Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
375 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.9) | 0.75% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 11/8/2026 | 14/8/2026 | Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network. | |
| Analizada | Alta (7.5) | 1.0% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 11/8/2026 | 14/8/2026 | Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (7) | 0.37% | — | Microsoft .net FrameworkMicrosoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 11/8/2026 | 14/8/2026 | Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net | 11/8/2026 | 8/9/2026 | Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 11/8/2026 | 13/8/2026 | Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft Visual Studio Code | 11/8/2026 | 25/9/2026 | Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.8) | 0.46% | — | Microsoft Visual Studio Code | 11/8/2026 | 25/9/2026 | Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally. | |
| Analizada | Alta (8.8) | 0.86% | — | Microsoft Visual Studio Code | 11/8/2026 | 25/9/2026 | Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.2) | 0.54% | — | Microsoft Visual Studio Code | 11/8/2026 | 25/9/2026 | Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | |
| Analizada | Alta (7.8) | 0.32% | — | Microsoft Visual Studio Code | 11/8/2026 | 25/9/2026 | Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | |
| Analizada | Alta (8.8) | 0.76% | — | Microsoft Visual Studio Code | 11/8/2026 | 24/9/2026 | Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.8) | 0.32% | — | Microsoft Visual Studio Code | 11/8/2026 | 25/9/2026 | Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | |
| Analizada | Media (6.5) | 0.92% | — | Microsoft Visual Studio Code | 11/8/2026 | 25/9/2026 | Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose information over a network. | |
| Pendiente de análisis | Media (5.4) | 0.18% | — | Ruby LSPAIMicrosoft Visual Studio CodeAI | 7/8/2026 | 18/9/2026 | Ruby LSP is an implementation of the language server protocol for Ruby. Several workspace-level settings in the Ruby LSP VS Code extension prior to version 0.10.4 could override the path to the Ruby executable, the version manager executables, or the Bundler `Gemfile` used at startup. A malicious repository containing… | |
| Pendiente de análisis | Alta (7.8) | 0.82% | — | Microsoft Visual Studio CodeAIRedhat Ansible LightspeedAI | 22/7/2026 | 22/7/2026 | A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) arises from improper handling of the ansible.executionEnvironment.containerOptions and ansible.executionEnvironment.volumeMounts settings, allowing an attacker to inject shell separators. This can be… | |
| Pendiente de análisis | Alta (7.8) | 0.75% | — | Ansible LightspeedAIMicrosoft Visual Studio CodeAI | 22/7/2026 | 23/7/2026 | A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability (CWE-78) allows a remote attacker to execute unauthorized commands on a user's system. The issue occurs because the `ansible.python.activationScript` setting, intended for a virtual environment activation… | |
| Pendiente de análisis | Alta (7.8) | 0.95% | — | Microsoft Visual Studio CodeAIRedhat AnsibleAI | 22/7/2026 | 22/7/2026 | A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This command injection vulnerability allows an attacker to craft a malicious playbook filename containing special characters. When a victim runs the playbook, these characters are not properly sanitized, leading to… | |
| Pendiente de análisis | Baja (3.3) | 0.13% | — | Ansible LightspeedAIMicrosoft Visual Studio CodeAIGoogle GeminiAI | 22/7/2026 | 22/7/2026 | A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability allows an attacker with local access to the workstation, or malware running with the user's privileges, to read the Google Gemini API key. The extension insecurely stores the API key in plain text within the user's… | |
| Analizada | Media (6.5) | 0.74% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/7/2026 | 24/7/2026 | Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/7/2026 | 22/7/2026 | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | |
| Analizada | Alta (7.8) | 4.0% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2026 | 14/7/2026 | 24/7/2026 | Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/7/2026 | 24/7/2026 | Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network. | |
| Analizada | Alta (7.8) | 4.0% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/7/2026 | 24/7/2026 | Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (8.2) | 0.61% | — | Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/7/2026 | 22/7/2026 | Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/7/2026 | 24/7/2026 | Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network. |