Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3008▲ 385 respecto a la semana anterior
Críticas / altas1453▲ 24 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

18.402 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.3)0.54%—Pulumi Crossguard Policy PacksAI24/7/202630/7/2026
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, IAM-role policy checks can be bypassed when the role trusts multiple OIDC providers. This issue has been patched in version 1.4.0.
AnalizadaCrítica (9.8)0.86%—Microsoft Azure APP Service FOR Linux24/7/20266/8/2026
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (10)0.90%—Microsoft Purview Data Governance24/7/202629/7/2026
Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (10)0.90%—Microsoft Azure Kubernetes Service24/7/202629/7/2026
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.8)0.92%—Microsoft Azure KEY Vault24/7/20267/8/2026
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.8)0.92%—Microsoft Azure DNS24/7/20267/8/2026
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (10)0.90%—Microsoft Exchange Online24/7/202629/7/2026
Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.
AnalizadaAlta (8.8)0.55%—Microsoft Azure AI Search24/7/202629/7/2026
Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.8)0.97%—Microsoft Account24/7/202630/7/2026
Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
AnalizadaCrítica (9.9)0.79%—Microsoft Azure RED HAT Openshift24/7/20267/8/2026
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (8.8)0.96%—Microsoft Surface Management Services24/7/20266/8/2026
Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
AnalizadaCrítica (9.9)1.7%—Microsoft 365 Copilot24/7/202629/7/2026
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
AnalizadaMedia (6.5)1.00%—Microsoft Graph24/7/202629/7/2026
Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.
AnalizadaAlta (7.2)0.70%—Microsoft Azure API Management24/7/202617/8/2026
Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.
Pendiente de análisisAlta (7.8)0.82%—Microsoft Visual Studio CodeAIRedhat Ansible LightspeedAI22/7/202622/7/2026
A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) arises from improper handling of the ansible.executionEnvironment.containerOptions and ansible.executionEnvironment.volumeMounts settings, allowing an attacker to inject shell separators. This can be…
Pendiente de análisisAlta (7.8)0.75%—Ansible LightspeedAIMicrosoft Visual Studio CodeAI22/7/202623/7/2026
A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability (CWE-78) allows a remote attacker to execute unauthorized commands on a user's system. The issue occurs because the `ansible.python.activationScript` setting, intended for a virtual environment activation…
Pendiente de análisisAlta (7.8)0.95%—Microsoft Visual Studio CodeAIRedhat AnsibleAI22/7/202622/7/2026
A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This command injection vulnerability allows an attacker to craft a malicious playbook filename containing special characters. When a victim runs the playbook, these characters are not properly sanitized, leading to…
Pendiente de análisisBaja (3.3)0.13%—Ansible LightspeedAIMicrosoft Visual Studio CodeAIGoogle GeminiAI22/7/202622/7/2026
A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability allows an attacker with local access to the workstation, or malware running with the user's privileges, to read the Google Gemini API key. The extension insecurely stores the API key in plain text within the user's…
Pendiente de análisisCrítica (9.8)0.43%💥 PoCMicrosoft Azure API ManagementAI21/7/20265/10/2026
En Microsoft Azure API Management hasta el 17-10-2025, cuando el registro de autoservicio (autenticación básica de nombre de usuario/contraseña) está habilitado en el Inquilino A, un atacante puede reutilizar el flujo de registro cambiando el nombre de host o el identificador de inquilino al Inquilino B, incluso…
AnalizadaMedia (5.4)0.39%—Microsoft Edge Chromium17/7/202621/7/2026
Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.
AnalizadaAlta (7.5)0.66%—Microsoft Remote Desktop WEB ClientMicrosoft Windows Admin Center17/7/202622/7/2026
Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.
Pendiente de análisisMedia (5.1)0.17%—Microsoft WindowsAIMicrosoft Task SchedulerAIMicrosoft DcomAI17/7/202621/7/2026
A non-administrator interactive user can obtain full SYSTEM code execution through a DCOM/task scheduler logic chain — no network access, no memory corruption required (ITMS 8.7.3)
AplazadaMedia (6.5)0.16%—HCL Traveler FOR Microsoft OutlookAI17/7/202617/7/2026
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.
AnalizadaMedia (5.4)0.58%—Microsoft Sharepoint Server16/7/202622/7/2026
Una neutralización incorrecta de la entrada durante la generación de páginas web ('secuencias de comandos en sitios cruzados' o XSS) en Microsoft Office SharePoint permite a un atacante autorizado realizar suplantación (spoofing) a través de una red.
AnalizadaAlta (7.5)0.61%—Microsoft Terminal16/7/202630/7/2026
Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network.