Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
–

11 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.53%—Microsoft Azure ARC17/9/202625/9/2026
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.8)0.48%—Microsoft Azure ARC17/9/202625/9/2026
Azure Arc Elevation of Privilege Vulnerability
Pendiente de análisisAlta (8.8)0.82%—Microsoft Azure ARCAI8/9/202610/9/2026
Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (10)0.80%—Microsoft Azure ARC20/8/202624/8/2026
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
ModificadaCrítica (9.8)1.5%—Microsoft Azure ARC5/2/202617/6/2026
Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
AnalizadaAlta (7)0.90%—Microsoft Azure ARC11/3/202517/6/2026
Improper neutralization of special elements used in a command ('command injection') in Azure Arc allows an authorized attacker to elevate privileges locally.
AnalizadaMedia (6.2)0.89%—Azure ARC Extension Microsoft.azstackhci.operatorAzure ARC Extension Microsoft.azure.hybridnetworkAzure ARC Extension Microsoft.azurekeyvaultsecretsproviderAzure ARC Extension Microsoft.iotoperations.mq+39/4/202417/6/2026
Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability
ModificadaAlta (7)0.39%—Microsoft Azure Arc-enabled Servers8/8/202310/8/2026
Azure Arc-Enabled Servers Elevation of Privilege Vulnerability
ModificadaBaja (3.3)0.49%—Microsoft Azure ARC Jumpstart18/5/202317/6/2026
Azure Arc Jumpstart Information Disclosure Vulnerability
ModificadaCrítica (10)2.6%—Microsoft Azure Arc-enabled KubernetesMicrosoft Azure Stack Edge11/10/202217/6/2026
Microsoft has identified a vulnerability affecting the cluster connect feature of Azure Arc-enabled Kubernetes clusters. This vulnerability could allow an unauthenticated user to elevate their privileges and potentially gain administrative control over the Kubernetes cluster. Additionally, because Azure Stack Edge…
ModificadaAlta (7.8)0.69%—Microsoft Azure ARCMicrosoft Azure Guest Configuration13/9/202217/6/2026
Azure Guest Configuration and Azure Arc-enabled servers Elevation of Privilege Vulnerability