Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

618 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.75%—Microsoft Azure IOT Explorer10/3/202617/6/2026
Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (7.5)0.73%—Microsoft Azure IOT Explorer10/3/202617/6/2026
Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
AplazadaCrítica (9.8)0.73%—Miniorange ALL IN ONE Microsoft 365 Entra ID Azure AD SSO LoginAI3/3/202617/6/2026
The All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.2.5. This makes it possible for unauthenticated attackers to bypass authentication and log in as other users, including administrators.
AnalizadaCrítica (9.8)2.5%💥 PoCMicrosoft Azure Conversation Authoring Client Library10/2/202617/6/2026
Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.
AnalizadaMedia (5.4)0.66%—Microsoft Azure Hdinsight10/2/202617/6/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsights allows an authorized attacker to perform spoofing over a network.
ModificadaMedia (6.5)0.54%—Microsoft Azure IOT Explorer10/2/202617/6/2026
Binding to an unrestricted ip address in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
AnalizadaMedia (6.5)1.0%—Microsoft Azure Devops Server10/2/202617/6/2026
Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (8.1)0.77%—Microsoft Azure Local10/2/202617/6/2026
Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over a network.
ModificadaCrítica (9.8)1.5%—Microsoft Azure ARC5/2/202617/6/2026
Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.8)1.2%—Microsoft Azure Front Door5/2/202617/6/2026
Azure Front Door Elevation of Privilege Vulnerability
AnalizadaAlta (8.2)0.90%—Microsoft Azure Functions5/2/202617/6/2026
Azure Function Information Disclosure Vulnerability
ModificadaAlta (8.8)0.68%—Microsoft Azure Resource Manager23/1/202630/7/2026
Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.8)0.86%💥 PoCMicrosoft Azure Front Door22/1/202617/6/2026
Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network.
AnalizadaAlta (7.4)0.60%—Microsoft Azure Data Explorer22/1/202617/6/2026
Exposure of sensitive information to an unauthorized actor in Azure Data Explorer allows an unauthorized attacker to disclose information over a network.
AnalizadaCrítica (9.8)0.56%—Microsoft Azure Logic Apps22/1/202617/6/2026
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
AnalizadaAlta (7.5)0.93%—Microsoft Azure Core Shared Client Library13/1/202617/6/2026
Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execute code over a network.
AnalizadaAlta (7.8)0.32%—Microsoft Azure Connected Machine Agent13/1/202617/6/2026
Stack-based buffer overflow in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
AnalizadaCrítica (9.6)0.71%—Microsoft Azure Cosmos DB19/12/202517/6/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauthorized attacker to perform spoofing over a network.
AnalizadaCrítica (10)0.97%—Microsoft Azure Container Apps18/12/202517/6/2026
Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.71%—Microsoft Azure Language18/12/202517/6/2026
Custom Question Answering Elevation of Privilege Vulnerability
AnalizadaAlta (8.8)0.74%—Microsoft Azure Monitor Agent9/12/202517/6/2026
Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network.
ModificadaCrítica (9.8)0.62%—Microsoft Azure Application Gateway26/11/202517/6/2026
Stack-based buffer overflow in Azure Application Gateway allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.8)0.62%—Microsoft Azure Application Gateway26/11/202517/6/2026
Out-of-bounds read in Application Gateway allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.8)0.71%—Microsoft Azure Monitor20/11/202517/6/2026
Azure Monitor Elevation of Privilege Vulnerability
AnalizadaCrítica (10)0.91%—Microsoft Azure Bastion Developer20/11/202517/6/2026
Azure Bastion Elevation of Privilege Vulnerability
Orbitaley — Vulnerabilidades