Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 82 respecto a la semana anterior
Críticas / altas1248▼ 291 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)249▲ 212 respecto a la semana anterior
25.767 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.5) | 0.63% | — | Http4s-blaze-serverAI | 12/8/2026 | 10/9/2026 | Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42, http4s-blaze-server aggregates fragments of an incoming WebSocket message with no limit on total size or fragment count. A client that completes a WebSocket handshake can send an unterminated… | |
| Analizada | Alta (7.3) | 0.43% | — | IBM Informix Dynamic Server | 12/8/2026 | 18/8/2026 | IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary commands with service account privileges on the system due to improper validation of user supplied input. | |
| Analizada | Alta (7.8) | 0.14% | — | IBM Informix Dynamic Server | 12/8/2026 | 18/8/2026 | IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in the oninit setuid-root utility. | |
| Analizada | Alta (8.8) | 0.49% | — | IBM Informix Dynamic Server | 12/8/2026 | 18/8/2026 | IBM Informix oninit sq_sgkprepare RCE via unchecked SQL Interface length field. | |
| Analizada | Alta (8.1) | 0.42% | — | IBM Websphere Application Server | 12/8/2026 | 17/8/2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to a privilege escalation when using Liberty collectives. | |
| Aplazada | Baja (2.3) | 0.37% | — | Temporal UI ServerAI | 11/8/2026 | 8/9/2026 | When OAuth authentication is enabled and browser-facing TLS terminates at a reverse proxy that forwards the callback to Temporal UI Server over HTTP, affected versions derive authentication-cookie Secure attributes from the proxy-to-server connection. Temporal UI Server can therefore issue access-token cookies, and… | |
| Modificada | Alta (8.1) | 0.71% | — | Microsoft Windows 10 1809Microsoft Windows Server 2019Microsoft Windows Server 2022Microsoft Windows Server 2025 | 11/8/2026 | 20/8/2026 | Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.7) | 0.78% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 11/8/2026 | 16/8/2026 | Desbordamiento de búfer basado en montón (heap) en Windows Installer permite a un atacante autorizado elevar privilegios localmente. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 11/8/2026 | 16/8/2026 | Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 11/8/2026 | 16/8/2026 | Desbordamiento de búfer basado en montón (heap) en Windows Installer permite a un atacante autorizado elevar privilegios localmente. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 11/8/2026 | 16/8/2026 | Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.34% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 11/8/2026 | 18/8/2026 | Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 0.94% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 1.7% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (7) | 0.26% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 11/8/2026 | 16/8/2026 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | |
| Analizada | Crítica (9.3) | 1.0% | — | Microsoft Sharepoint Server | 11/8/2026 | 16/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.8) | 0.34% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 11/8/2026 | 17/8/2026 | Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7) | 0.33% | ⚠ Explotación activa💥 PoC | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 11/8/2026 | 16/8/2026 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.5) | 0.98% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows Server 2012Microsoft Windows Server 2016+3 | 11/8/2026 | 16/8/2026 | Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network. | |
| Analizada | Alta (8.8) | 2.0% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 2.0% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Modificada | Alta (8.1) | 0.54% | — | Microsoft Windows 10 1809Microsoft Windows 11 26h1Microsoft Windows Server 2019Microsoft Windows Server 2022+1 | 11/8/2026 | 20/8/2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 11/8/2026 | 16/8/2026 | Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally. |