Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2538▼ 392 respecto a la semana anterior
Críticas / altas1301▲ 22 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
4 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.92% | — | Microsoft Azure KEY Vault | 24/7/2026 | 7/8/2026 | Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. | |
| Modificada | Alta (7.5) | 0.48% | — | Jenkins Azure KEY Vault | 12/4/2023 | 17/6/2026 | Jenkins Azure Key Vault Plugin 187.va_cd5fecd198a_ and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when push mode for durable task logging is enabled. | |
| Modificada | Media (6.5) | 1.4% | — | Google Secret Manager Provider FOR Secret Store CSI DriverHashicorp Vault Provider FOR Secrets Store CSI DriverMicrosoft Azure KEY Vault Provider FOR Secrets Store CSI Driver | 21/1/2021 | 17/6/2026 | Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass objects to write to arbitrary file paths on the host filesystem, including /var/lib/kubelet/pods. | |
| Modificada | Media (4.3) | 0.79% | — | Jenkins Azure KEY Vault | 4/11/2020 | 17/6/2026 | A missing permission check in Jenkins Azure Key Vault Plugin 2.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. |