Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

618 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.9)0.78%—Microsoft Azure Managed Instance FOR Apache Cassandra7/5/202617/6/2026
Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.
AnalizadaMedia (6.1)0.55%—Microsoft Azure Machine Learning7/5/202617/6/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network.
AnalizadaMedia (5.9)0.38%—Opentelemetry.resources.azure6/5/202617/6/2026
OpenTelemetry.Resources.Azure is the .NET resource detector for Azure environments. In versions 1.15.0-beta.1 and earlier, the AzureVmMetaDataRequestor class makes HTTP requests to the Azure VM instance metadata service and reads the response body into memory without any size limit. An attacker who controls the…
AnalizadaMedia (4.3)0.33%—Jenkins Azure AD29/4/202617/6/2026
Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.
AnalizadaCrítica (9.9)0.70%—Microsoft Azure IOT Central24/4/202617/6/2026
Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (7.8)2.5%—Microsoft Azure Monitor Agent14/4/202617/6/2026
Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (8.8)0.78%—Microsoft Azure Logic Apps14/4/202617/6/2026
Insufficiently protected credentials in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (7.8)0.33%—Microsoft Azure Monitor Agent14/4/202617/6/2026
Improper input validation in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
AnalizadaCrítica (9.8)0.90%—Microsoft Azure Databricks3/4/202624/7/2026
Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.8)0.90%—Microsoft Azure Kubernetes Service3/4/202624/7/2026
Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.8)0.90%—Microsoft Azure AI Foundry3/4/202624/7/2026
Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
AnalizadaAlta (7.5)1.00%—Microsoft Azure WEB Apps3/4/202624/7/2026
Missing authentication for critical function in Azure MCP Server allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (7.5)1.1%—Microsoft Azure SRE Agent3/4/202624/7/2026
Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (8.8)0.75%—Microsoft Azure Custom Locations Resource Provider3/4/202624/7/2026
Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (8.1)0.43%💥 PoCPab1it0 Azure Data Explorer MCP Server27/3/202617/6/2026
Azure Data Explorer MCP Server is a Model Context Protocol (MCP) server that enables AI assistants to execute KQL queries and explore Azure Data Explorer (ADX/Kusto) databases through standardized interfaces. Versions up to and including 0.1.1 contain KQL (Kusto Query Language) injection vulnerabilities in three MCP…
AnalizadaCrítica (9.8)0.90%—Microsoft Azure Cloud Shell19/3/202617/6/2026
Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network.
AnalizadaAlta (7.5)0.80%—Microsoft Azure Data Factory19/3/202617/6/2026
Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disclose information over a network.
AnalizadaCrítica (9.8)0.78%—Microsoft Azure Devops19/3/202617/6/2026
Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
AplazadaAlta (8.7)0.43%—Craftcms Azure Blob StorageAICraftcms Craft CMSAI18/3/202617/6/2026
The Azure Blob Storage for Craft CMS plugin provides an Azure Blob Storage integration for Craft CMS. In versions on the 2.x branch prior to 2.1.1, unauthenticated users can view a list of buckets the plugin has access to. The `DefaultController->actionLoadContainerData()` endpoint allows unauthenticated users with a…
AnalizadaAlta (8.1)0.30%—Microsoft Azure AD SSH Login Extension FOR Linux10/3/202617/6/2026
External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.31%—Microsoft Azure Automation Hybrid Worker Windows Extension10/3/202617/6/2026
Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.5)1.1%—Microsoft Azure IOT Explorer10/3/202617/6/2026
Server-side request forgery (ssrf) in Azure IoT Explorer allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (8.8)0.89%💥 PoCMicrosoft Azure MCP Server10/3/202617/6/2026
Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (7.8)0.31%—Microsoft ARC Enabled Servers Azure Connected Machine Agent10/3/202617/6/2026
Authentication bypass using an alternate path or channel in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.5)1.0%—Microsoft Azure IOT Explorer10/3/202617/6/2026
Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.