Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
618 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.77% | — | Microsoft Azure AI BOT Service | 18/6/2026 | 24/6/2026 | Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 0.97% | — | Microsoft Azure Stack Edge | 9/6/2026 | 23/7/2026 | External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.2) | 0.35% | — | Microsoft Azure Network Adapter | 9/6/2026 | 23/7/2026 | Use after free in Linux MANA Driver allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (8.4) | 0.83% | — | Microsoft Azure Stack Edge | 9/6/2026 | 23/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Alta (8.8) | 0.37% | — | Microsoft Azure Kubernetes Service | 9/6/2026 | 23/7/2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally. | |
| Analizada | Crítica (9.8) | 0.92% | — | Microsoft Azure Horizondb | 4/6/2026 | 23/7/2026 | Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 0.90% | — | Microsoft Azure Resource Manager | 22/5/2026 | 23/7/2026 | Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 0.97% | — | Microsoft Azure Orbital Spatio | 22/5/2026 | 23/7/2026 | Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.96% | — | Microsoft Azure Virtual Network Gateway | 22/5/2026 | 23/7/2026 | Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Azure Privileged Identity Management | 22/5/2026 | 23/7/2026 | Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.7) | 1.0% | — | Microsoft Azure Stack HCI | 22/5/2026 | 23/7/2026 | Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network. | |
| Analizada | Crítica (10) | 0.90% | — | Microsoft Azure LocalMicrosoft Azure Resource Manager | 18/5/2026 | 17/6/2026 | Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Media (6.5) | 0.64% | — | Microsoft Azure Monitor Agent | 12/5/2026 | 17/6/2026 | Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. | |
| Analizada | Crítica (9.9) | 0.78% | — | Microsoft Azure Logic Apps | 12/5/2026 | 17/6/2026 | Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.8) | 0.30% | — | Microsoft Azure Connected Machine Agent | 12/5/2026 | 17/6/2026 | Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (8.2) | 0.54% | — | Microsoft Azure Machine Learning | 12/5/2026 | 18/6/2026 | Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network. | |
| Modificada | Crítica (9.1) | 0.50% | — | Microsoft Azure SDK FOR Java | 12/5/2026 | 17/6/2026 | The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag comparison was implemented incorrectly. In affected applications that use the vulnerable local cryptography path, specially crafted encrypted input may bypass integrity… | |
| Analizada | Alta (7.8) | 0.36% | — | Microsoft Azure Monitor Agent | 12/5/2026 | 18/6/2026 | External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. | |
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa💥 PoC | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Aplazada | Media (6.5) | 0.48% | — | Microsoft Kafka Sink Azure KustoAIApache KafkaAIMicrosoft Azure Data ExplorerAI | 11/5/2026 | 17/6/2026 | kafka-sink-azure-kusto Kafka Connect plugin is the official Microsoft sink for Azure Data Explorer (Kusto). Prior to 5.2.3, kafka-sink-azure-kusto did not sanitize user-controlled values inside the kusto.tables.topics.mapping configuration. The db, table, mapping, and format fields of each mapping entry were… | |
| Analizada | Alta (7.5) | 1.2% | 💥 PoC | Microsoft Azure Devops | 7/5/2026 | 17/6/2026 | Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (8.1) | 0.69% | — | Microsoft Azure Monitor Action Group Notification System | 7/5/2026 | 17/6/2026 | Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (10) | 1.1% | — | Microsoft Azure AI Foundry | 7/5/2026 | 17/6/2026 | Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.6) | 0.86% | — | Microsoft Azure Cloud Shell | 7/5/2026 | 17/6/2026 | Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform spoofing over a network. | |
| Modificada | Crítica (9) | 0.81% | — | Microsoft Azure Managed Instance FOR Apache Cassandra | 7/5/2026 | 17/6/2026 | Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. |