Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
618 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.75% | — | Microsoft Azure IOT Explorer | 10/3/2026 | 17/6/2026 | Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (7.5) | 0.73% | — | Microsoft Azure IOT Explorer | 10/3/2026 | 17/6/2026 | Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. | |
| Aplazada | Crítica (9.8) | 0.73% | — | Miniorange ALL IN ONE Microsoft 365 Entra ID Azure AD SSO LoginAI | 3/3/2026 | 17/6/2026 | The All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.2.5. This makes it possible for unauthenticated attackers to bypass authentication and log in as other users, including administrators. | |
| Analizada | Crítica (9.8) | 2.5% | 💥 PoC | Microsoft Azure Conversation Authoring Client Library | 10/2/2026 | 17/6/2026 | Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network. | |
| Analizada | Media (5.4) | 0.66% | — | Microsoft Azure Hdinsight | 10/2/2026 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsights allows an authorized attacker to perform spoofing over a network. | |
| Modificada | Media (6.5) | 0.54% | — | Microsoft Azure IOT Explorer | 10/2/2026 | 17/6/2026 | Binding to an unrestricted ip address in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (6.5) | 1.0% | — | Microsoft Azure Devops Server | 10/2/2026 | 17/6/2026 | Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Alta (8.1) | 0.77% | — | Microsoft Azure Local | 10/2/2026 | 17/6/2026 | Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over a network. | |
| Modificada | Crítica (9.8) | 1.5% | — | Microsoft Azure ARC | 5/2/2026 | 17/6/2026 | Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 1.2% | — | Microsoft Azure Front Door | 5/2/2026 | 17/6/2026 | Azure Front Door Elevation of Privilege Vulnerability | |
| Analizada | Alta (8.2) | 0.90% | — | Microsoft Azure Functions | 5/2/2026 | 17/6/2026 | Azure Function Information Disclosure Vulnerability | |
| Modificada | Alta (8.8) | 0.68% | — | Microsoft Azure Resource Manager | 23/1/2026 | 30/7/2026 | Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 0.86% | 💥 PoC | Microsoft Azure Front Door | 22/1/2026 | 17/6/2026 | Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.4) | 0.60% | — | Microsoft Azure Data Explorer | 22/1/2026 | 17/6/2026 | Exposure of sensitive information to an unauthorized actor in Azure Data Explorer allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Crítica (9.8) | 0.56% | — | Microsoft Azure Logic Apps | 22/1/2026 | 17/6/2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.5) | 0.93% | — | Microsoft Azure Core Shared Client Library | 13/1/2026 | 17/6/2026 | Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (7.8) | 0.32% | — | Microsoft Azure Connected Machine Agent | 13/1/2026 | 17/6/2026 | Stack-based buffer overflow in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. | |
| Analizada | Crítica (9.6) | 0.71% | — | Microsoft Azure Cosmos DB | 19/12/2025 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Crítica (10) | 0.97% | — | Microsoft Azure Container Apps | 18/12/2025 | 17/6/2026 | Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.71% | — | Microsoft Azure Language | 18/12/2025 | 17/6/2026 | Custom Question Answering Elevation of Privilege Vulnerability | |
| Analizada | Alta (8.8) | 0.74% | — | Microsoft Azure Monitor Agent | 9/12/2025 | 17/6/2026 | Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network. | |
| Modificada | Crítica (9.8) | 0.62% | — | Microsoft Azure Application Gateway | 26/11/2025 | 17/6/2026 | Stack-based buffer overflow in Azure Application Gateway allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 0.62% | — | Microsoft Azure Application Gateway | 26/11/2025 | 17/6/2026 | Out-of-bounds read in Application Gateway allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 0.71% | — | Microsoft Azure Monitor | 20/11/2025 | 17/6/2026 | Azure Monitor Elevation of Privilege Vulnerability | |
| Analizada | Crítica (10) | 0.91% | — | Microsoft Azure Bastion Developer | 20/11/2025 | 17/6/2026 | Azure Bastion Elevation of Privilege Vulnerability |