Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
618 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.6) | 1.0% | — | Microsoft Azure Stack HCI | 20/8/2026 | 25/8/2026 | Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (8.8) | 0.74% | — | Microsoft Azure Data Manager FOR Energy | 20/8/2026 | 4/9/2026 | Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network. | |
| Analizada | Crítica (9.6) | 0.94% | — | Microsoft Azure Logic Apps | 20/8/2026 | 24/8/2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.9) | 0.99% | — | Microsoft Azure SQL Database | 20/8/2026 | 24/8/2026 | Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.9) | 0.99% | — | Microsoft Azure SQL Database | 20/8/2026 | 24/8/2026 | Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.5) | 0.97% | — | Microsoft Azure Data Factory | 20/8/2026 | 24/8/2026 | Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Crítica (9.1) | 0.86% | — | Microsoft Azure SQL Database | 20/8/2026 | 24/8/2026 | Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (10) | 0.97% | — | Microsoft Azure WEB Apps | 20/8/2026 | 24/8/2026 | Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (10) | 1.1% | — | Microsoft Azure Managed Instance FOR Apache Cassandra | 20/8/2026 | 25/8/2026 | Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network. | |
| Analizada | Crítica (9.8) | 0.53% | — | Microsoft Azure Data Factory | 20/8/2026 | 24/8/2026 | Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network. | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | Splunk SoarAIMicrosoft Azure AD GraphAI | 19/8/2026 | 20/8/2026 | In versions below 2.5.3 of the Azure AD Graph app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive password by invoking the reset password action, because the action's temp_password parameter is not masked and is shown in cleartext in the user interface. The information… | |
| Aplazada | Media (5.4) | 0.38% | — | Next-tinacms-s3AINext-tinacms-dosAINext-tinacms-azureAINext-tinacms-cloudinaryAI | 19/8/2026 | 18/9/2026 | Tina is a headless content management system. Prior to next-tinacms-s3 23.0.4, next-tinacms-dos 23.0.4, next-tinacms-azure 14.0.4, and next-tinacms-cloudinary 26.0.4, the first-party production media adapters pass attacker-controlled object keys to storage SDK upload and delete operations without enforcing the… | |
| Aplazada | Alta (7.2) | 0.68% | — | Flow-likeAIMicrosoft Azure Blob StorageAI | 19/8/2026 | 18/9/2026 | Flow-Like is a platform for building end-to-end use cases. Prior to version 1.0.4, `GET /api/v1/apps/{app_id}/invoke/presign` grants Azure Blob Storage SAS credentials with write and delete access to app content to any app member that has `ExecuteEvents`, even when that member lacks `ReadFiles` and `WriteFiles`. The… | |
| Pendiente de análisis | Alta (8.7) | 0.43% | — | RenovateAIMicrosoft Azure DevopsAI | 19/8/2026 | 8/9/2026 | Renovate versions >=19.180.0 and <23.25.1, when used with Azure DevOps, may expose the bot's authorization token in server or pipeline logs because the git http.extraheader=AUTHORIZATION parameter is logged without redaction. Anyone with access to saved logs could obtain the bot credentials. Fixed in 23.25.1; Azure… | |
| Analizada | Alta (8.8) | 0.80% | — | Microsoft Azure Cyclecloud | 11/8/2026 | 17/8/2026 | Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Media (6.5) | 0.84% | — | Microsoft Azure Cyclecloud | 11/8/2026 | 17/8/2026 | Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network. | |
| Analizada | Alta (7.8) | 0.30% | — | Microsoft Azure SQL Database | 11/8/2026 | 17/8/2026 | Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally. | |
| Analizada | Crítica (9.6) | 0.86% | — | Microsoft Azure Storage Explorer | 11/8/2026 | 17/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.4) | 0.83% | — | Microsoft Azure Kubernetes Service | 11/8/2026 | 12/8/2026 | Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.2) | 1.0% | — | Microsoft Azure Monitor Agent | 11/8/2026 | 13/8/2026 | Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network. | |
| Pendiente de análisis | Media (5.3) | 0.36% | — | Apache AirflowAIApache Airflow-providers-microsoft-azureAI | 10/8/2026 | 16/9/2026 | The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with this backend, a caller in one team could resolve a secret belonging to… | |
| Analizada | Crítica (9.1) | 0.93% | — | Microsoft Azure Confidential Ledger | 7/8/2026 | 7/8/2026 | Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network. | |
| Analizada | Crítica (10) | 0.65% | — | Microsoft Azure SQL Managed Instance | 7/8/2026 | 12/8/2026 | Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.9) | 0.78% | — | Microsoft Azure SRE Agent | 7/8/2026 | 7/8/2026 | Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (10) | 0.90% | — | Microsoft Azure SQL Database | 7/8/2026 | 8/8/2026 | Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. |