Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.4)0.83%—Microsoft Azure Kubernetes Service11/8/202612/8/2026
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (10)0.90%—Microsoft Azure Kubernetes Service24/7/202629/7/2026
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
AnalizadaAlta (8.8)0.37%—Microsoft Azure Kubernetes Service9/6/202623/7/2026
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally.
AnalizadaCrítica (9.8)0.90%—Microsoft Azure Kubernetes Service3/4/202624/7/2026
Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (9)18%—Microsoft Azure Kubernetes Service Confidential Containers9/4/202417/6/2026
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
ModificadaCrítica (9)1.3%—Microsoft Azure Kubernetes Service13/2/202410/8/2026
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
ModificadaCrítica (9)1.2%—Microsoft Azure Kubernetes Service13/2/202410/8/2026
Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability
AnalizadaAlta (7.5)100%⚠ Explotación activaSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/202311/8/2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
ModificadaCrítica (9.8)2.7%—Microsoft Azure Kubernetes Service12/9/202317/6/2026
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
ModificadaMedia (6.8)1.4%—Microsoft Azure Container InstancesMicrosoft Azure Container RegistryMicrosoft Azure Kubernetes ServiceMicrosoft Azure Service Fabric+111/3/202119/8/2026
Azure Virtual Machine Information Disclosure Vulnerability
ModificadaMedia (6.8)2.2%—Microsoft Azure Kubernetes Service25/2/202117/6/2026
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
ModificadaMedia (5.5)1.1%—Microsoft Azure Kubernetes Service12/1/202117/6/2026
Azure Active Directory Pod Identity Spoofing Vulnerability