Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2709▼ 126 respecto a la semana anterior
Críticas / altas1231▼ 312 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)257▲ 221 respecto a la semana anterior
–

18.401 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (10)0.80%—Microsoft Azure SQL Database21/8/20264/9/2026
Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
AplazadaMedia (5.3)0.44%—Prospero Flow CRMAI21/8/20261/9/2026
Authorization Bypass Through User-Controlled Key in the transaction save endpoint in Roskus Prospero Flow CRM 4.9.1 through 5.14.0 allows a user with transaction and accounting creation permissions to disclose another company's bank account name, bank name and card last four digits via a bank_account_id or…
AplazadaAlta (8.7)0.51%—Roskus Prospero Flow CRMAI21/8/20261/9/2026
Authorization Bypass Through User-Controlled Key in the transaction API in Roskus Prospero Flow CRM 5.0.0 through 5.3.5 allows an authenticated user to read the transactions of other companies on the same instance via an incremented identifier in GET /api/transaction/{id}, which is resolved without company scoping and…
AnalizadaAlta (7.5)0.97%—Microsoft 365Microsoft OfficeMicrosoft Office 2021Microsoft Office 2024+120/8/20264/9/2026
Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
AnalizadaMedia (6.5)0.84%—Microsoft Azure Copilot20/8/20268/9/2026
Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.
AnalizadaCrítica (9.9)0.78%—Microsoft Entra ID20/8/202625/8/2026
Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
AnalizadaCrítica (10)1.5%💥 PoCMicrosoft Entra ID20/8/202625/8/2026
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.6)0.97%—Microsoft Partner Center20/8/202625/8/2026
Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.
AnalizadaCrítica (10)0.80%—Microsoft Azure ARC20/8/202624/8/2026
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
AnalizadaAlta (8.5)0.56%—Microsoft Azure Virtual Machines20/8/202626/8/2026
Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (8.6)1.0%—Microsoft Azure Stack HCI20/8/202625/8/2026
Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (8.8)0.74%—Microsoft Azure Data Manager FOR Energy20/8/20264/9/2026
Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network.
AnalizadaCrítica (9.6)0.94%—Microsoft Azure Logic Apps20/8/202624/8/2026
Una limitación incorrecta de una ruta a un directorio restringido ('path traversal') en Azure Logic Apps permite a un atacante no autorizado elevar privilegios a través de una red.
AnalizadaCrítica (9.9)0.99%—Microsoft Azure SQL Database20/8/202624/8/2026
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.9)0.99%—Microsoft Azure SQL Database20/8/202624/8/2026
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (7.5)0.97%—Microsoft Azure Data Factory20/8/202624/8/2026
Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.
AnalizadaCrítica (9.1)0.86%—Microsoft Azure SQL Database20/8/202624/8/2026
Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
AnalizadaCrítica (10)0.97%—Microsoft Azure WEB Apps20/8/202624/8/2026
Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (10)0.90%—Microsoft Exchange Online20/8/202624/8/2026
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (10)1.1%—Microsoft Azure Managed Instance FOR Apache Cassandra20/8/202625/8/2026
Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.8)1.0%—Microsoft Fabric20/8/20264/9/2026
Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.8)0.53%—Microsoft Azure Data Factory20/8/202624/8/2026
Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.
AnalizadaMedia (5.5)0.98%—Microsoft Remote Help20/8/202626/8/2026
Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally.
AnalizadaAlta (7.1)0.46%—Microsoft Remote Help20/8/202626/8/2026
Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally.
AplazadaMedia (6.9)0.42%—Kerberos AgentAI20/8/202618/9/2026
Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the Kerberos Hub upload path sends the agent's Hub credentials in the custom `X-Kerberos-Hub-PrivateKey` and `X-Kerberos-Hub-PublicKey` request headers to the operator-configured Hub URL (`config.HubURI`). The HTTP client…