Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
375 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.22% | — | Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/7/2026 | 22/7/2026 | Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/7/2026 | 24/7/2026 | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/7/2026 | 22/7/2026 | Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/7/2026 | 16/7/2026 | Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally. | |
| Analizada | Crítica (9.8) | 0.29% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2017Microsoft Visual Studio 2019+2 | 14/7/2026 | 24/7/2026 | Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network. | |
| Analizada | Alta (8.8) | 0.84% | — | Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/7/2026 | 22/7/2026 | Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/7/2026 | 24/7/2026 | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/7/2026 | 22/7/2026 | Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft Visual Studio Code | 14/7/2026 | 16/7/2026 | Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | |
| Analizada | Media (6.1) | 0.48% | — | Microsoft Visual Studio Code | 14/7/2026 | 16/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | |
| Analizada | Alta (8.4) | 0.35% | — | Microsoft Visual Studio Code | 14/7/2026 | 16/7/2026 | Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (6.5) | 0.87% | — | Microsoft Visual Studio Code | 14/7/2026 | 16/7/2026 | Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (5.5) | 0.47% | — | Microsoft Visual Studio Code | 14/7/2026 | 16/7/2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | |
| Pendiente de análisis | Media (4.4) | 0.33% | — | Github CLIAIGithub CodespaceAIMicrosoft Visual Studio CodeAI | 9/7/2026 | 14/7/2026 | GitHub CLI (gh) is GitHub’s official command line tool. From 2.10.0 through 2.95.0, connecting to a malicious Codespace with gh codespace jupyter can allow command execution because the command opens a JupyterLab URL supplied by a process inside the Codespace without validating that it is a loopback HTTP or HTTPS… | |
| Analizada | Media (5.5) | 0.41% | — | Microsoft Visual Studio Code | 9/6/2026 | 23/7/2026 | Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | |
| Analizada | Alta (7.8) | 0.46% | — | Microsoft Visual Studio Code | 9/6/2026 | 24/8/2026 | Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally. | |
| Analizada | Media (6.5) | 0.76% | — | Microsoft Visual Studio Code | 9/6/2026 | 23/7/2026 | Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network. | |
| Analizada | Media (6.5) | 0.92% | — | Microsoft Visual Studio Code | 9/6/2026 | 23/7/2026 | Exposure of sensitive information to an unauthorized actor in Visual Studio Code allows an unauthorized attacker to disclose information over a network. | |
| Modificada | Crítica (9.6) | 0.76% | — | Microsoft Visual Studio Code | 9/6/2026 | 23/7/2026 | Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. | |
| Modificada | Alta (7.5) | 2.4% | — | Microsoft Asp.net CoreMicrosoft Visual Studio 2026Microsoft .net | 9/6/2026 | 23/7/2026 | Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network. | |
| Modificada | Alta (8.4) | 0.41% | — | Microsoft Visual Studio Code | 9/6/2026 | 23/7/2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | |
| Analizada | Alta (8.1) | 0.68% | — | Microsoft Visual Studio Code | 9/6/2026 | 23/7/2026 | Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 0.80% | — | Microsoft Visual Studio Code | 12/5/2026 | 17/6/2026 | Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Baja (3.3) | 0.50% | — | Microsoft Visual Studio Code | 12/5/2026 | 17/6/2026 | Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (5) | 0.71% | — | Microsoft Visual Studio Code | 12/5/2026 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. |