Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
16.783 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.4) | 0.83% | — | Microsoft Azure Kubernetes Service | 11/8/2026 | 12/8/2026 | Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7) | 0.26% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 11/8/2026 | 16/8/2026 | Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (8.8) | 0.86% | 💥 PoC | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 11/8/2026 | 16/8/2026 | Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.2) | 1.0% | — | Microsoft Azure Monitor Agent | 11/8/2026 | 13/8/2026 | Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.8) | 0.30% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+8 | 11/8/2026 | 16/8/2026 | Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally. | |
| Analizada | Media (6.5) | 0.84% | — | Microsoft Dynamics 365 Business Central 2024Microsoft Dynamics 365 Business Central 2025Microsoft Dynamics 365 Business Central 2026 | 11/8/2026 | 13/8/2026 | Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft Visual Studio Code | 11/8/2026 | 25/9/2026 | Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.8) | 0.46% | — | Microsoft Visual Studio Code | 11/8/2026 | 25/9/2026 | Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally. | |
| Analizada | Alta (8.8) | 0.86% | — | Microsoft Visual Studio Code | 11/8/2026 | 25/9/2026 | Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.2) | 0.54% | — | Microsoft Visual Studio Code | 11/8/2026 | 25/9/2026 | No fallar de forma segura ('fallo abierto') en Visual Studio Code permite a un atacante no autorizado omitir una característica de seguridad a través de una red. | |
| Analizada | Alta (7.8) | 0.32% | — | Microsoft Visual Studio Code | 11/8/2026 | 25/9/2026 | Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | |
| Modificada | Media (6.5) | 0.64% | — | Microsoft Github Copilot Chat | 11/8/2026 | 24/9/2026 | No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network. | |
| Analizada | Alta (8.8) | 2.1% | ⚠ Explotación activa💥 PoC | Microsoft Sharepoint Server | 11/8/2026 | 26/9/2026 | Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Modificada | Media (6.8) | 0.44% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 11/8/2026 | 25/9/2026 | Null pointer dereference in Windows Universal Disk Format File System Driver (UDFS) allows an authorized attacker to execute code locally. | |
| Analizada | Alta (8.8) | 0.76% | — | Microsoft Visual Studio Code | 11/8/2026 | 24/9/2026 | Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.8) | 0.32% | — | Microsoft Visual Studio Code | 11/8/2026 | 25/9/2026 | Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | |
| Analizada | Media (6.5) | 0.92% | — | Microsoft Visual Studio Code | 11/8/2026 | 25/9/2026 | Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose information over a network. | |
| Pendiente de análisis | Media (5.3) | 0.36% | — | Apache AirflowAIApache Airflow-providers-microsoft-azureAI | 10/8/2026 | 16/9/2026 | The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with this backend, a caller in one team could resolve a secret belonging to… | |
| Aplazada | Alta (8.4) | 0.17% | — | Line FOR WindowsAIMicrosoft MsfteditAI | 10/8/2026 | 28/8/2026 | A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is loaded via a relative path without a secure DLL search path, allowing a malicious DLL placed in the installer's directory to be loaded ahead of the legitimate System32 copy. | |
| Pendiente de análisis | Media (5.4) | 0.18% | — | Ruby LSPAIMicrosoft Visual Studio CodeAI | 7/8/2026 | 18/9/2026 | Ruby LSP is an implementation of the language server protocol for Ruby. Several workspace-level settings in the Ruby LSP VS Code extension prior to version 0.10.4 could override the path to the Ruby executable, the version manager executables, or the Bundler `Gemfile` used at startup. A malicious repository containing… | |
| Analizada | Crítica (9.6) | 0.86% | — | Microsoft Sharepoint Online | 7/8/2026 | 7/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Crítica (9.1) | 0.93% | — | Microsoft Azure Confidential Ledger | 7/8/2026 | 7/8/2026 | Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Purview Ediscovery | 7/8/2026 | 7/8/2026 | Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (10) | 0.80% | — | Microsoft Teams | 7/8/2026 | 11/8/2026 | Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (10) | 0.80% | — | Microsoft Planetary Computer | 7/8/2026 | 7/8/2026 | Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network. |