Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2779▼ 337 respecto a la semana anterior
Críticas / altas1284▼ 248 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▼ 88 respecto a la semana anterior
16.783 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.51% | — | Microsoft UFOAI | 21/8/2026 | 9/9/2026 | Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, ufo/client/mcp/http_servers/linux_mcp_server.py binds a FastMCP streamable HTTP server to localhost:8010 but does not validate the Host, Origin, or Sec-Fetch-Site headers. An attacker-controlled web page can… | |
| Analizada | Crítica (10) | 0.80% | — | Microsoft Azure SQL Database | 21/8/2026 | 4/9/2026 | Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.5) | 0.97% | — | Microsoft 365Microsoft OfficeMicrosoft Office 2021Microsoft Office 2024+1 | 20/8/2026 | 4/9/2026 | Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (6.5) | 0.84% | — | Microsoft Azure Copilot | 20/8/2026 | 8/9/2026 | Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network. | |
| Analizada | Crítica (9.9) | 0.78% | — | Microsoft Entra ID | 20/8/2026 | 25/8/2026 | Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (10) | 1.5% | 💥 PoC | Microsoft Entra ID | 20/8/2026 | 25/8/2026 | Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.6) | 0.97% | — | Microsoft Partner Center | 20/8/2026 | 25/8/2026 | Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Crítica (10) | 0.80% | — | Microsoft Azure ARC | 20/8/2026 | 24/8/2026 | Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.5) | 0.56% | — | Microsoft Azure Virtual Machines | 20/8/2026 | 26/8/2026 | Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.6) | 1.0% | — | Microsoft Azure Stack HCI | 20/8/2026 | 25/8/2026 | Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (8.8) | 0.74% | — | Microsoft Azure Data Manager FOR Energy | 20/8/2026 | 4/9/2026 | Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network. | |
| Analizada | Crítica (9.6) | 0.94% | — | Microsoft Azure Logic Apps | 20/8/2026 | 24/8/2026 | Una limitación incorrecta de una ruta a un directorio restringido ('path traversal') en Azure Logic Apps permite a un atacante no autorizado elevar privilegios a través de una red. | |
| Analizada | Crítica (9.9) | 0.99% | — | Microsoft Azure SQL Database | 20/8/2026 | 24/8/2026 | Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.9) | 0.99% | — | Microsoft Azure SQL Database | 20/8/2026 | 24/8/2026 | Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.5) | 0.97% | — | Microsoft Azure Data Factory | 20/8/2026 | 24/8/2026 | Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Crítica (9.1) | 0.86% | — | Microsoft Azure SQL Database | 20/8/2026 | 24/8/2026 | Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (10) | 0.97% | — | Microsoft Azure WEB Apps | 20/8/2026 | 24/8/2026 | Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (10) | 0.90% | — | Microsoft Exchange Online | 20/8/2026 | 24/8/2026 | Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (10) | 1.1% | — | Microsoft Azure Managed Instance FOR Apache Cassandra | 20/8/2026 | 25/8/2026 | Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 1.0% | — | Microsoft Fabric | 20/8/2026 | 4/9/2026 | Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 0.53% | — | Microsoft Azure Data Factory | 20/8/2026 | 24/8/2026 | Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Media (5.5) | 0.98% | — | Microsoft Remote Help | 20/8/2026 | 26/8/2026 | Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally. | |
| Analizada | Alta (7.1) | 0.46% | — | Microsoft Remote Help | 20/8/2026 | 26/8/2026 | Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally. | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | Splunk SoarAIMicrosoft Azure AD GraphAI | 19/8/2026 | 20/8/2026 | In versions below 2.5.3 of the Azure AD Graph app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive password by invoking the reset password action, because the action's temp_password parameter is not masked and is shown in cleartext in the user interface. The information… | |
| Modificada | Media (6.5) | 0.92% | — | Microsoft Windows APP | 19/8/2026 | 27/8/2026 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. |