Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
18.389 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.35% | — | Acer NitrosenseAI | 23/9/2026 | 25/9/2026 | An unauthenticated local attacker can connect to the MQTT broker over its localhost WebSocket endpoint in Acer NitroSense software (versions up to and including 5.2.62). This allows the attacker to invoke exposed ddsc RPC functions, including child_process.execSync(), resulting in arbitrary command execution in the… | |
| Pendiente de análisis | Alta (8.7) | 0.49% | — | Mikrotik RouterosAI | 22/9/2026 | 25/9/2026 | MikroTik RouterOS before 7.25beta4 contains an improper input validation vulnerability in the labelled-VPN NLRI iterators of the routing service that allows an unauthenticated on-path attacker to crash the BGP service by sending a malformed MP_REACH_NLRI UPDATE message with a prefix-length value below the minimum… | |
| Aplazada | Alta (7.8) | 0.19% | — | Crosswire XiphosAI | 21/9/2026 | 22/9/2026 | An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menu_popup.c components | |
| Aplazada | Alta (8.7) | 0.44% | — | ZaprosAI | 21/9/2026 | 24/9/2026 | Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service via memory exhaustion. The issue affects all callers who streamed compressed responses relying on the chunk size — explicit (`iter_bytes(chunk_size=...)`) or the default — to bound memory. The decoder ignored that bound, so a… | |
| Aplazada | Media (6.9) | 0.43% | — | ZaprosAI | 21/9/2026 | 30/9/2026 | Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service when an application requests content from an untrusted server, or follows a redirect to one, because a malicious response containing an excessive number of chained `Content-Encoding` values causes Zapros to construct a deeply… | |
| Aplazada | Media (6.9) | 0.14% | — | Watchdog AntivirusAIMicrosoft WindowsAI | 20/9/2026 | 22/9/2026 | Missing Authorization in the IOCTL handlers of the wsdkd.sys kernel drivers in Watchdog WatchDog Antivirus 1.8.640 (driver versions 1.3.0.0 and earlier) on Microsoft Windows allows local, low-privileged attackers to delete arbitrary files with SYSTEM privileges, bypassing NTFS access controls and potentially disabling… | |
| Analizada | Alta (7.8) | 0.26% | — | Microsoft Edge Chromium | 18/9/2026 | 24/9/2026 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally. | |
| Aplazada | Media (6.5) | 0.11% | — | MicrosandboxAI | 18/9/2026 | 24/9/2026 | microsandbox is an easy, fast, local-first microVM runtime and library. Prior to 0.5.10, sdk/rust/lib/runtime/spawn.rs serializes NetworkConfig secret values into the --network-config argument and passes per-sandbox secrets through repeated --env arguments accepted by crates/cli/lib/sandbox_cmd.rs. Other local users… | |
| Analizada | Alta (7.7) | 0.84% | — | Microsoft 365 Copilot | 17/9/2026 | 28/9/2026 | Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network. | |
| Analizada | Crítica (9.9) | 0.78% | — | Microsoft Azure Horizondb | 17/9/2026 | 25/9/2026 | Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Media (6.1) | 0.32% | — | Microsoft Azure Portal | 17/9/2026 | 25/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Crítica (10) | 0.90% | — | Microsoft Fabric | 17/9/2026 | 25/9/2026 | Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network. | |
| En análisis | Crítica (10) | 0.43% | — | Microsoft Azure BillingAI | 17/9/2026 | 19/9/2026 | Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.6) | 0.79% | — | Microsoft Azure Cosmos DB | 17/9/2026 | 29/9/2026 | Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.5) | 0.97% | — | Microsoft Foundry | 17/9/2026 | 25/9/2026 | Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 0.67% | — | Microsoft Azure AI Foundry | 17/9/2026 | 25/9/2026 | Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 0.72% | — | Microsoft 365 Copilot | 17/9/2026 | 25/9/2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.1) | 0.44% | — | Microsoft Azure Logic Apps | 17/9/2026 | 25/9/2026 | Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. | |
| Pendiente de análisis | Alta (7.4) | 0.89% | — | Microsoft 365 CopilotAI | 17/9/2026 | 18/9/2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (8.1) | 0.37% | — | Microsoft Dataverse | 17/9/2026 | 25/9/2026 | Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 0.60% | — | Microsoft Azure Logic Apps | 17/9/2026 | 25/9/2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 0.53% | — | Microsoft Azure ARC | 17/9/2026 | 25/9/2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (10) | 0.80% | — | Microsoft Azure Container Registry | 17/9/2026 | 29/9/2026 | Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 0.48% | — | Microsoft Azure ARC | 17/9/2026 | 25/9/2026 | Azure Arc Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.5) | 0.54% | — | Microsoft Azure Machine Learning | 17/9/2026 | 25/9/2026 | Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network. |