Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

25.772 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7)0.20%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/8/202616/8/2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
AnalizadaMedia (6.5)0.91%—Microsoft Sharepoint Server11/8/202612/8/2026
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaMedia (5.4)0.62%—Microsoft Sharepoint Server11/8/202612/8/2026
Una neutralización incorrecta de la entrada durante la generación de páginas web ('secuencias de comandos en sitios cruzados' o XSS) en Microsoft Office SharePoint permite a un atacante autorizado realizar suplantación (spoofing) a través de una red.
AnalizadaAlta (8.3)0.28%—Microsoft Windows 11 24h2Microsoft Windows 11 25h2Microsoft Windows 11 26h1Microsoft Windows Server 202511/8/202613/8/2026
Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.
AnalizadaAlta (7.8)0.46%—Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 23h2+311/8/202616/8/2026
Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.47%💥 PoCMicrosoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/8/202616/8/2026
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.5)1.2%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/8/202616/8/2026
Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (7)0.26%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/8/202616/8/2026
Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (8.8)0.86%💥 PoCMicrosoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/8/202616/8/2026
Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (7.8)0.30%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+811/8/202616/8/2026
Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.
Pendiente de análisisMedia (4.3)0.36%—Oauth-serverAI11/8/202614/8/2026
A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the grant approval handler is not properly validated. A remote attacker can craft a malicious URL that, when approved or denied by an authenticated user, redirects them to an attacker-controlled…
AnalizadaAlta (8.8)2.1%⚠ Explotación activa💥 PoCMicrosoft Sharepoint Server11/8/202626/9/2026
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
ModificadaMedia (6.8)0.44%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/8/202625/9/2026
Null pointer dereference in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to execute code locally.
Pendiente de análisisAlta (8.7)0.62%—Siemens License ServerAI11/8/202628/8/2026
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.3). The affected application is vulnerable to a path traversal vulnerability due to lack of sanitization of user input. This could allow a remote attacker to access arbitrary files on the application.
Pendiente de análisisAlta (8.3)0.17%—Siemens License ServerAI11/8/202628/8/2026
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.1). The affected application is vulnerable to a local privilege escalation due to an insecure sudoers policy. This could allow an attacker to execute arbitrary commands and plant malicious files as root, leading to full system…
Pendiente de análisisMedia (6.3)0.35%—SAP Netweaver Application Server AbapAI11/8/202626/8/2026
Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP, an authenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated victim accesses this link, the injected input is processed and reflected within the DOM on the client side during…
Pendiente de análisisMedia (5.5)0.69%—SAP Netweaver Application Server AbapAISAP Abap PlatformAI11/8/202626/8/2026
SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing security controls on an internal code path leading to operating system command execution. Successful exploitation could allow the attacker to execute OS-level commands that write to the operating system or…
Pendiente de análisisMedia (6.3)0.29%—SAP Netweaver Application Server JavaAIAdobe Document ServiceAI11/8/202626/8/2026
SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated open source cryptographic and data transfer libraries that contain known vulnerabilities addressed in later versions. A low-privileged authenticated attacker could potentially leverage these weaknesses against the affected component, though…
Pendiente de análisisCrítica (9.8)0.64%—SAP Netweaver Application Server AbapAI11/8/202626/8/2026
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive system information or crash the system, leading to a high impact on the confidentiality, integrity, and…
AplazadaAlta (7.1)0.39%—Spacebar ServerAI10/8/202617/9/2026
Spacebar Server before commit 8d126f4 contains a cross-channel message deletion vulnerability in the single-delete and bulk-delete message handlers that fail to scope message queries to the requested channel. Authenticated users with MANAGE_MESSAGES permission in any controlled channel can delete arbitrary messages in…
Pendiente de análisisCrítica (9.3)0.45%—Jaspersoft Jasperreports ServerAI10/8/202631/8/2026
Improper restriction of XML external entity reference vulnerability (unauthenticated) in Jaspersoft JasperReports Server. This issue affects JasperReports Server: from 9.0.0 before HF-9 and from 10.0.0 before HF-10.
AplazadaAlta (7.5)0.44%—Opensignlabs OpensignserverAI10/8/202626/8/2026
A missing authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to irreversibly decline any in-flight document and forge the decline attribution to an arbitrary user via the declinedoc Parse cloud function. The function writes IsDeclined, DeclineReason, and…
AplazadaAlta (7.5)0.65%—Opensignlabs OpensignserverAI10/8/202626/8/2026
An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to mint MASTER_KEY-signed file access tokens for arbitrary stored files via the getsignedurl Parse cloud function. The function skips its isAuthenticated check whenever any docId parameter is…
AplazadaAlta (7.5)0.53%—Opensignlabs OpensignserverAI10/8/202626/8/2026
A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read complete contract records via the getDocument Parse cloud function. The function fetches documents using useMasterKey, bypassing the object ACL, and returns full records…
AplazadaAlta (7.5)0.61%—Opensignlabs OpensignserverAI10/8/202626/8/2026
A missing authentication vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read arbitrary stored documents via the fileupload Parse cloud function. The function mints MASTER_KEY-signed file access tokens for any caller-supplied URL without performing any session…