Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
618 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7) | 0.56% | — | Microsoft Azure Connected Machine Agent | 14/10/2025 | 17/6/2026 | Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (8.7) | 0.66% | — | Microsoft Azure Cache FOR RedisMicrosoft Azure Managed Redis | 9/10/2025 | 17/6/2026 | Redis Enterprise Elevation of Privilege Vulnerability | |
| Analizada | Crítica (9.8) | 1.5% | — | Microsoft Azure Playfab | 9/10/2025 | 17/6/2026 | Azure PlayFab Elevation of Privilege Vulnerability | |
| Modificada | Media (5.4) | 0.44% | — | Microsoft Azure Monitor | 9/10/2025 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthorized attacker to perform spoofing over a network. | |
| Aplazada | Crítica (9.9) | 0.52% | — | Gardener Extensions AWSAIGardener Extensions AzureAIGardener Extensions OpenstackAIGardener Extensions GCPAI+1 | 25/9/2025 | 17/6/2026 | Project Gardener implements the automated management and operation of Kubernetes clusters as a service. Code injection may be possible in Gardener Extensions for AWS providers prior to version 1.64.0, Azure providers prior to version 1.55.0, OpenStack providers prior to version 1.49.0, and GCP providers prior to… | |
| Aplazada | Media (6.4) | 0.24% | — | Azurecurve BbcodeAI | 11/9/2025 | 17/6/2026 | The azurecurve BBCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'url' shortcode in all versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.4) | 0.14% | — | Microsoft Azure Entra IDAIMicrosoft IntuneAIHimmelblau-idm HimmelblauAI | 9/9/2025 | 17/6/2026 | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Himmelblau 0.9.x derives numeric GIDs for Entra ID groups from the group display name when himmelblau.conf `id_attr_map = name` (the default configuration). Because Microsoft Entra ID allows multiple groups with the same `displayName`… | |
| Analizada | Alta (7.8) | 0.37% | — | Microsoft Azure Connected Machine Agent | 9/9/2025 | 17/6/2026 | External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.35% | — | Microsoft Azure Connected Machine Agent | 9/9/2025 | 1/10/2026 | Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally. | |
| Analizada | Crítica (9) | 0.62% | — | Microsoft Azure AI BOT Service | 4/9/2025 | 17/6/2026 | Azure Bot Service Elevation of Privilege Vulnerability | |
| Analizada | Crítica (9.8) | 2.4% | 💥 PoC | Microsoft Azure Networking | 4/9/2025 | 17/6/2026 | Azure Networking Elevation of Privilege Vulnerability | |
| Aplazada | Media (6.9) | 0.40% | — | Microsoft KnackAIMicrosoft Azure CLIAI | 20/8/2025 | 17/6/2026 | Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module. extract_full_summary_from_signature employs an inefficient regular expression pattern: "\s(:param)\s+(.+?)\s:(.*)" that is susceptible to catastrophic backtracking when processing crafted docstrings containing… | |
| Analizada | Alta (7.5) | 1.3% | — | Microsoft Azure Stack HUB | 12/8/2025 | 17/6/2026 | Improper authentication in Azure Stack allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (6.5) | 1.2% | — | Microsoft Ecesv6-series Azure VM FirmwareMicrosoft Dcesv6-series Azure VM FirmwareMicrosoft Nccadsh100v5-series Azure VM FirmwareMicrosoft Ecedsv5-series Azure VM Firmware+7 | 12/8/2025 | 17/6/2026 | Exposure of sensitive information to an unauthorized actor in Azure Virtual Machines allows an authorized attacker to disclose information over a network. | |
| Analizada | Media (5.5) | 0.49% | — | Microsoft Azure APP Service ON Azure Stack | 12/8/2025 | 17/6/2026 | Exposure of private personal information to an unauthorized actor in Azure Stack allows an authorized attacker to disclose information locally. | |
| Analizada | Alta (7.8) | 0.30% | — | Microsoft Azure File Sync | 12/8/2025 | 17/6/2026 | Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally. | |
| Analizada | Media (5.5) | 0.45% | — | Microsoft Ecesv6-series Azure VM FirmwareMicrosoft Dcesv6-series Azure VM FirmwareMicrosoft Nccadsh100v5-series Azure VM FirmwareMicrosoft Ecedsv5-series Azure VM Firmware+7 | 12/8/2025 | 17/6/2026 | Improper access control in Azure Virtual Machines allows an authorized attacker to perform spoofing locally. | |
| Analizada | Crítica (9.1) | 0.82% | — | Microsoft Azure Portal | 7/8/2025 | 17/6/2026 | Azure Portal Elevation of Privilege Vulnerability | |
| Analizada | Crítica (10) | 1.1% | — | Microsoft Azure Openai | 7/8/2025 | 17/6/2026 | Azure OpenAI Elevation of Privilege Vulnerability | |
| Aplazada | Baja (2.8) | 0.14% | — | Microsoft Azure Entra IDAIMicrosoft IntuneAIHimmelblau-idm HimmelblauAI | 2/8/2025 | 17/6/2026 | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. When debugging is enabled for Himmelblau in version 1.0.0, the himmelblaud_tasks service leaks an Intune service access token to the system journal. This short-lived token can be used to detect the host's Intune compliance status, and may… | |
| Analizada | Alta (8.8) | 0.68% | — | Microsoft Azure Machine Learning | 18/7/2025 | 17/6/2026 | Missing authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 0.73% | — | Microsoft Azure Machine Learning | 18/7/2025 | 17/6/2026 | Improper authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 0.64% | — | Microsoft Azure Machine Learning | 18/7/2025 | 17/6/2026 | Weak authentication in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9) | 0.70% | — | Microsoft Azure Devops | 18/7/2025 | 17/6/2026 | Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.5) | 0.96% | — | Microsoft Azure Monitor Agent | 8/7/2025 | 17/6/2026 | Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent network. |