Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.4) | 0.83% | — | Microsoft Azure Kubernetes Service | 11/8/2026 | 12/8/2026 | Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (10) | 0.90% | — | Microsoft Azure Kubernetes Service | 24/7/2026 | 29/7/2026 | Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 0.37% | — | Microsoft Azure Kubernetes Service | 9/6/2026 | 23/7/2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally. | |
| Analizada | Crítica (9.8) | 0.90% | — | Microsoft Azure Kubernetes Service | 3/4/2026 | 24/7/2026 | Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9) | 18% | — | Microsoft Azure Kubernetes Service Confidential Containers | 9/4/2024 | 17/6/2026 | Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability | |
| Modificada | Crítica (9) | 1.3% | — | Microsoft Azure Kubernetes Service | 13/2/2024 | 10/8/2026 | Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability | |
| Modificada | Crítica (9) | 1.2% | — | Microsoft Azure Kubernetes Service | 13/2/2024 | 10/8/2026 | Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Crítica (9.8) | 2.7% | — | Microsoft Azure Kubernetes Service | 12/9/2023 | 17/6/2026 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | |
| Modificada | Media (6.8) | 1.4% | — | Microsoft Azure Container InstancesMicrosoft Azure Container RegistryMicrosoft Azure Kubernetes ServiceMicrosoft Azure Service Fabric+1 | 11/3/2021 | 19/8/2026 | Azure Virtual Machine Information Disclosure Vulnerability | |
| Modificada | Media (6.8) | 2.2% | — | Microsoft Azure Kubernetes Service | 25/2/2021 | 17/6/2026 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | |
| Modificada | Media (5.5) | 1.1% | — | Microsoft Azure Kubernetes Service | 12/1/2021 | 17/6/2026 | Azure Active Directory Pod Identity Spoofing Vulnerability |