Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

18.389 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.8)——Microsoft KiotaAI6/10/20266/10/2026
Kiota is an OpenAPI based HTTP Client code generator. From 0.5.0 until 1.35.0, Kiota's Java and PHP documentation-comment sanitizers delete block-comment terminators rather than neutralizing them, allowing overlapping characters to reform a terminator and place attacker-controlled OpenAPI text outside a generated…
Pendiente de análisisBaja (3.1)——Microsoft KiotaAI6/10/20266/10/2026
Kiota is an OpenAPI based HTTP Client code generator. From 1.25.1 until 1.35.0, Kiota copies x-ai-capabilities.response_semantics.oauth_card_path from an attacker-controlled or compromised OpenAPI description into a generated API plugin manifest without validating that the value is a safe package-relative file…
Pendiente de análisisCrítica (9.1)——Microsoft MsquicAI6/10/20266/10/2026
MsQuic is a cross-platform C implementation of the IETF QUIC protocol exposed to C, C++, C#, and Rust. Prior to 2.4.20, 2.5.11, and 2.6.1, MsQuic clients using the OpenSSL or QuicTLS TLS backend do not properly verify that a server certificate matches the intended target server hostname. An on-path attacker can…
AplazadaCrítica (9.1)——Microsoft UFOAI6/10/20266/10/2026
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the press_key tool in ufo/client/mcp/http_servers/mobile_mcp_server.py accepts a free-form key_code parameter and passes it to `adb shell input keyevent`. The adb client joins the arguments into a remote…
AplazadaMedia (6.5)——Microsoft UFOAI6/10/20266/10/2026
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the /api/task_result/{task_name} endpoint calls SessionManager.get_result_by_task() in ufo/server/services/session_manager.py, which acquires a non-reentrant lock and then calls…
AplazadaAlta (7.5)——Microsoft UFOAI6/10/20266/10/2026
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the run_shell tool in the CommandLineExecutor component of ufo/client/mcp/local_servers/cli_mcp_server.py validates only the first token of the bash_command parameter and permits explorer.exe. On Windows,…
AplazadaMedia (6.4)——Microsoft UFOAI6/10/20266/10/2026
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, authenticated device registration through /api/devices can supply a permitted attacker-controlled WebSocket endpoint while aip/transport/websocket.py applies pinned_addresses only to the initial…
AplazadaMedia (5.4)——Microsoft UFOAI6/10/20266/10/2026
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the execute_command tool in ufo/client/mcp/http_servers/linux_mcp_server.py treats sort and uniq as read-only commands while the free-form command parameter can select their file-output forms. An…
AplazadaAlta (8.8)——Microsoft UFOAI6/10/20266/10/2026
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.10, the type_text and launch_app tools in ufo/client/mcp/http_servers/mobile_mcp_server.py pass the authenticated caller-controlled text and package_name parameters into adb shell command argument positions…
AplazadaMedia (6.9)0.32%—Crossplane RuntimeAI4/10/20266/10/2026
A vulnerability was detected in crossplane crossplane-runtime up to 2.2.2/2.3.2. This vulnerability affects the function Get of the file pkg/xpkg/client.go of the component ImageConfig. The manipulation results in time-of-check time-of-use. The attack may be launched remotely. Upgrading to version 2.2.3, 2.3.3 and…
Pendiente de análisisCrítica (9.3)0.95%—Mikrotik RouterosAI2/10/20266/10/2026
The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single…
En análisisAlta (8.8)0.50%💥 PoCMicrosoft Exchange ServerAI2/10/20266/10/2026
Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.
Pendiente de análisisAlta (8.5)0.30%—Prosemirror-viewAI2/10/20262/10/2026
ProseMirror's view component renders and manages the editable browser interface for ProseMirror documents. Prior to 1.42.3, prosemirror-view paste handling accepts attacker-provided HTML whose clipboard slice context contains attributes that are not passed through schema attribute validation. When a user pastes the…
Pendiente de análisisCrítica (9.3)0.25%—Microsoft Netx DUOAI29/9/202630/9/2026
NetX Duo's WebSocket client resets the unmasking cursor to the first `NX_PACKET` each time it advances through a chained packet, while the loop's upper bound belongs to the current packet. With the standard contiguous packet-pool layout, a masked server frame split across two packets therefore drives the XOR loop…
Pendiente de análisisAlta (7.5)0.17%—Microsoft Netx SecureAI29/9/202630/9/2026
The `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate parsing in NetX Secure, and therefore runs on certificates supplied by a remote peer during the TLS handshake. The function reads the one-byte…
Pendiente de análisisAlta (8.5)0.10%—Microsoft ThreadxAI29/9/20262/10/2026
An unprivileged, memory-protected ThreadX module can have the kernel read and write memory at addresses of its choosing, in privileged mode, and can use that to clear the MPU enable bit and remove its own isolation boundary. The Module Manager decided whether a privileged service could dereference an object address a…
Pendiente de análisisAlta (8.6)0.12%—Microsoft LevelxAI29/9/202629/9/2026
Mounting an attacker-controlled NAND flash image (`lx_nand_flash_open()`) triggers an unbounded out-of-bounds heap **write** in LevelX's NAND flash-translation-layer metadata parser that overwrites a driver function pointer in the control block, giving a demonstrated control-flow hijack — RIP set to a full 8-byte…
Pendiente de análisisAlta (8.7)0.25%—Microsoft NetxAI29/9/202629/9/2026
An unauthenticated client can drain the RTSP server's packet pool with a couple of dozen requests that carry a Session header the parser cannot convert. The Session branch returns the raw NetX error code instead of an RTSP status code: ```c /* addons/rtsp/nx_rtsp_server.c:2754 */ if (status) ``` Every other branch of…
En análisisMedia (4.7)0.14%—Microsoft Network MonitorAI29/9/202629/9/2026
Microsoft Network Monitor file parser large loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
Pendiente de análisisAlta (8.6)0.16%—Ros2AI28/9/202630/9/2026
A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) 'ros2topic' command-line tool, affecting all ROS 2 distributions from Crystal Clemmys up to and including Lyrical Luth and Rolling Ridley. The vulnerability lies in the 'hz' verb, which reports the publishing rate of a topic and…
En análisisAlta (7.5)0.35%—Microsoft Office OutlookAI25/9/202629/9/2026
Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
ExternaSin puntuar——Microsoft OfficeAI25/9/2026—
Microsoft Office vulnerability that allows information disclosure. The vulnerability was addressed by updates released in July 2026, though the CVE was inadvertently omitted from the initial security bulletin. This is an informational update for tracking purposes.
AnalizadaAlta (8.8)0.43%—Microsoft 365 AppsMicrosoft Office 2021Microsoft Office 202423/9/20265/10/2026
Microsoft Office Outlook Remote Code Execution Vulnerability
AplazadaAlta (7.1)0.24%—AlbatrossAI23/9/202624/9/2026
Robur Albatross 1.0.0 through 2.x before 2.7.2 does not limit use of the ring buffer, leading to an albatross-console loop with no recognized termination condition. This is only exploitable by users who can send console subscription commands to unikernels that produce sufficient log output to fill the ring buffer…
AplazadaMedia (6.1)0.13%—Acer NitrosenseAI23/9/202625/9/2026
An unauthenticated local attacker can connect to the Electron DevTools endpoint exposed by Acer NitroSense software (versions up to and including 5.2.63) on localhost TCP port 9993. Because Chromium remote debugging is enabled in the production application, the attacker can execute JavaScript in the privileged…
Orbitaley — Vulnerabilidades