Vulnerabilities

Summary — last 7 days

New vulnerabilities2,819→ no change vs. last week
Critical / high1,469▲ 239 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)83▼ 429 vs. last week
–

15 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
AnalyzedHigh (7.2)1.0%—Microsoft Azure Monitor Agent8/11/20268/13/2026
Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network.
AnalyzedMedium (6.5)0.64%—Microsoft Azure Monitor Agent5/12/20266/17/2026
Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
AnalyzedHigh (7.8)0.36%—Microsoft Azure Monitor Agent5/12/20266/18/2026
External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
AnalyzedHigh (7.8)2.5%—Microsoft Azure Monitor Agent4/14/20266/17/2026
Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
AnalyzedHigh (7.8)0.33%—Microsoft Azure Monitor Agent4/14/20266/17/2026
Improper input validation in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
AnalyzedHigh (8.8)0.74%—Microsoft Azure Monitor Agent12/9/20256/17/2026
Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network.
AnalyzedHigh (7.3)0.33%—Microsoft Azure Monitor Agent11/11/20256/17/2026
Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally.
AnalyzedHigh (7.8)0.64%—Microsoft Azure Monitor Agent10/14/20256/17/2026
Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
AnalyzedHigh (7)0.78%—Microsoft Azure Monitor Agent10/14/20256/17/2026
Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
AnalyzedHigh (7.5)0.96%—Microsoft Azure Monitor Agent7/8/20256/17/2026
Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent network.
DeferredCritical (9.8)1.2%—Opsview Monitor AgentAI1/9/20256/17/2026
An issue was discovered in Opsview Monitor Agent 6.8. An unauthenticated remote attacker can call check_nrpe against affected targets, specifying known NRPE plugins, which in default installations are configured to accept command control characters and pass them to command-line interpreters for NRPE plugin execution.…
AnalyzedHigh (7.1)0.65%—Microsoft Azure Monitor Agent10/8/20246/17/2026
Azure Monitor Agent Elevation of Privilege Vulnerability
ModifiedHigh (7.1)0.83%—Microsoft Azure Monitor Agent6/11/20247/20/2026
Azure Monitor Agent Elevation of Privilege Vulnerability
AnalyzedHigh (7.8)0.49%—Microsoft Azure Monitor Agent5/16/20246/17/2026
Azure Monitor Agent Elevation of Privilege Vulnerability
AnalyzedHigh (8.4)0.75%—Microsoft Azure Monitor Agent4/9/20246/17/2026
Azure Monitor Agent Elevation of Privilege Vulnerability