Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▲ 15 respecto a la semana anterior
Críticas / altas1274▼ 248 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
–

16.783 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.2)0.70%—Microsoft Azure API Management24/7/202617/8/2026
Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.
Pendiente de análisisAlta (7.8)0.82%—Microsoft Visual Studio CodeAIRedhat Ansible LightspeedAI22/7/202622/7/2026
A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) arises from improper handling of the ansible.executionEnvironment.containerOptions and ansible.executionEnvironment.volumeMounts settings, allowing an attacker to inject shell separators. This can be…
Pendiente de análisisAlta (7.8)0.75%—Ansible LightspeedAIMicrosoft Visual Studio CodeAI22/7/202623/7/2026
A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability (CWE-78) allows a remote attacker to execute unauthorized commands on a user's system. The issue occurs because the `ansible.python.activationScript` setting, intended for a virtual environment activation…
Pendiente de análisisAlta (7.8)0.95%—Microsoft Visual Studio CodeAIRedhat AnsibleAI22/7/202622/7/2026
A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This command injection vulnerability allows an attacker to craft a malicious playbook filename containing special characters. When a victim runs the playbook, these characters are not properly sanitized, leading to…
Pendiente de análisisBaja (3.3)0.13%—Ansible LightspeedAIMicrosoft Visual Studio CodeAIGoogle GeminiAI22/7/202622/7/2026
A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability allows an attacker with local access to the workstation, or malware running with the user's privileges, to read the Google Gemini API key. The extension insecurely stores the API key in plain text within the user's…
Pendiente de análisisCrítica (9.8)0.43%💥 PoCMicrosoft Azure API ManagementAI21/7/20265/10/2026
En Microsoft Azure API Management hasta el 17-10-2025, cuando el registro de autoservicio (autenticación básica de nombre de usuario/contraseña) está habilitado en el Inquilino A, un atacante puede reutilizar el flujo de registro cambiando el nombre de host o el identificador de inquilino al Inquilino B, incluso…
AnalizadaMedia (5.4)0.39%—Microsoft Edge Chromium17/7/202621/7/2026
Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.
AnalizadaAlta (7.5)0.66%—Microsoft Remote Desktop WEB ClientMicrosoft Windows Admin Center17/7/202622/7/2026
Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.
Pendiente de análisisMedia (5.1)0.17%—Microsoft WindowsAIMicrosoft Task SchedulerAIMicrosoft DcomAI17/7/202621/7/2026
A non-administrator interactive user can obtain full SYSTEM code execution through a DCOM/task scheduler logic chain — no network access, no memory corruption required (ITMS 8.7.3)
AplazadaMedia (6.5)0.16%—HCL Traveler FOR Microsoft OutlookAI17/7/202617/7/2026
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.
AnalizadaMedia (5.4)0.58%—Microsoft Sharepoint Server16/7/202622/7/2026
Una neutralización incorrecta de la entrada durante la generación de páginas web ('secuencias de comandos en sitios cruzados' o XSS) en Microsoft Office SharePoint permite a un atacante autorizado realizar suplantación (spoofing) a través de una red.
AnalizadaAlta (7.5)0.61%—Microsoft Terminal16/7/202630/7/2026
Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network.
AnalizadaMedia (6.1)0.41%—Microsoft Windows Admin Center16/7/202614/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (7)0.20%—Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 24h2Microsoft Windows 11 25h2+116/7/202622/7/2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.
AplazadaAlta (7.1)2.4%—Microsoft KiotaAI16/7/202617/8/2026
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota resolved OpenAPI $ref values by fetching remote http(s) URLs and reading local absolute or out-of-tree file paths, allowing `kiota generate` on an attacker-controlled or attacker-influenced description to perform build-time SSRF,…
AplazadaCrítica (9.3)1.4%—Microsoft KiotaAI16/7/202617/8/2026
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota emitted x-ms-kiota-info clientClassName and clientNamespaceName values without identifier or path sanitization as both generated client class or namespace names and generated output path components when `kiota generate` ran without…
AplazadaCrítica (9.3)4.4%—Microsoft KiotaAI16/7/202617/8/2026
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, `kiota info` read x-ms-kiota-info.languagesInformation.<language>.dependencyInstallCommand plus dependency name and version values from an OpenAPI description and presented the spec-supplied command as Kiota's recommended install…
AplazadaCrítica (9.3)1.3%—Microsoft KiotaAI16/7/202617/8/2026
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, `kiota plugin add` and `kiota plugin generate` (with `-t APIPlugin`) emitted attacker-controlled static_template.file values from x-ai-adaptive-card and x-ai-capabilities into generated Microsoft 365 Copilot and Teams plugin manifests…
AplazadaMedia (6.5)1.3%—Microsoft UFOAI16/7/202616/7/2026
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.7, the COMMAND_RESULTS handler in ufo/server/ws/handler.py called get_or_create_session in ufo/server/services/session_manager.py without owner_client_id, allowing an authenticated client to create an unowned…
Pendiente de análisisCrítica (9.3)0.88%—Moodle Microsoft 365 AND Microsoft Entra ID PluginsAIMoodle Local O365AI16/7/202616/7/2026
The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0.5, and 5.1.1, the Microsoft Office 365 Integration plugin local_o365 Teams SSO endpoint sso_login.php base64-decodes a JWT payload and authenticates users from the upn…
AplazadaMedia (4.3)0.98%—Microsoft UFOAI16/7/202616/7/2026
Microsoft UFO open-source framework for intelligent automation across devices and platforms. From 3.0.0 until 3.0.6, a client connected to the UFO WebSocket server as a DEVICE could call DEVICE_INFO_REQUEST with another device's target_id and receive that device's server-side system_info through…
AplazadaAlta (7)1.4%—Microsoft KiotaAI16/7/202617/8/2026
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota honored a poisoned .kiota/workspace.json workspace configuration without validating per-client or per-plugin outputPath values during kiota client generate and kiota plugin generate, allowing a malicious repository or pull request…
AplazadaAlta (7.5)1.4%—Microsoft KiotaAI16/7/202617/8/2026
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.0, Kiota's Python generator let attacker-controlled enum value descriptions from x-ms-enum.values[].description flow through KiotaBuilder.SetEnumOptions into Documentation.DescriptionTemplate and…
AplazadaAlta (7.5)2.0%—Microsoft KiotaAI16/7/202617/8/2026
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.0, Kiota's Ruby generator embedded OpenAPI default fields, property names, and other schema-derived strings through CodeMethodWriter.cs and SanitizeForQuotedLiteral() in Writers/StringExtensions.cs into Ruby double-quoted literals without…
AplazadaAlta (8.7)1.4%—Microsoft KiotaAI16/7/202617/8/2026
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.3, Kiota is affected by a code-generation injection vulnerability in the C# XML documentation-comment sink (the description, externalDocs label, and externalDocs link fields emitted as /// … comments). When text from an OpenAPI description…