/2/2023 | 19/8/2026 | Azure Data Box Gateway Remote Code Execution Vulnerability | |
| Modificada | Alta (7.1) | 0.89% | — | Microsoft Azure Devops Server | 14/2/2023 | 19/8/2026 | Azure DevOps Server Cross-Site Scripting Vulnerability | |
| Modificada | Alta (8.8) | 1.0% | — | Jenkins Azure AD | 26/1/2023 | 17/6/2026 | Jenkins Azure AD Plugin 303.va_91ef20ee49f and earlier does not invalidate the previous session on login. | |
| Modificada | Alta (7) | 0.61% | — | Microsoft Azure Service Fabric | 10/1/2023 | 17/6/2026 | Azure Service Fabric Container Elevation of Privilege Vulnerability | |
| Modificada | Media (5.3) | 0.74% | — | Microsoft Azure AD POD Identity | 21/12/2022 | 17/6/2026 | aad-pod-identity assigns Azure Active Directory identities to Kubernetes applications and has now been deprecated as of 24 October 2022. The NMI component in AAD Pod Identity intercepts and validates token requests based on regex. In this case, a token request made with backslash in the request (example:… | |
| Modificada | Media (5.5) | 0.46% | — | Microsoft Azure Network Watcher Agent | 13/12/2022 | 17/6/2026 | Azure Network Watcher Agent Security Feature Bypass Vulnerability | |
| Modificada | Media (4.3) | 0.38% | — | Chocolatey Azure-pipelines-agent | 29/11/2022 | 17/6/2026 | Insecure permissions in Chocolatey Azure-Pipelines-Agent package v2.211.1 and below grants all users in the Authenticated Users group write privileges for the subfolder C:\agent and all files located in that folder. | |
| Modificada | Alta (8.8) | 0.71% | — | Microsoft Azure Cyclecloud | 9/11/2022 | 10/8/2026 | Azure CycleCloud Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.8) | 0.80% | — | Microsoft Azure Rtos Guix Studio | 9/11/2022 | 10/8/2026 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7) | 0.34% | — | Microsoft Azure IOT Edge FOR LinuxMicrosoft Windows Subsystem FOR Linux | 9/11/2022 | 10/8/2026 | Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.8) | 0.89% | — | Microsoft Azure Rtos Filex | 8/11/2022 | 17/6/2026 | Azure RTOS FileX is a FAT-compatible file system that’s fully integrated with Azure RTOS ThreadX. In versions before 6.2.0, the Fault Tolerant feature of Azure RTOS FileX includes integer under and overflows which may be exploited to achieve buffer overflow and modify memory contents. When a valid log file with… | |
| Modificada | Crítica (9.8) | 2.1% | — | Microsoft Azure Rtos Usbx | 4/11/2022 | 17/6/2026 | Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. Prior to version 6.1.12, the USB DFU UPLOAD functionality may be utilized to introduce a buffer overflow resulting in overwrite of memory contents. In particular cases this may allow an attacker… | |
| Modificada | Crítica (9.8) | 3.5% | — | Microsoft Azure Command-line Interface | 25/10/2022 | 17/6/2026 | Azure CLI is the command-line interface for Microsoft Azure. In versions previous to 2.40.0, Azure CLI contains a vulnerability for potential code injection. Critical scenarios are where a hosting machine runs an Azure CLI command where parameter values have been provided by an external source. The vulnerability is… | |
| Modificada | Crítica (10) | 2.6% | — | Microsoft Azure Arc-enabled KubernetesMicrosoft Azure Stack Edge | 11/10/2022 | 17/6/2026 | Microsoft has identified a vulnerability affecting the cluster connect feature of Azure Arc-enabled Kubernetes clusters. This vulnerability could allow an unauthenticated user to elevate their privileges and potentially gain administrative control over the Kubernetes cluster. Additionally, because Azure Stack Edge… | |
| Modificada | Media (4.8) | 18% | — | Microsoft Azure Service Fabric | 11/10/2022 | 17/6/2026 | Service Fabric Explorer Spoofing Vulnerability | |
| Modificada | Alta (7.8) | 0.69% | — | Microsoft Azure ARCMicrosoft Azure Guest Configuration | 13/9/2022 | 17/6/2026 | Azure Guest Configuration and Azure Arc-enabled servers Elevation of Privilege Vulnerability |