Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
618 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.4% | — | Dell EMC Integrated System FOR Microsoft Azure Stack HUB Firmware | 6/5/2021 | 17/6/2026 | Dell EMC Integrated System for Microsoft Azure Stack Hub, versions 1906 – 2011, contain an undocumented default iDRAC account. A remote unauthenticated attacker, with the knowledge of the default credentials, could potentially exploit this to log in to the system to gain root privileges. | |
| Modificada | Alta (7.8) | 0.48% | — | Microsoft Azure Sphere | 13/4/2021 | 17/6/2026 | Azure Sphere Unsigned Code Execution Vulnerability | |
| Modificada | Media (6.1) | 2.3% | — | Microsoft Azure Devops Server | 13/4/2021 | 17/6/2026 | Azure DevOps Server Spoofing Vulnerability | |
| Modificada | Media (6.5) | 2.6% | — | Microsoft Team Foundation ServerMicrosoft Azure Devops Server | 13/4/2021 | 17/6/2026 | Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability | |
| Modificada | Media (6.3) | 0.65% | — | Theforeman Foreman AzurermRedhat Satellite | 8/4/2021 | 17/6/2026 | A flaw was found in Red Hat Satellite in tfm-rubygem-foreman_azure_rm in versions before 2.2.0. A credential leak was identified which will expose Azure Resource Manager's secret key through JSON of the API output. The highest threat from this vulnerability is to data confidentiality and integrity as well as system… | |
| Modificada | Alta (8.8) | 1.3% | — | Microsoft Azure Sphere | 11/3/2021 | 19/8/2026 | Azure Sphere Unsigned Code Execution Vulnerability | |
| Modificada | Media (6.8) | 1.4% | — | Microsoft Azure Container InstancesMicrosoft Azure Container RegistryMicrosoft Azure Kubernetes ServiceMicrosoft Azure Service Fabric+1 | 11/3/2021 | 19/8/2026 | Azure Virtual Machine Information Disclosure Vulnerability | |
| Modificada | Media (5.5) | 1.3% | — | Microsoft Azure Sphere | 11/3/2021 | 19/8/2026 | Azure Sphere Unsigned Code Execution Vulnerability | |
| Modificada | Media (6.8) | 2.2% | — | Microsoft Azure Kubernetes Service | 25/2/2021 | 17/6/2026 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.8) | 0.49% | — | Azure-iot-cli-extension | 25/2/2021 | 17/6/2026 | Azure IoT CLI extension Elevation of Privilege Vulnerability | |
| Modificada | Media (6.5) | 1.4% | — | Google Secret Manager Provider FOR Secret Store CSI DriverHashicorp Vault Provider FOR Secrets Store CSI DriverMicrosoft Azure KEY Vault Provider FOR Secrets Store CSI Driver | 21/1/2021 | 17/6/2026 | Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass objects to write to arbitrary file paths on the host filesystem, including /var/lib/kubelet/pods. | |
| Modificada | Media (5.5) | 1.2% | — | Microsoft Azure Kubernetes Service | 12/1/2021 | 17/6/2026 | Azure Active Directory Pod Identity Spoofing Vulnerability | |
| Modificada | Media (5.5) | 1.3% | — | Microsoft Azure Sphere | 22/12/2020 | 17/6/2026 | A denial-of-service vulnerability exists in the asynchronous ioctl functionality of Microsoft Azure Sphere 20.05. A sequence of specially crafted ioctl calls can cause a denial of service. An attacker can write shellcode to trigger this vulnerability. | |
| Modificada | Alta (7.8) | 4.1% | — | Microsoft Azure Sphere | 22/12/2020 | 17/6/2026 | A code execution vulnerability exists in the normal world’s signed code execution functionality of Microsoft Azure Sphere 20.07. A specially crafted AF_PACKET socket can cause a process to create an executable memory mapping with controllable content. An attacker can execute a shellcode that uses the PACKET_MMAP… | |
| Modificada | Media (5.4) | 1.6% | — | Microsoft Team Foundation ServerMicrosoft Azure Devops Server | 10/12/2020 | 17/6/2026 | Azure DevOps Server and Team Foundation Services Spoofing Vulnerability | |
| Modificada | Media (5.4) | 1.3% | — | Microsoft Azure Devops Server | 10/12/2020 | 17/6/2026 | Azure DevOps Server Spoofing Vulnerability | |
| Modificada | Crítica (9.1) | 3.5% | — | Microsoft C SDK FOR Azure IOT | 10/12/2020 | 17/6/2026 | Azure SDK for C Security Feature Bypass Vulnerability | |
| Modificada | Crítica (9.1) | 4.3% | — | Microsoft Azure SDK FOR Java | 10/12/2020 | 17/6/2026 | Azure SDK for Java Security Feature Bypass Vulnerability | |
| Modificada | Media (5.4) | 1.6% | — | Microsoft Azure Devops Server | 11/11/2020 | 17/6/2026 | Azure DevOps Server and Team Foundation Services Spoofing Vulnerability | |
| Modificada | Media (5.5) | 1.6% | — | Microsoft Azure Sphere | 11/11/2020 | 17/6/2026 | Azure Sphere Unsigned Code Execution Vulnerability | |
| Modificada | Media (6.8) | 0.84% | — | Microsoft Azure Sphere | 11/11/2020 | 17/6/2026 | Azure Sphere Elevation of Privilege Vulnerability | |
| Modificada | Alta (8.2) | 1.4% | — | Microsoft Azure Sphere | 11/11/2020 | 17/6/2026 | Azure Sphere Elevation of Privilege Vulnerability | |
| Modificada | Media (5.5) | 1.7% | — | Microsoft Azure Sphere | 11/11/2020 | 17/6/2026 | Azure Sphere Unsigned Code Execution Vulnerability | |
| Modificada | Media (5.5) | 1.5% | — | Microsoft Azure Sphere | 11/11/2020 | 17/6/2026 | Azure Sphere Information Disclosure Vulnerability | |
| Modificada | Media (6.2) | 0.71% | — | Microsoft Azure Sphere | 11/11/2020 | 17/6/2026 | Azure Sphere Elevation of Privilege Vulnerability |