Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
618 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.9) | 0.78% | — | Microsoft Azure Managed Instance FOR Apache Cassandra | 7/5/2026 | 17/6/2026 | Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. | |
| Analizada | Media (6.1) | 0.55% | — | Microsoft Azure Machine Learning | 7/5/2026 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.9) | 0.38% | — | Opentelemetry.resources.azure | 6/5/2026 | 17/6/2026 | OpenTelemetry.Resources.Azure is the .NET resource detector for Azure environments. In versions 1.15.0-beta.1 and earlier, the AzureVmMetaDataRequestor class makes HTTP requests to the Azure VM instance metadata service and reads the response body into memory without any size limit. An attacker who controls the… | |
| Analizada | Media (4.3) | 0.33% | — | Jenkins Azure AD | 29/4/2026 | 17/6/2026 | Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks. | |
| Analizada | Crítica (9.9) | 0.70% | — | Microsoft Azure IOT Central | 24/4/2026 | 17/6/2026 | Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.8) | 2.5% | — | Microsoft Azure Monitor Agent | 14/4/2026 | 17/6/2026 | Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Azure Logic Apps | 14/4/2026 | 17/6/2026 | Insufficiently protected credentials in Azure Logic Apps allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft Azure Monitor Agent | 14/4/2026 | 17/6/2026 | Improper input validation in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. | |
| Analizada | Crítica (9.8) | 0.90% | — | Microsoft Azure Databricks | 3/4/2026 | 24/7/2026 | Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 0.90% | — | Microsoft Azure Kubernetes Service | 3/4/2026 | 24/7/2026 | Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 0.90% | — | Microsoft Azure AI Foundry | 3/4/2026 | 24/7/2026 | Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.5) | 1.00% | — | Microsoft Azure WEB Apps | 3/4/2026 | 24/7/2026 | Missing authentication for critical function in Azure MCP Server allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (7.5) | 1.1% | — | Microsoft Azure SRE Agent | 3/4/2026 | 24/7/2026 | Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (8.8) | 0.75% | — | Microsoft Azure Custom Locations Resource Provider | 3/4/2026 | 24/7/2026 | Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.1) | 0.43% | 💥 PoC | Pab1it0 Azure Data Explorer MCP Server | 27/3/2026 | 17/6/2026 | Azure Data Explorer MCP Server is a Model Context Protocol (MCP) server that enables AI assistants to execute KQL queries and explore Azure Data Explorer (ADX/Kusto) databases through standardized interfaces. Versions up to and including 0.1.1 contain KQL (Kusto Query Language) injection vulnerabilities in three MCP… | |
| Analizada | Crítica (9.8) | 0.90% | — | Microsoft Azure Cloud Shell | 19/3/2026 | 17/6/2026 | Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.5) | 0.80% | — | Microsoft Azure Data Factory | 19/3/2026 | 17/6/2026 | Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Crítica (9.8) | 0.78% | — | Microsoft Azure Devops | 19/3/2026 | 17/6/2026 | Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Alta (8.7) | 0.43% | — | Craftcms Azure Blob StorageAICraftcms Craft CMSAI | 18/3/2026 | 17/6/2026 | The Azure Blob Storage for Craft CMS plugin provides an Azure Blob Storage integration for Craft CMS. In versions on the 2.x branch prior to 2.1.1, unauthenticated users can view a list of buckets the plugin has access to. The `DefaultController->actionLoadContainerData()` endpoint allows unauthenticated users with a… | |
| Analizada | Alta (8.1) | 0.30% | — | Microsoft Azure AD SSH Login Extension FOR Linux | 10/3/2026 | 17/6/2026 | External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.31% | — | Microsoft Azure Automation Hybrid Worker Windows Extension | 10/3/2026 | 17/6/2026 | Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.5) | 1.1% | — | Microsoft Azure IOT Explorer | 10/3/2026 | 17/6/2026 | Server-side request forgery (ssrf) in Azure IoT Explorer allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (8.8) | 0.89% | 💥 PoC | Microsoft Azure MCP Server | 10/3/2026 | 17/6/2026 | Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.8) | 0.31% | — | Microsoft ARC Enabled Servers Azure Connected Machine Agent | 10/3/2026 | 17/6/2026 | Authentication bypass using an alternate path or channel in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.5) | 1.0% | — | Microsoft Azure IOT Explorer | 10/3/2026 | 17/6/2026 | Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. |