Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 82 respecto a la semana anterior
Críticas / altas1248▼ 291 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)249▲ 212 respecto a la semana anterior
–

25.767 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.5)0.63%—Http4s-blaze-serverAI12/8/202610/9/2026
Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42, http4s-blaze-server aggregates fragments of an incoming WebSocket message with no limit on total size or fragment count. A client that completes a WebSocket handshake can send an unterminated…
AnalizadaAlta (7.3)0.43%—IBM Informix Dynamic Server12/8/202618/8/2026
IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary commands with service account privileges on the system due to improper validation of user supplied input.
AnalizadaAlta (7.8)0.14%—IBM Informix Dynamic Server12/8/202618/8/2026
IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in the oninit setuid-root utility.
AnalizadaAlta (8.8)0.49%—IBM Informix Dynamic Server12/8/202618/8/2026
IBM Informix oninit sq_sgkprepare RCE via unchecked SQL Interface length field.
AnalizadaAlta (8.1)0.42%—IBM Websphere Application Server12/8/202617/8/2026
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to a privilege escalation when using Liberty collectives.
AplazadaBaja (2.3)0.37%—Temporal UI ServerAI11/8/20268/9/2026
When OAuth authentication is enabled and browser-facing TLS terminates at a reverse proxy that forwards the callback to Temporal UI Server over HTTP, affected versions derive authentication-cookie Secure attributes from the proxy-to-server connection. Temporal UI Server can therefore issue access-token cookies, and…
ModificadaAlta (8.1)0.71%—Microsoft Windows 10 1809Microsoft Windows Server 2019Microsoft Windows Server 2022Microsoft Windows Server 202511/8/202620/8/2026
Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.7)0.78%—Microsoft Sharepoint Server11/8/202613/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (7.8)0.33%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/8/202616/8/2026
Desbordamiento de búfer basado en montón (heap) en Windows Installer permite a un atacante autorizado elevar privilegios localmente.
AnalizadaAlta (7.8)0.33%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/8/202616/8/2026
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.33%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/8/202616/8/2026
Desbordamiento de búfer basado en montón (heap) en Windows Installer permite a un atacante autorizado elevar privilegios localmente.
AnalizadaAlta (7.8)0.33%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/8/202616/8/2026
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.34%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/8/202618/8/2026
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (8.8)0.78%—Microsoft Sharepoint Server11/8/202613/8/2026
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (8.8)0.94%—Microsoft Sharepoint Server11/8/202613/8/2026
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (8.8)1.7%—Microsoft Sharepoint Server11/8/202613/8/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (7)0.26%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/8/202616/8/2026
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
AnalizadaCrítica (9.3)1.0%—Microsoft Sharepoint Server11/8/202616/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (7.8)0.34%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/8/202617/8/2026
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7)0.33%⚠ Explotación activa💥 PoCMicrosoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/8/202616/8/2026
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.5)0.98%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows Server 2012Microsoft Windows Server 2016+311/8/202616/8/2026
Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (8.8)2.0%—Microsoft Sharepoint Server11/8/202613/8/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.8)2.0%—Microsoft Sharepoint Server11/8/202613/8/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
ModificadaAlta (8.1)0.54%—Microsoft Windows 10 1809Microsoft Windows 11 26h1Microsoft Windows Server 2019Microsoft Windows Server 2022+111/8/202620/8/2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (7.8)0.33%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/8/202616/8/2026
Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.