Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

618 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7)0.56%—Microsoft Azure Connected Machine Agent14/10/202517/6/2026
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (8.7)0.66%—Microsoft Azure Cache FOR RedisMicrosoft Azure Managed Redis9/10/202517/6/2026
Redis Enterprise Elevation of Privilege Vulnerability
AnalizadaCrítica (9.8)1.5%—Microsoft Azure Playfab9/10/202517/6/2026
Azure PlayFab Elevation of Privilege Vulnerability
ModificadaMedia (5.4)0.44%—Microsoft Azure Monitor9/10/202517/6/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthorized attacker to perform spoofing over a network.
AplazadaCrítica (9.9)0.52%—Gardener Extensions AWSAIGardener Extensions AzureAIGardener Extensions OpenstackAIGardener Extensions GCPAI+125/9/202517/6/2026
Project Gardener implements the automated management and operation of Kubernetes clusters as a service. Code injection may be possible in Gardener Extensions for AWS providers prior to version 1.64.0, Azure providers prior to version 1.55.0, OpenStack providers prior to version 1.49.0, and GCP providers prior to…
AplazadaMedia (6.4)0.24%—Azurecurve BbcodeAI11/9/202517/6/2026
The azurecurve BBCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'url' shortcode in all versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AplazadaMedia (4.4)0.14%—Microsoft Azure Entra IDAIMicrosoft IntuneAIHimmelblau-idm HimmelblauAI9/9/202517/6/2026
Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Himmelblau 0.9.x derives numeric GIDs for Entra ID groups from the group display name when himmelblau.conf `id_attr_map = name` (the default configuration). Because Microsoft Entra ID allows multiple groups with the same `displayName`…
AnalizadaAlta (7.8)0.37%—Microsoft Azure Connected Machine Agent9/9/202517/6/2026
External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.35%—Microsoft Azure Connected Machine Agent9/9/20251/10/2026
Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally.
AnalizadaCrítica (9)0.62%—Microsoft Azure AI BOT Service4/9/202517/6/2026
Azure Bot Service Elevation of Privilege Vulnerability
AnalizadaCrítica (9.8)2.4%💥 PoCMicrosoft Azure Networking4/9/202517/6/2026
Azure Networking Elevation of Privilege Vulnerability
AplazadaMedia (6.9)0.40%—Microsoft KnackAIMicrosoft Azure CLIAI20/8/202517/6/2026
Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module. extract_full_summary_from_signature employs an inefficient regular expression pattern: "\s(:param)\s+(.+?)\s:(.*)" that is susceptible to catastrophic backtracking when processing crafted docstrings containing…
AnalizadaAlta (7.5)1.3%—Microsoft Azure Stack HUB12/8/202517/6/2026
Improper authentication in Azure Stack allows an unauthorized attacker to disclose information over a network.
AnalizadaMedia (6.5)1.2%—Microsoft Ecesv6-series Azure VM FirmwareMicrosoft Dcesv6-series Azure VM FirmwareMicrosoft Nccadsh100v5-series Azure VM FirmwareMicrosoft Ecedsv5-series Azure VM Firmware+712/8/202517/6/2026
Exposure of sensitive information to an unauthorized actor in Azure Virtual Machines allows an authorized attacker to disclose information over a network.
AnalizadaMedia (5.5)0.49%—Microsoft Azure APP Service ON Azure Stack12/8/202517/6/2026
Exposure of private personal information to an unauthorized actor in Azure Stack allows an authorized attacker to disclose information locally.
AnalizadaAlta (7.8)0.30%—Microsoft Azure File Sync12/8/202517/6/2026
Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally.
AnalizadaMedia (5.5)0.45%—Microsoft Ecesv6-series Azure VM FirmwareMicrosoft Dcesv6-series Azure VM FirmwareMicrosoft Nccadsh100v5-series Azure VM FirmwareMicrosoft Ecedsv5-series Azure VM Firmware+712/8/202517/6/2026
Improper access control in Azure Virtual Machines allows an authorized attacker to perform spoofing locally.
AnalizadaCrítica (9.1)0.82%—Microsoft Azure Portal7/8/202517/6/2026
Azure Portal Elevation of Privilege Vulnerability
AnalizadaCrítica (10)1.1%—Microsoft Azure Openai7/8/202517/6/2026
Azure OpenAI Elevation of Privilege Vulnerability
AplazadaBaja (2.8)0.14%—Microsoft Azure Entra IDAIMicrosoft IntuneAIHimmelblau-idm HimmelblauAI2/8/202517/6/2026
Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. When debugging is enabled for Himmelblau in version 1.0.0, the himmelblaud_tasks service leaks an Intune service access token to the system journal. This short-lived token can be used to detect the host's Intune compliance status, and may…
AnalizadaAlta (8.8)0.68%—Microsoft Azure Machine Learning18/7/202517/6/2026
Missing authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (8.8)0.73%—Microsoft Azure Machine Learning18/7/202517/6/2026
Improper authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (8.8)0.64%—Microsoft Azure Machine Learning18/7/202517/6/2026
Weak authentication in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.
AnalizadaCrítica (9)0.70%—Microsoft Azure Devops18/7/202517/6/2026
Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
AnalizadaAlta (7.5)0.96%—Microsoft Azure Monitor Agent8/7/202517/6/2026
Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent network.
Orbitaley — Vulnerabilidades