Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2624▼ 223 respecto a la semana anterior
Críticas / altas1373▲ 144 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

5 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.9)0.63%—Microsoft Power Platform3/9/20268/9/2026
Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (8.6)1.1%—Microsoft Power Platform15/10/202417/6/2026
Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a network attack vector.
AnalizadaAlta (8.8)1.6%—Microsoft Power Platform Terraform Provider25/9/202417/6/2026
Power Platform Terraform Provider allows managing environments and other resources within Power Platform. Versions prior to 3.0.0 have an issue in the Power Platform Terraform Provider where sensitive information, specifically the `client_secret` used in the service principal authentication, may be exposed in logs.…
AnalizadaCrítica (9.8)0.83%—Microsoft Power Platform27/6/202420/7/2026
An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network.
ModificadaAlta (7.4)16%—Microsoft Azure Logic AppsMicrosoft Power Platform12/12/202317/6/2026
Microsoft Power Platform Connector Spoofing Vulnerability