Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 82 respecto a la semana anterior
Críticas / altas1248▼ 291 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)249▲ 212 respecto a la semana anterior
18.401 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.3) | 0.19% | — | Splunk SoarAIMicrosoft Azure AD GraphAI | 19/8/2026 | 20/8/2026 | In versions below 2.5.3 of the Azure AD Graph app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive password by invoking the reset password action, because the action's temp_password parameter is not masked and is shown in cleartext in the user interface. The information… | |
| Modificada | Media (6.5) | 0.92% | — | Microsoft Windows APP | 19/8/2026 | 27/8/2026 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (7) | 0.20% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 19/8/2026 | 8/9/2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally. | |
| Pendiente de análisis | Crítica (9.9) | 0.42% | — | Cisco CrossworkAI | 19/8/2026 | 20/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities trackled… | |
| Pendiente de análisis | Crítica (10) | 0.48% | — | Cisco CrossworkAI | 19/8/2026 | 21/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked… | |
| Pendiente de análisis | Crítica (10) | 0.61% | — | Cisco CrossworkAI | 19/8/2026 | 21/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked… | |
| Pendiente de análisis | Crítica (10) | 0.55% | — | Cisco CrossworkAI | 19/8/2026 | 20/8/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked… | |
| Aplazada | Alta (7.2) | 0.68% | — | Flow-likeAIMicrosoft Azure Blob StorageAI | 19/8/2026 | 18/9/2026 | Flow-Like is a platform for building end-to-end use cases. Prior to version 1.0.4, `GET /api/v1/apps/{app_id}/invoke/presign` grants Azure Blob Storage SAS credentials with write and delete access to app content to any app member that has `ExecuteEvents`, even when that member lacks `ReadFiles` and `WriteFiles`. The… | |
| Pendiente de análisis | Alta (8.7) | 0.43% | — | RenovateAIMicrosoft Azure DevopsAI | 19/8/2026 | 8/9/2026 | Renovate versions >=19.180.0 and <23.25.1, when used with Azure DevOps, may expose the bot's authorization token in server or pipeline logs because the git http.extraheader=AUTHORIZATION parameter is logged without redaction. Anyone with access to saved logs could obtain the bot credentials. Fixed in 23.25.1; Azure… | |
| Aplazada | Alta (7.1) | 0.25% | — | Prosolution WP ClientAI | 19/8/2026 | 26/8/2026 | The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape a parameter before reflecting it into an HTML attribute on one of its administrative pages, leading to reflected Cross-Site Scripting that runs in the session of an administrator induced to submit a crafted request. | |
| Aplazada | Alta (7.1) | 0.25% | — | Prosolution WP ClientAI | 19/8/2026 | 26/8/2026 | The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parameters before reflecting them into HTML attributes on its public pages, leading to reflected Cross-Site Scripting that can be triggered against any visitor, including a logged-in administrator. | |
| Analizada | Alta (7.5) | 4.1% | 💥 PoC | Microsoft Copilot | 18/8/2026 | 10/9/2026 | Una neutralización incorrecta de elementos especiales utilizados en un comando ('command injection') en Microsoft Copilot permite a un atacante no autorizado divulgar información a través de una red. | |
| Aplazada | Media (6.1) | 2.3% | — | Microsoft KiotaAI | 17/8/2026 | 18/9/2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.34.0, an attacker who controls or tampers with the OpenAPI description consumed by Kiota can supply a file reference that resolves outside the manifest package (e.g. ../../../../etc/passwd, an absolute path, or a file:// / http(s):// URI).… | |
| Aplazada | Alta (8.6) | 0.21% | — | Microsoft DefenderAIB3log SiyuanAI | 17/8/2026 | 26/8/2026 | SiYuan before 3.7.4 fails to properly escape workspace directory paths when constructing command-line arguments for the elevated elevator.exe helper process. Attackers can create a malicious workspace directory with command metacharacters in its path and trigger the Microsoft Defender exclusion flow to execute… | |
| Aplazada | Crítica (9.8) | 1.2% | — | Prosolution WP ClientAI | 16/8/2026 | 20/8/2026 | The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the attacker-controlled Content-Disposition header filename, which overrides the allow-listed multipart… | |
| Aplazada | Crítica (9.1) | 1.1% | — | Prosolution WP ClientAI | 16/8/2026 | 20/8/2026 | The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and including, 2.0.8. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can… | |
| Modificada | Alta (7.8) | 0.33% | 💥 PoC | Microsoft Malware Protection Engine | 14/8/2026 | 3/9/2026 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ". | |
| Analizada | Alta (7.8) | 0.32% | — | Microsoft Powershell | 14/8/2026 | 18/8/2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally. | |
| Analizada | Alta (8.3) | 0.73% | — | Microsoft Edge Chromium | 14/8/2026 | 18/8/2026 | Un desbordamiento de búfer basado en heap en Microsoft Edge (basado en Chromium) permite a un atacante no autorizado ejecutar código a través de una red. | |
| Aplazada | Crítica (9.3) | 0.53% | — | Roskus Prospero Flow CRMAI | 14/8/2026 | 1/9/2026 | Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to authenticate as any employee onboarded through the standard flow, knowing only their email address, because the employee save controller falls back to the literal password… | |
| Aplazada | Alta (8.6) | 0.39% | — | Roskus Prospero Flow CRMAI | 14/8/2026 | 1/9/2026 | Authorization Bypass Through User-Controlled Key in the payroll module in Roskus Prospero Flow CRM before 5.15.10 allows authenticated users holding the read payroll permission to view the salary and banking details of employees of any other company in the instance, and users holding the create payroll permission to… | |
| Aplazada | Media (5.3) | 0.24% | — | RosariosisAI | 14/8/2026 | 14/8/2026 | A vulnerability was found in francoisjacquet RosarioSIS up to 12.8. This issue affects some unknown processing of the file Modules.php. Performing a manipulation results in cross-site request forgery. Remote exploitation of the attack is possible. Upgrading to version 12.9 is capable of addressing this issue. The… | |
| Aplazada | Media (5.3) | 0.34% | — | RosariosisAI | 14/8/2026 | 18/8/2026 | A vulnerability has been found in francoisjacquet RosarioSIS up to 12.7.4. This vulnerability affects unknown code of the file modules/Students/includes/Medical.inc.php of the component Student Medical Module. Such manipulation of the argument table leads to sql injection. The attack may be launched remotely.… | |
| Aplazada | Baja (2.1) | 0.46% | — | RosariosisAI | 14/8/2026 | 14/8/2026 | A flaw has been found in francoisjacquet RosarioSIS up to 12.8. This affects the function DBUpdate of the file Discipline/Referrals.php. This manipulation causes authorization bypass. The attack may be initiated remotely. The exploit has been published and may be used. Upgrading to version 12.9 is able to mitigate… | |
| Aplazada | Alta (8.6) | 0.59% | — | Roskus Prospero Flow CRMAI | 13/8/2026 | 1/9/2026 | Missing Authorization and Authorization Bypass Through User-Controlled Key in the product management component in Roskus Prospero Flow CRM before 5.4.7 allows authenticated users of any company to read the full sensitive data (price, cost, stock, SKU, and barcode) of another company's product and to hijack that… |