Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2773▼ 2 respecto a la semana anterior
Críticas / altas1273▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 185 respecto a la semana anterior
16.783 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7) | 0.20% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 19/8/2026 | 8/9/2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | |
| Aplazada | Alta (7.2) | 0.68% | — | Flow-likeAIMicrosoft Azure Blob StorageAI | 19/8/2026 | 18/9/2026 | Flow-Like is a platform for building end-to-end use cases. Prior to version 1.0.4, `GET /api/v1/apps/{app_id}/invoke/presign` grants Azure Blob Storage SAS credentials with write and delete access to app content to any app member that has `ExecuteEvents`, even when that member lacks `ReadFiles` and `WriteFiles`. The… | |
| Pendiente de análisis | Alta (8.7) | 0.43% | — | RenovateAIMicrosoft Azure DevopsAI | 19/8/2026 | 8/9/2026 | Renovate versions >=19.180.0 and <23.25.1, when used with Azure DevOps, may expose the bot's authorization token in server or pipeline logs because the git http.extraheader=AUTHORIZATION parameter is logged without redaction. Anyone with access to saved logs could obtain the bot credentials. Fixed in 23.25.1; Azure… | |
| Analizada | Alta (7.5) | 4.1% | 💥 PoC | Microsoft Copilot | 18/8/2026 | 10/9/2026 | Una neutralización incorrecta de elementos especiales utilizados en un comando ('command injection') en Microsoft Copilot permite a un atacante no autorizado divulgar información a través de una red. | |
| Aplazada | Media (6.1) | 2.3% | — | Microsoft KiotaAI | 17/8/2026 | 18/9/2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.34.0, an attacker who controls or tampers with the OpenAPI description consumed by Kiota can supply a file reference that resolves outside the manifest package (e.g. ../../../../etc/passwd, an absolute path, or a file:// / http(s):// URI).… | |
| Aplazada | Alta (8.6) | 0.21% | — | Microsoft DefenderAIB3log SiyuanAI | 17/8/2026 | 26/8/2026 | SiYuan before 3.7.4 fails to properly escape workspace directory paths when constructing command-line arguments for the elevated elevator.exe helper process. Attackers can create a malicious workspace directory with command metacharacters in its path and trigger the Microsoft Defender exclusion flow to execute… | |
| Modificada | Alta (7.8) | 0.33% | 💥 PoC | Microsoft Malware Protection Engine | 14/8/2026 | 3/9/2026 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ". | |
| Analizada | Alta (7.8) | 0.32% | — | Microsoft Powershell | 14/8/2026 | 18/8/2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally. | |
| Analizada | Alta (8.3) | 0.73% | — | Microsoft Edge Chromium | 14/8/2026 | 18/8/2026 | Un desbordamiento de búfer basado en heap en Microsoft Edge (basado en Chromium) permite a un atacante no autorizado ejecutar código a través de una red. | |
| Pendiente de análisis | Alta (8.7) | 0.97% | — | Microsoft Container Migration Solution AcceleratorAI | 12/8/2026 | 18/9/2026 | The Microsoft Container Migration Solution Accelerator is a multi-service application that provides a multi-agent, AI-driven migration solution for moving container service configurations to Azure Kubernetes Service. In version 2.1.2 and earlier, a security vulnerability was identified in the Container Migration… | |
| Pendiente de análisis | Media (6.9) | 2.9% | — | Microsoft UFOAI | 12/8/2026 | 18/9/2026 | Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, _is_blocked_ip in ufo/utils/url_security.py did not block NAT64 prefixes 64:ff9b::/96 and 64:ff9b:1::/48, the 6to4 prefix 2002::/16, or the Teredo prefix 2001::/32 and did not re-check embedded IPv4… | |
| Pendiente de análisis | Crítica (9.4) | 3.7% | 💥 PoC | Microsoft UFOAI | 12/8/2026 | 18/9/2026 | Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and create_mobile_action_server in ufo/client/mcp/http_servers/mobile_mcp_server.py exposed Streamable HTTP MCP services on TCP ports 8020 and 8021 without authentication,… | |
| Pendiente de análisis | Media (6.1) | 0.36% | — | Microsoft ExcelAIVelociraptorAI | 12/8/2026 | 28/8/2026 | When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CSV files arbitrary execution. Velociraptor fails to sanitize such cells when exporting to CSV from various places such as the GUI, offline collector or data exports. It is not clear if the… | |
| Analizada | Media (5.4) | 0.41% | — | Microsoft Edge Chromium | 11/8/2026 | 17/8/2026 | El acceso a un recurso usando un tipo incompatible ('confusión de tipos') en Microsoft Edge (basado en Chromium) permite a un atacante no autorizado ejecutar código a través de una red. | |
| Pendiente de análisis | Alta (7.7) | 0.63% | — | Docker DesktopAIMicrosoft DEV Containers CLIAIAnysphere CursorAI | 11/8/2026 | 9/9/2026 | Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode, when Docker Desktop and the Dev Containers CLI are installed, to launch a privileged container and mount Docker's virtiofs0, granting read and write access to the user's home… | |
| Pendiente de análisis | Alta (7.7) | 0.43% | — | Microsoft PythonAIAnysphere CursorAI | 11/8/2026 | 9/9/2026 | Cursor is a code editor built for programming with AI. Prior to 3.1.2, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode to replace a virtual environment's Python executable with a malicious wrapper that the Microsoft Python extension invokes outside the sandbox, allowing arbitrary host commands… | |
| Analizada | Media (6.7) | 0.39% | — | Microsoft Onedrive | 11/8/2026 | 17/8/2026 | Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally. | |
| Analizada | Media (5.5) | 0.36% | — | Microsoft Windows 11 26h1 | 11/8/2026 | 14/8/2026 | Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally. | |
| Modificada | Alta (8.1) | 0.71% | — | Microsoft Windows 10 1809Microsoft Windows Server 2019Microsoft Windows Server 2022Microsoft Windows Server 2025 | 11/8/2026 | 20/8/2026 | Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.7) | 0.78% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.8) | 0.36% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net FrameworkMicrosoft .net | 11/8/2026 | 17/8/2026 | Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (5.5) | 0.44% | — | Microsoft Windows 11 24h2Microsoft Windows 11 25h2Microsoft Windows 11 26h1 | 11/8/2026 | 14/8/2026 | Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 11/8/2026 | 16/8/2026 | Desbordamiento de búfer basado en montón (heap) en Windows Installer permite a un atacante autorizado elevar privilegios localmente. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 11/8/2026 | 16/8/2026 | Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 11/8/2026 | 16/8/2026 | Desbordamiento de búfer basado en montón (heap) en Windows Installer permite a un atacante autorizado elevar privilegios localmente. |