Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2734▼ 7 respecto a la semana anterior
Críticas / altas1273▼ 240 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
–

16.783 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.1)0.36%—Microsoft Edge4/8/202617/9/2026
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
AnalizadaMedia (6.1)0.41%—Microsoft Edge Chromium4/8/20266/8/2026
Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (7.4)0.92%—Microsoft Edge Chromium4/8/20267/8/2026
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (8.8)0.82%—Microsoft 365 AppsMicrosoft ExcelMicrosoft Office 2019Microsoft Office 2021+14/8/20269/8/2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.
AnalizadaCrítica (10)0.90%—Microsoft Azure Cosmos DB30/7/20264/8/2026
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
AplazadaAlta (8.7)0.37%—Microsoft WindowsAIGladinet CentrestackAI30/7/202631/7/2026
CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accounts by supplying a crafted base64-encoded XML string to exposed API endpoints. Attackers can send a malicious StorageConfigure parameter to…
AplazadaAlta (7.1)0.27%—LG Electronics SmartshareAIMicrosoft Windows 10AI30/7/202630/7/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in LG Electronics SmartShare allows SQL Injection. This issue affects SmartShare: through 2.3.1712.1202, which is supported on Microsoft Windows 10 and earlier versions.
AnalizadaMedia (5.4)0.41%—Microsoft Edge28/7/20265/8/2026
Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform tampering over a network.
AplazadaAlta (7.5)0.36%—Microsoft ViridianAI28/7/202628/7/2026
The logic to handle periodic Viridian STIMERs performs a division with an unchecked user-controlled divisor value, that can be set to zero to cause a #DE fault.
AnalizadaAlta (7.4)0.92%—Microsoft Edge Chromium26/7/20263/8/2026
Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (7.4)0.43%—Microsoft Edge Chromium26/7/20263/8/2026
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
AnalizadaMedia (5.4)0.21%—Microsoft Edge Chromium26/7/20263/8/2026
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (7.5)0.97%—Microsoft Azure Portal24/7/202629/7/2026
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
AnalizadaCrítica (9.8)0.86%—Microsoft Azure APP Service FOR Linux24/7/20266/8/2026
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (10)0.90%—Microsoft Purview Data Governance24/7/202629/7/2026
Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (10)0.90%—Microsoft Azure Kubernetes Service24/7/202629/7/2026
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.8)0.92%—Microsoft Azure KEY Vault24/7/20267/8/2026
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.8)0.92%—Microsoft Azure DNS24/7/20267/8/2026
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (10)0.90%—Microsoft Exchange Online24/7/202629/7/2026
Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.
AnalizadaAlta (8.8)0.55%—Microsoft Azure AI Search24/7/202629/7/2026
Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.8)0.97%—Microsoft Account24/7/202630/7/2026
Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
AnalizadaCrítica (9.9)0.79%—Microsoft Azure RED HAT Openshift24/7/20267/8/2026
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (8.8)0.96%—Microsoft Surface Management Services24/7/20266/8/2026
Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
AnalizadaCrítica (9.9)1.7%—Microsoft 365 Copilot24/7/202629/7/2026
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
AnalizadaMedia (6.5)1.00%—Microsoft Graph24/7/202629/7/2026
Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.