Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

618 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.77%—Microsoft Azure AI BOT Service18/6/202624/6/2026
Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.8)0.97%—Microsoft Azure Stack Edge9/6/202623/7/2026
External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.2)0.35%—Microsoft Azure Network Adapter9/6/202623/7/2026
Use after free in Linux MANA Driver allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (8.4)0.83%—Microsoft Azure Stack Edge9/6/202623/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (8.8)0.37%—Microsoft Azure Kubernetes Service9/6/202623/7/2026
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally.
AnalizadaCrítica (9.8)0.92%—Microsoft Azure Horizondb4/6/202623/7/2026
Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.8)0.90%—Microsoft Azure Resource Manager22/5/202623/7/2026
Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.8)0.97%—Microsoft Azure Orbital Spatio22/5/202623/7/2026
Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.96%—Microsoft Azure Virtual Network Gateway22/5/202623/7/2026
Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.78%—Microsoft Azure Privileged Identity Management22/5/202623/7/2026
Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (7.7)1.0%—Microsoft Azure Stack HCI22/5/202623/7/2026
Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network.
AnalizadaCrítica (10)0.90%—Microsoft Azure LocalMicrosoft Azure Resource Manager18/5/202617/6/2026
Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.
AnalizadaMedia (6.5)0.64%—Microsoft Azure Monitor Agent12/5/202617/6/2026
Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
AnalizadaCrítica (9.9)0.78%—Microsoft Azure Logic Apps12/5/202617/6/2026
Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (7.8)0.30%—Microsoft Azure Connected Machine Agent12/5/202617/6/2026
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (8.2)0.54%—Microsoft Azure Machine Learning12/5/202618/6/2026
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network.
ModificadaCrítica (9.1)0.50%—Microsoft Azure SDK FOR Java12/5/202617/6/2026
The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag comparison was implemented incorrectly. In affected applications that use the vulnerable local cryptography path, specially crafted encrypted input may bypass integrity…
AnalizadaAlta (7.8)0.36%—Microsoft Azure Monitor Agent12/5/202618/6/2026
External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
AnalizadaCrítica (9.6)1.1%⚠ Explotación activa💥 PoCTanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+16712/5/202617/6/2026
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The…
AplazadaMedia (6.5)0.48%—Microsoft Kafka Sink Azure KustoAIApache KafkaAIMicrosoft Azure Data ExplorerAI11/5/202617/6/2026
kafka-sink-azure-kusto Kafka Connect plugin is the official Microsoft sink for Azure Data Explorer (Kusto). Prior to 5.2.3, kafka-sink-azure-kusto did not sanitize user-controlled values inside the kusto.tables.topics.mapping configuration. The db, table, mapping, and format fields of each mapping entry were…
AnalizadaAlta (7.5)1.2%💥 PoCMicrosoft Azure Devops7/5/202617/6/2026
Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (8.1)0.69%—Microsoft Azure Monitor Action Group Notification System7/5/202617/6/2026
Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network.
AnalizadaCrítica (10)1.1%—Microsoft Azure AI Foundry7/5/202617/6/2026
Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.6)0.86%—Microsoft Azure Cloud Shell7/5/202617/6/2026
Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform spoofing over a network.
ModificadaCrítica (9)0.81%—Microsoft Azure Managed Instance FOR Apache Cassandra7/5/202617/6/2026
Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.
Orbitaley — Vulnerabilidades