Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 223 respecto a la semana anterior
Críticas / altas1373▲ 144 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.9) | 0.63% | — | Microsoft Power Platform | 3/9/2026 | 8/9/2026 | Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.6) | 1.1% | — | Microsoft Power Platform | 15/10/2024 | 17/6/2026 | Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a network attack vector. | |
| Analizada | Alta (8.8) | 1.6% | — | Microsoft Power Platform Terraform Provider | 25/9/2024 | 17/6/2026 | Power Platform Terraform Provider allows managing environments and other resources within Power Platform. Versions prior to 3.0.0 have an issue in the Power Platform Terraform Provider where sensitive information, specifically the `client_secret` used in the service principal authentication, may be exposed in logs.… | |
| Analizada | Crítica (9.8) | 0.83% | — | Microsoft Power Platform | 27/6/2024 | 20/7/2026 | An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network. | |
| Modificada | Alta (7.4) | 16% | — | Microsoft Azure Logic AppsMicrosoft Power Platform | 12/12/2023 | 17/6/2026 | Microsoft Power Platform Connector Spoofing Vulnerability |