Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
–

4 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)0.48%—LokkaAIMicrosoft 365AIMicrosoft GraphAIMicrosoft Azure Resource ManagerAI15/9/202630/9/2026
Lokka is a Model Context Protocol server for Microsoft 365, including Microsoft Graph and other services. Prior to 2.1.2, the Lokka-Microsoft tool in src/mcp/src/main.ts uses direct URL string concatenation to append the user-controlled path value to the management.azure.com base URL. A specially crafted path can…
AnalizadaCrítica (9.8)0.90%—Microsoft Azure Resource Manager22/5/202623/7/2026
Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (10)0.90%—Microsoft Azure LocalMicrosoft Azure Resource Manager18/5/202617/6/2026
Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.
ModificadaAlta (8.8)0.68%—Microsoft Azure Resource Manager23/1/202630/7/2026
Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.