Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3008▲ 385 respecto a la semana anterior
Críticas / altas1453▲ 24 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
18.402 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.3) | 0.54% | — | Pulumi Crossguard Policy PacksAI | 24/7/2026 | 30/7/2026 | Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, IAM-role policy checks can be bypassed when the role trusts multiple OIDC providers. This issue has been patched in version 1.4.0. | |
| Analizada | Crítica (9.8) | 0.86% | — | Microsoft Azure APP Service FOR Linux | 24/7/2026 | 6/8/2026 | Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (10) | 0.90% | — | Microsoft Purview Data Governance | 24/7/2026 | 29/7/2026 | Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (10) | 0.90% | — | Microsoft Azure Kubernetes Service | 24/7/2026 | 29/7/2026 | Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 0.92% | — | Microsoft Azure KEY Vault | 24/7/2026 | 7/8/2026 | Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 0.92% | — | Microsoft Azure DNS | 24/7/2026 | 7/8/2026 | Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (10) | 0.90% | — | Microsoft Exchange Online | 24/7/2026 | 29/7/2026 | Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. | |
| Analizada | Alta (8.8) | 0.55% | — | Microsoft Azure AI Search | 24/7/2026 | 29/7/2026 | Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 0.97% | — | Microsoft Account | 24/7/2026 | 30/7/2026 | Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network. | |
| Analizada | Crítica (9.9) | 0.79% | — | Microsoft Azure RED HAT Openshift | 24/7/2026 | 7/8/2026 | Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 0.96% | — | Microsoft Surface Management Services | 24/7/2026 | 6/8/2026 | Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network. | |
| Analizada | Crítica (9.9) | 1.7% | — | Microsoft 365 Copilot | 24/7/2026 | 29/7/2026 | Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network. | |
| Analizada | Media (6.5) | 1.00% | — | Microsoft Graph | 24/7/2026 | 29/7/2026 | Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. | |
| Analizada | Alta (7.2) | 0.70% | — | Microsoft Azure API Management | 24/7/2026 | 17/8/2026 | Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network. | |
| Pendiente de análisis | Alta (7.8) | 0.82% | — | Microsoft Visual Studio CodeAIRedhat Ansible LightspeedAI | 22/7/2026 | 22/7/2026 | A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) arises from improper handling of the ansible.executionEnvironment.containerOptions and ansible.executionEnvironment.volumeMounts settings, allowing an attacker to inject shell separators. This can be… | |
| Pendiente de análisis | Alta (7.8) | 0.75% | — | Ansible LightspeedAIMicrosoft Visual Studio CodeAI | 22/7/2026 | 23/7/2026 | A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability (CWE-78) allows a remote attacker to execute unauthorized commands on a user's system. The issue occurs because the `ansible.python.activationScript` setting, intended for a virtual environment activation… | |
| Pendiente de análisis | Alta (7.8) | 0.95% | — | Microsoft Visual Studio CodeAIRedhat AnsibleAI | 22/7/2026 | 22/7/2026 | A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This command injection vulnerability allows an attacker to craft a malicious playbook filename containing special characters. When a victim runs the playbook, these characters are not properly sanitized, leading to… | |
| Pendiente de análisis | Baja (3.3) | 0.13% | — | Ansible LightspeedAIMicrosoft Visual Studio CodeAIGoogle GeminiAI | 22/7/2026 | 22/7/2026 | A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability allows an attacker with local access to the workstation, or malware running with the user's privileges, to read the Google Gemini API key. The extension insecurely stores the API key in plain text within the user's… | |
| Pendiente de análisis | Crítica (9.8) | 0.43% | 💥 PoC | Microsoft Azure API ManagementAI | 21/7/2026 | 5/10/2026 | En Microsoft Azure API Management hasta el 17-10-2025, cuando el registro de autoservicio (autenticación básica de nombre de usuario/contraseña) está habilitado en el Inquilino A, un atacante puede reutilizar el flujo de registro cambiando el nombre de host o el identificador de inquilino al Inquilino B, incluso… | |
| Analizada | Media (5.4) | 0.39% | — | Microsoft Edge Chromium | 17/7/2026 | 21/7/2026 | Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network. | |
| Analizada | Alta (7.5) | 0.66% | — | Microsoft Remote Desktop WEB ClientMicrosoft Windows Admin Center | 17/7/2026 | 22/7/2026 | Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network. | |
| Pendiente de análisis | Media (5.1) | 0.17% | — | Microsoft WindowsAIMicrosoft Task SchedulerAIMicrosoft DcomAI | 17/7/2026 | 21/7/2026 | A non-administrator interactive user can obtain full SYSTEM code execution through a DCOM/task scheduler logic chain — no network access, no memory corruption required (ITMS 8.7.3) | |
| Aplazada | Media (6.5) | 0.16% | — | HCL Traveler FOR Microsoft OutlookAI | 17/7/2026 | 17/7/2026 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content. | |
| Analizada | Media (5.4) | 0.58% | — | Microsoft Sharepoint Server | 16/7/2026 | 22/7/2026 | Una neutralización incorrecta de la entrada durante la generación de páginas web ('secuencias de comandos en sitios cruzados' o XSS) en Microsoft Office SharePoint permite a un atacante autorizado realizar suplantación (spoofing) a través de una red. | |
| Analizada | Alta (7.5) | 0.61% | — | Microsoft Terminal | 16/7/2026 | 30/7/2026 | Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network. |