Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2697▼ 181 respecto a la semana anterior
Críticas / altas1225▼ 327 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 208 respecto a la semana anterior
–

9290 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.27%—LG Electronics SmartshareAIMicrosoft Windows 10AI30/7/202630/7/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in LG Electronics SmartShare allows SQL Injection. This issue affects SmartShare: through 2.3.1712.1202, which is supported on Microsoft Windows 10 and earlier versions.
AnalizadaAlta (7.5)0.66%—Microsoft Remote Desktop WEB ClientMicrosoft Windows Admin Center17/7/202622/7/2026
Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.
Pendiente de análisisMedia (5.1)0.17%—Microsoft WindowsAIMicrosoft Task SchedulerAIMicrosoft DcomAI17/7/202621/7/2026
A non-administrator interactive user can obtain full SYSTEM code execution through a DCOM/task scheduler logic chain — no network access, no memory corruption required (ITMS 8.7.3)
AnalizadaMedia (6.1)0.41%—Microsoft Windows Admin Center16/7/202614/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (7)0.20%—Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 24h2Microsoft Windows 11 25h2+116/7/202622/7/2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.
Pendiente de análisisAlta (8.8)1.2%—Lenovo Xclarity Integrator FOR Windows Admin CenterAI16/7/202616/7/2026
The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vulnerable to Powershell Command Injection when establishing remote PowerShell commands.
AnalizadaMedia (5.5)0.24%—Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 23h2+814/7/202622/7/2026
Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.
AnalizadaAlta (7)0.26%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+814/7/202622/7/2026
Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.33%—Microsoft Windows 11 26h114/7/202615/7/2026
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.33%—Microsoft Windows 11 26h114/7/202615/7/2026
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.33%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+714/7/202622/7/2026
Un uso después de liberar (use-after-free) en Windows Win32K permite a un atacante autorizado elevar privilegios localmente.
AnalizadaAlta (7)0.26%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+914/7/202629/7/2026
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.20%—Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 24h2+514/7/202622/7/2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.5)1.2%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows Server 2012Microsoft Windows Server 2016+314/7/202617/7/2026
Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (8.8)0.91%—Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 24h2Microsoft Windows 11 25h2+314/7/202622/7/2026
Un uso después de liberar (use-after-free) en Windows Remote Desktop Services permite a un atacante autorizado ejecutar código a través de una red.
AnalizadaAlta (7)0.26%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+714/7/202622/7/2026
Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.38%—Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 24h2+514/7/202622/7/2026
Un uso después de liberar (use-after-free) en Windows Cloud Files Mini Filter Driver permite a un atacante autorizado elevar privilegios localmente.
AnalizadaCrítica (9.8)0.82%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+814/7/202622/7/2026
Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (7.8)0.41%—Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 24h2+514/7/202622/7/2026
Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.
AnalizadaMedia (6.5)0.92%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+814/7/202622/7/2026
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
AnalizadaMedia (5.5)0.35%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+814/7/202622/7/2026
Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.
AnalizadaAlta (7)0.26%—Microsoft Windows 11 24h2Microsoft Windows 11 25h2Microsoft Windows 11 26h1Microsoft Windows Server 202514/7/202622/7/2026
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
AnalizadaMedia (6.3)0.24%—Microsoft Windows 11 24h2Microsoft Windows 11 25h2Microsoft Windows 11 26h1Microsoft Windows Server 202514/7/202622/7/2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges with a physical attack.
AnalizadaAlta (7.8)0.36%—Microsoft Windows 11 24h2Microsoft Windows 11 25h2Microsoft Windows 11 26h1Microsoft Windows Server 202514/7/202622/7/2026
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.33%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+714/7/202622/7/2026
Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally.