Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2751▼ 38 respecto a la semana anterior
Críticas / altas1262▼ 270 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 209 respecto a la semana anterior
–

18.401 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.22%—Bestwebsoft Subscriber Cross Site Scripting Profile Extra FieldsAI13/8/202614/8/2026
Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions.
AplazadaMedia (5.9)0.09%—Oberon Microsystem AG Oberon PSA Crypto LibraryAI13/8/202626/8/2026
Padding oracle attack vulnerability in Oberon microsystem AG’s Oberon PSA Crypto library in all versions since 1.0.0 and prior to 2.1.1 allows an attacker to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations.
AplazadaMedia (5.9)0.09%—Oberon Microsystem AG OcryptoAI13/8/202626/8/2026
Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.0.0 and prior to 4.0.1 allows an attacker to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations.
Pendiente de análisisAlta (8.7)0.97%—Microsoft Container Migration Solution AcceleratorAI12/8/202618/9/2026
The Microsoft Container Migration Solution Accelerator is a multi-service application that provides a multi-agent, AI-driven migration solution for moving container service configurations to Azure Kubernetes Service. In version 2.1.2 and earlier, a security vulnerability was identified in the Container Migration…
Pendiente de análisisMedia (6.9)2.9%—Microsoft UFOAI12/8/202618/9/2026
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, _is_blocked_ip in ufo/utils/url_security.py did not block NAT64 prefixes 64:ff9b::/96 and 64:ff9b:1::/48, the 6to4 prefix 2002::/16, or the Teredo prefix 2001::/32 and did not re-check embedded IPv4…
Pendiente de análisisCrítica (9.4)3.7%💥 PoCMicrosoft UFOAI12/8/202618/9/2026
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and create_mobile_action_server in ufo/client/mcp/http_servers/mobile_mcp_server.py exposed Streamable HTTP MCP services on TCP ports 8020 and 8021 without authentication,…
Pendiente de análisisMedia (6.1)0.36%—Microsoft ExcelAIVelociraptorAI12/8/202628/8/2026
When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CSV files arbitrary execution. Velociraptor fails to sanitize such cells when exporting to CSV from various places such as the GUI, offline collector or data exports. It is not clear if the…
AplazadaMedia (4.3)0.25%—Prosolution WP ClientAI12/8/202626/8/2026
The ProSolution WP Client WordPress plugin before 2.0.9 does not perform capability checks on two administrative AJAX actions, and the nonce they rely on is published on its public frontend, allowing any authenticated user, such as a subscriber, to trigger an administrative data synchronisation and to clear the…
AplazadaMedia (6.4)0.23%—Prosolution WP ClientAI12/8/202626/8/2026
The ProSolution WP Client WordPress plugin before 2.0.9 does not validate a user-supplied URL, and does not check the capability or nonce of the requester, before performing a server-side HTTP request with it, allowing any authenticated user, such as a subscriber, to make the site issue arbitrary requests to internal…
AnalizadaMedia (5.4)0.41%—Microsoft Edge Chromium11/8/202617/8/2026
El acceso a un recurso usando un tipo incompatible ('confusión de tipos') en Microsoft Edge (basado en Chromium) permite a un atacante no autorizado ejecutar código a través de una red.
Pendiente de análisisAlta (7.7)0.63%—Docker DesktopAIMicrosoft DEV Containers CLIAIAnysphere CursorAI11/8/20269/9/2026
Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode, when Docker Desktop and the Dev Containers CLI are installed, to launch a privileged container and mount Docker's virtiofs0, granting read and write access to the user's home…
Pendiente de análisisAlta (7.7)0.43%—Microsoft PythonAIAnysphere CursorAI11/8/20269/9/2026
Cursor is a code editor built for programming with AI. Prior to 3.1.2, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode to replace a virtual environment's Python executable with a malicious wrapper that the Microsoft Python extension invokes outside the sandbox, allowing arbitrary host commands…
AnalizadaMedia (6.7)0.39%—Microsoft Onedrive11/8/202617/8/2026
Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally.
AnalizadaMedia (5.5)0.36%—Microsoft Windows 11 26h111/8/202614/8/2026
Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.
ModificadaAlta (8.1)0.71%—Microsoft Windows 10 1809Microsoft Windows Server 2019Microsoft Windows Server 2022Microsoft Windows Server 202511/8/202620/8/2026
Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.7)0.78%—Microsoft Sharepoint Server11/8/202613/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (7.8)0.36%—Microsoft Visual Studio 2022Microsoft Visual Studio 2026Microsoft .net FrameworkMicrosoft .net11/8/202617/8/2026
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
AnalizadaMedia (5.5)0.44%—Microsoft Windows 11 24h2Microsoft Windows 11 25h2Microsoft Windows 11 26h111/8/202614/8/2026
Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally.
AnalizadaAlta (7.8)0.33%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/8/202616/8/2026
Desbordamiento de búfer basado en montón (heap) en Windows Installer permite a un atacante autorizado elevar privilegios localmente.
AnalizadaAlta (7.8)0.33%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/8/202616/8/2026
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.33%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/8/202616/8/2026
Desbordamiento de búfer basado en montón (heap) en Windows Installer permite a un atacante autorizado elevar privilegios localmente.
AnalizadaAlta (7.8)0.33%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/8/202616/8/2026
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (8.8)0.80%—Microsoft Azure Cyclecloud11/8/202617/8/2026
Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (7.8)0.36%—Microsoft Powershell11/8/202614/8/2026
Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
AnalizadaAlta (8.8)0.94%—Microsoft Powershell11/8/202614/8/2026
Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.