Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2845▼ 222 respecto a la semana anterior
Críticas / altas1330▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

9290 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.82%—Microsoft Windows 11 24h2Microsoft Windows 11 25h2Microsoft Windows 11 26h1Microsoft Windows Server 20258/9/202628/9/2026
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.82%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+98/9/202624/9/2026
Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (7)0.26%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+98/9/202624/9/2026
Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.33%—Microsoft Windows 11 24h2Microsoft Windows 11 25h2Microsoft Windows 11 26h1Microsoft Windows Server 20258/9/202629/9/2026
Out-of-bounds read in Microsoft Trace Data Helper allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7)0.20%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+98/9/202624/9/2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Pendiente de análisisMedia (5.1)0.14%—Fortinet Forticlient WindowsAI8/9/20262/10/2026
A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control via via an exposed minifilter communication port.
Pendiente de análisisBaja (2.3)0.33%—OpenvpnAITAP Windows6AI7/9/20268/9/2026
OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries
AplazadaAlta (8.6)1.6%—Microsoft Windows ML CLIAI2/9/202628/9/2026
Windows ML CLI es una herramienta de línea de comandos para construir modelos de IA portátiles, de alto rendimiento y de alta calidad para Windows ML. Antes de la versión 0.4.0, el componente src/winml/modelkit/serve/cli_api.py expone comandos de WinML CLI a través de una API HTTP de localhost sin autenticación y…
AplazadaAlta (7.8)0.33%—Backblaze ClientAIMicrosoft WindowsAI1/9/202611/9/2026
A vulnerability in the Backblaze Client allows a local user to make the system not bootable by creating a link from Backblaze's folder to Windows OS system files during a backup. Successful exploitation requires an administrator-level system change that results in the absence of specific Windows OS security controls.…
AplazadaAlta (7)0.17%—Electron-builderAIMicrosoft Windows InstallerAI30/8/20261/9/2026
SiYuan Windows installer before version 3.8.1 (affected versions >= 2.0.14) contains an uncontrolled search path element vulnerability in its NSIS installer, which invokes system executables such as TASKKILL by name rather than by absolute path. Because NSIS nsExec::Exec resolves these calls using a search path that…
AplazadaAlta (7.8)0.17%—Scheidt & Bachmann Entervo HMIAIMicrosoft WindowsAI24/8/20269/9/2026
A local privilege escalation vulnerability exists in the Restricted Access (Kiosk) Mode implementation of Scheidt & Bachmann entervo HMI prior to V2 R5 P0 M5. The vulnerability affects the external PDF viewer functionality used to display the application manual and its interaction with the underlying Windows operating…
Pendiente de análisisAlta (7.4)0.46%—GIT FOR WindowsAI21/8/202625/9/2026
Git for Windows is the Windows port of Git. Prior to 2.55.0.windows.4, a malicious remote Git server can advertise a bundle URI that reaches transport_get_remote_bundle_uri(), fetch_bundle_uri_internal(), and copy_uri_to_file() in bundle-uri.c during clone or fetch when transfer.bundleuri=true. Non-HTTP(S) values are…
ModificadaMedia (6.5)0.92%—Microsoft Windows APP19/8/202627/8/2026
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (7)0.20%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+919/8/20268/9/2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
AnalizadaMedia (5.5)0.36%—Microsoft Windows 11 26h111/8/202614/8/2026
Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.
ModificadaAlta (8.1)0.71%—Microsoft Windows 10 1809Microsoft Windows Server 2019Microsoft Windows Server 2022Microsoft Windows Server 202511/8/202620/8/2026
Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.
AnalizadaMedia (5.5)0.44%—Microsoft Windows 11 24h2Microsoft Windows 11 25h2Microsoft Windows 11 26h111/8/202614/8/2026
Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally.
AnalizadaAlta (7.8)0.33%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/8/202616/8/2026
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.33%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/8/202616/8/2026
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.33%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/8/202616/8/2026
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.33%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/8/202616/8/2026
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.34%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/8/202618/8/2026
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7)0.26%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/8/202616/8/2026
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.34%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/8/202617/8/2026
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7)0.33%⚠ Explotación activa💥 PoCMicrosoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/8/202616/8/2026
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.