Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
2343 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.97% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 8/9/2026 | 17/9/2026 | Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (6.5) | 0.92% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 8/9/2026 | 17/9/2026 | Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 8/9/2026 | 17/9/2026 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 8/9/2026 | 17/9/2026 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 8/9/2026 | 17/9/2026 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7) | 0.28% | — | Microsoft Power Automate FOR Desktop | 8/9/2026 | 29/9/2026 | Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally. | |
| Aplazada | Media (6.4) | 0.19% | — | Codesupplyco PowerkitAI | 7/9/2026 | 8/9/2026 | The Powerkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Lazy Load module's image processing in all versions up to, and including, 3.0.4. This is due to the 'content_process_images' function using a flawed regex-based HTML attribute parser. This makes it possible for authenticated… | |
| Aplazada | Media (6.7) | 0.12% | — | Power HALAI | 7/9/2026 | 8/9/2026 | In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11165543; Issue ID: MSV-9011. | |
| Aplazada | Media (6.7) | 0.11% | — | Power HALAI | 7/9/2026 | 8/9/2026 | In Power HAL, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11165543; Issue ID: MSV-9012. | |
| Aplazada | Crítica (9.8) | 1.2% | 💥 PoC | Powerjob WorkerAI | 4/9/2026 | 8/9/2026 | PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port. This allows a remote attacker to execute arbitrary code. | |
| Aplazada | Crítica (9.1) | 1.1% | 💥 PoC | Powerjob ServerAI | 4/9/2026 | 8/9/2026 | PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256-based authentication. This allows a remote attacker to execute arbitrary code. | |
| Aplazada | Crítica (9.8) | 0.98% | 💥 PoC | PowerjobAI | 4/9/2026 | 14/9/2026 | PowerJob versions 4.x through 5.1.2 contain an unauthenticated remote code execution vulnerability in the /friend/process endpoint of the Server-Worker transport layer | |
| Aplazada | Crítica (9.3) | 1.3% | 💥 PoC | Voltronicpower Snmp WEB PROAI | 4/9/2026 | 10/9/2026 | Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar archive without valid credentials. Attackers can supply a malicious tar archive… | |
| Analizada | Crítica (9.9) | 0.63% | — | Microsoft Power Platform | 3/9/2026 | 8/9/2026 | Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network. | |
| En análisis | Media (6.5) | 0.41% | — | Dell Powerprotect Data ManagerAI | 3/9/2026 | 5/9/2026 | Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain an Incorrect Authorization vulnerability in the REST API. A low privileged remote attacker could potentially exploit this vulnerability, leading to Protection mechanism bypass. | |
| En análisis | Media (4.1) | 0.36% | — | Dell Powerprotect Data ManagerAI | 3/9/2026 | 3/9/2026 | Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Server-Side Request Forgery (SSRF) vulnerability in the REST API. A high privileged remote attacker could potentially exploit this vulnerability, leading to Information disclosure. | |
| En análisis | Alta (7.8) | 0.20% | — | Dell Powerprotect Data ManagerAI | 3/9/2026 | 4/9/2026 | Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a stack buffer overflow vulnerability in file-level restore agent. A high privileged remote attacker could potentially exploit this vulnerability, leading to Information disclosure. | |
| En análisis | Media (6.8) | 0.38% | — | Dell Powerprotect Data ManagerAI | 3/9/2026 | 4/9/2026 | Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Reliance on Data/Memory Layout vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to Launch of phishing attacks. | |
| En análisis | Alta (8.8) | 0.30% | — | Openai Codex CLIAIOpenai Codex DesktopAIMicrosoft PowershellAI | 1/9/2026 | 2/9/2026 | OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS misclassified certain PowerShell commands as safe because their command-safety parser interpreted PowerShell's stop-parsing token (--%) differently than PowerShell itself. If a user opens an attacker-prepared repository and Codex… | |
| Pendiente de análisis | Alta (8.8) | 0.42% | — | Dell PowerstoreAI | 1/9/2026 | 4/9/2026 | Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Crítica (10) | 0.29% | — | Dell Powerstoreos | 1/9/2026 | 2/10/2026 | Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access. | |
| Analizada | Alta (8.8) | 0.75% | — | Dell Powerstoreos | 1/9/2026 | 2/10/2026 | Dell PowerStore contains a Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges. | |
| Analizada | Alta (8.8) | 0.75% | — | Dell Powerstoreos | 1/9/2026 | 2/10/2026 | Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges. | |
| Analizada | Alta (8.8) | 0.49% | — | Dell Powerstoreos | 1/9/2026 | 2/10/2026 | Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain escalated privileges. | |
| Analizada | Media (6.5) | 0.38% | — | Dell Powerstoreos | 1/9/2026 | 2/10/2026 | Dell PowerStore contains an Argument Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to gain unauthorized access to sensitive sensitive system information. |