Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

16.783 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.4)0.83%—Microsoft Azure Kubernetes Service11/8/202612/8/2026
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
AnalizadaAlta (7)0.26%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/8/202616/8/2026
Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (8.8)0.86%💥 PoCMicrosoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/8/202616/8/2026
Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (7.2)1.0%—Microsoft Azure Monitor Agent11/8/202613/8/2026
Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (7.8)0.30%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+811/8/202616/8/2026
Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.
AnalizadaMedia (6.5)0.84%—Microsoft Dynamics 365 Business Central 2024Microsoft Dynamics 365 Business Central 2025Microsoft Dynamics 365 Business Central 202611/8/202613/8/2026
Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.
AnalizadaAlta (8.8)0.82%—Microsoft Visual Studio Code11/8/202625/9/2026
Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (7.8)0.46%—Microsoft Visual Studio Code11/8/202625/9/2026
Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
AnalizadaAlta (8.8)0.86%—Microsoft Visual Studio Code11/8/202625/9/2026
Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.2)0.54%—Microsoft Visual Studio Code11/8/202625/9/2026
No fallar de forma segura ('fallo abierto') en Visual Studio Code permite a un atacante no autorizado omitir una característica de seguridad a través de una red.
AnalizadaAlta (7.8)0.32%—Microsoft Visual Studio Code11/8/202625/9/2026
Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
ModificadaMedia (6.5)0.64%—Microsoft Github Copilot Chat11/8/202624/9/2026
No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network.
AnalizadaAlta (8.8)2.1%⚠ Explotación activa💥 PoCMicrosoft Sharepoint Server11/8/202626/9/2026
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
ModificadaMedia (6.8)0.44%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/8/202625/9/2026
Null pointer dereference in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to execute code locally.
AnalizadaAlta (8.8)0.76%—Microsoft Visual Studio Code11/8/202624/9/2026
Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (7.8)0.32%—Microsoft Visual Studio Code11/8/202625/9/2026
Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
AnalizadaMedia (6.5)0.92%—Microsoft Visual Studio Code11/8/202625/9/2026
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose information over a network.
Pendiente de análisisMedia (5.3)0.36%—Apache AirflowAIApache Airflow-providers-microsoft-azureAI10/8/202616/9/2026
The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with this backend, a caller in one team could resolve a secret belonging to…
AplazadaAlta (8.4)0.17%—Line FOR WindowsAIMicrosoft MsfteditAI10/8/202628/8/2026
A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is loaded via a relative path without a secure DLL search path, allowing a malicious DLL placed in the installer's directory to be loaded ahead of the legitimate System32 copy.
Pendiente de análisisMedia (5.4)0.18%—Ruby LSPAIMicrosoft Visual Studio CodeAI7/8/202618/9/2026
Ruby LSP is an implementation of the language server protocol for Ruby. Several workspace-level settings in the Ruby LSP VS Code extension prior to version 0.10.4 could override the path to the Ruby executable, the version manager executables, or the Bundler `Gemfile` used at startup. A malicious repository containing…
AnalizadaCrítica (9.6)0.86%—Microsoft Sharepoint Online7/8/20267/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
AnalizadaCrítica (9.1)0.93%—Microsoft Azure Confidential Ledger7/8/20267/8/2026
Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.78%—Microsoft Purview Ediscovery7/8/20267/8/2026
Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network.
AnalizadaCrítica (10)0.80%—Microsoft Teams7/8/202611/8/2026
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (10)0.80%—Microsoft Planetary Computer7/8/20267/8/2026
Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.