Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2773▼ 2 respecto a la semana anterior
Críticas / altas1273▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 185 respecto a la semana anterior
–

16.783 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7)0.20%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+919/8/20268/9/2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
AplazadaAlta (7.2)0.68%—Flow-likeAIMicrosoft Azure Blob StorageAI19/8/202618/9/2026
Flow-Like is a platform for building end-to-end use cases. Prior to version 1.0.4, `GET /api/v1/apps/{app_id}/invoke/presign` grants Azure Blob Storage SAS credentials with write and delete access to app content to any app member that has `ExecuteEvents`, even when that member lacks `ReadFiles` and `WriteFiles`. The…
Pendiente de análisisAlta (8.7)0.43%—RenovateAIMicrosoft Azure DevopsAI19/8/20268/9/2026
Renovate versions >=19.180.0 and <23.25.1, when used with Azure DevOps, may expose the bot's authorization token in server or pipeline logs because the git http.extraheader=AUTHORIZATION parameter is logged without redaction. Anyone with access to saved logs could obtain the bot credentials. Fixed in 23.25.1; Azure…
AnalizadaAlta (7.5)4.1%💥 PoCMicrosoft Copilot18/8/202610/9/2026
Una neutralización incorrecta de elementos especiales utilizados en un comando ('command injection') en Microsoft Copilot permite a un atacante no autorizado divulgar información a través de una red.
AplazadaMedia (6.1)2.3%—Microsoft KiotaAI17/8/202618/9/2026
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.34.0, an attacker who controls or tampers with the OpenAPI description consumed by Kiota can supply a file reference that resolves outside the manifest package (e.g. ../../../../etc/passwd, an absolute path, or a file:// / http(s):// URI).…
AplazadaAlta (8.6)0.21%—Microsoft DefenderAIB3log SiyuanAI17/8/202626/8/2026
SiYuan before 3.7.4 fails to properly escape workspace directory paths when constructing command-line arguments for the elevated elevator.exe helper process. Attackers can create a malicious workspace directory with command metacharacters in its path and trigger the Microsoft Defender exclusion flow to execute…
ModificadaAlta (7.8)0.33%💥 PoCMicrosoft Malware Protection Engine14/8/20263/9/2026
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;ShieldBreak &quot;.
AnalizadaAlta (7.8)0.32%—Microsoft Powershell14/8/202618/8/2026
Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.
AnalizadaAlta (8.3)0.73%—Microsoft Edge Chromium14/8/202618/8/2026
Un desbordamiento de búfer basado en heap en Microsoft Edge (basado en Chromium) permite a un atacante no autorizado ejecutar código a través de una red.
Pendiente de análisisAlta (8.7)0.97%—Microsoft Container Migration Solution AcceleratorAI12/8/202618/9/2026
The Microsoft Container Migration Solution Accelerator is a multi-service application that provides a multi-agent, AI-driven migration solution for moving container service configurations to Azure Kubernetes Service. In version 2.1.2 and earlier, a security vulnerability was identified in the Container Migration…
Pendiente de análisisMedia (6.9)2.9%—Microsoft UFOAI12/8/202618/9/2026
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, _is_blocked_ip in ufo/utils/url_security.py did not block NAT64 prefixes 64:ff9b::/96 and 64:ff9b:1::/48, the 6to4 prefix 2002::/16, or the Teredo prefix 2001::/32 and did not re-check embedded IPv4…
Pendiente de análisisCrítica (9.4)3.7%💥 PoCMicrosoft UFOAI12/8/202618/9/2026
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and create_mobile_action_server in ufo/client/mcp/http_servers/mobile_mcp_server.py exposed Streamable HTTP MCP services on TCP ports 8020 and 8021 without authentication,…
Pendiente de análisisMedia (6.1)0.36%—Microsoft ExcelAIVelociraptorAI12/8/202628/8/2026
When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CSV files arbitrary execution. Velociraptor fails to sanitize such cells when exporting to CSV from various places such as the GUI, offline collector or data exports. It is not clear if the…
AnalizadaMedia (5.4)0.41%—Microsoft Edge Chromium11/8/202617/8/2026
El acceso a un recurso usando un tipo incompatible ('confusión de tipos') en Microsoft Edge (basado en Chromium) permite a un atacante no autorizado ejecutar código a través de una red.
Pendiente de análisisAlta (7.7)0.63%—Docker DesktopAIMicrosoft DEV Containers CLIAIAnysphere CursorAI11/8/20269/9/2026
Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode, when Docker Desktop and the Dev Containers CLI are installed, to launch a privileged container and mount Docker's virtiofs0, granting read and write access to the user's home…
Pendiente de análisisAlta (7.7)0.43%—Microsoft PythonAIAnysphere CursorAI11/8/20269/9/2026
Cursor is a code editor built for programming with AI. Prior to 3.1.2, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode to replace a virtual environment's Python executable with a malicious wrapper that the Microsoft Python extension invokes outside the sandbox, allowing arbitrary host commands…
AnalizadaMedia (6.7)0.39%—Microsoft Onedrive11/8/202617/8/2026
Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally.
AnalizadaMedia (5.5)0.36%—Microsoft Windows 11 26h111/8/202614/8/2026
Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.
ModificadaAlta (8.1)0.71%—Microsoft Windows 10 1809Microsoft Windows Server 2019Microsoft Windows Server 2022Microsoft Windows Server 202511/8/202620/8/2026
Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.7)0.78%—Microsoft Sharepoint Server11/8/202613/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (7.8)0.36%—Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net FrameworkMicrosoft .net11/8/202617/8/2026
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
AnalizadaMedia (5.5)0.44%—Microsoft Windows 11 24h2Microsoft Windows 11 25h2Microsoft Windows 11 26h111/8/202614/8/2026
Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally.
AnalizadaAlta (7.8)0.33%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/8/202616/8/2026
Desbordamiento de búfer basado en montón (heap) en Windows Installer permite a un atacante autorizado elevar privilegios localmente.
AnalizadaAlta (7.8)0.33%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/8/202616/8/2026
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.33%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/8/202616/8/2026
Desbordamiento de búfer basado en montón (heap) en Windows Installer permite a un atacante autorizado elevar privilegios localmente.