Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▲ 15 respecto a la semana anterior
Críticas / altas1274▼ 248 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
16.783 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 0.70% | — | Microsoft Azure API Management | 24/7/2026 | 17/8/2026 | Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network. | |
| Pendiente de análisis | Alta (7.8) | 0.82% | — | Microsoft Visual Studio CodeAIRedhat Ansible LightspeedAI | 22/7/2026 | 22/7/2026 | A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) arises from improper handling of the ansible.executionEnvironment.containerOptions and ansible.executionEnvironment.volumeMounts settings, allowing an attacker to inject shell separators. This can be… | |
| Pendiente de análisis | Alta (7.8) | 0.75% | — | Ansible LightspeedAIMicrosoft Visual Studio CodeAI | 22/7/2026 | 23/7/2026 | A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability (CWE-78) allows a remote attacker to execute unauthorized commands on a user's system. The issue occurs because the `ansible.python.activationScript` setting, intended for a virtual environment activation… | |
| Pendiente de análisis | Alta (7.8) | 0.95% | — | Microsoft Visual Studio CodeAIRedhat AnsibleAI | 22/7/2026 | 22/7/2026 | A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This command injection vulnerability allows an attacker to craft a malicious playbook filename containing special characters. When a victim runs the playbook, these characters are not properly sanitized, leading to… | |
| Pendiente de análisis | Baja (3.3) | 0.13% | — | Ansible LightspeedAIMicrosoft Visual Studio CodeAIGoogle GeminiAI | 22/7/2026 | 22/7/2026 | A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability allows an attacker with local access to the workstation, or malware running with the user's privileges, to read the Google Gemini API key. The extension insecurely stores the API key in plain text within the user's… | |
| Pendiente de análisis | Crítica (9.8) | 0.43% | 💥 PoC | Microsoft Azure API ManagementAI | 21/7/2026 | 5/10/2026 | En Microsoft Azure API Management hasta el 17-10-2025, cuando el registro de autoservicio (autenticación básica de nombre de usuario/contraseña) está habilitado en el Inquilino A, un atacante puede reutilizar el flujo de registro cambiando el nombre de host o el identificador de inquilino al Inquilino B, incluso… | |
| Analizada | Media (5.4) | 0.39% | — | Microsoft Edge Chromium | 17/7/2026 | 21/7/2026 | Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network. | |
| Analizada | Alta (7.5) | 0.66% | — | Microsoft Remote Desktop WEB ClientMicrosoft Windows Admin Center | 17/7/2026 | 22/7/2026 | Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network. | |
| Pendiente de análisis | Media (5.1) | 0.17% | — | Microsoft WindowsAIMicrosoft Task SchedulerAIMicrosoft DcomAI | 17/7/2026 | 21/7/2026 | A non-administrator interactive user can obtain full SYSTEM code execution through a DCOM/task scheduler logic chain — no network access, no memory corruption required (ITMS 8.7.3) | |
| Aplazada | Media (6.5) | 0.16% | — | HCL Traveler FOR Microsoft OutlookAI | 17/7/2026 | 17/7/2026 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content. | |
| Analizada | Media (5.4) | 0.58% | — | Microsoft Sharepoint Server | 16/7/2026 | 22/7/2026 | Una neutralización incorrecta de la entrada durante la generación de páginas web ('secuencias de comandos en sitios cruzados' o XSS) en Microsoft Office SharePoint permite a un atacante autorizado realizar suplantación (spoofing) a través de una red. | |
| Analizada | Alta (7.5) | 0.61% | — | Microsoft Terminal | 16/7/2026 | 30/7/2026 | Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network. | |
| Analizada | Media (6.1) | 0.41% | — | Microsoft Windows Admin Center | 16/7/2026 | 14/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7) | 0.20% | — | Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 24h2Microsoft Windows 11 25h2+1 | 16/7/2026 | 22/7/2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally. | |
| Aplazada | Alta (7.1) | 2.4% | — | Microsoft KiotaAI | 16/7/2026 | 17/8/2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota resolved OpenAPI $ref values by fetching remote http(s) URLs and reading local absolute or out-of-tree file paths, allowing `kiota generate` on an attacker-controlled or attacker-influenced description to perform build-time SSRF,… | |
| Aplazada | Crítica (9.3) | 1.4% | — | Microsoft KiotaAI | 16/7/2026 | 17/8/2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota emitted x-ms-kiota-info clientClassName and clientNamespaceName values without identifier or path sanitization as both generated client class or namespace names and generated output path components when `kiota generate` ran without… | |
| Aplazada | Crítica (9.3) | 4.4% | — | Microsoft KiotaAI | 16/7/2026 | 17/8/2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, `kiota info` read x-ms-kiota-info.languagesInformation.<language>.dependencyInstallCommand plus dependency name and version values from an OpenAPI description and presented the spec-supplied command as Kiota's recommended install… | |
| Aplazada | Crítica (9.3) | 1.3% | — | Microsoft KiotaAI | 16/7/2026 | 17/8/2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, `kiota plugin add` and `kiota plugin generate` (with `-t APIPlugin`) emitted attacker-controlled static_template.file values from x-ai-adaptive-card and x-ai-capabilities into generated Microsoft 365 Copilot and Teams plugin manifests… | |
| Aplazada | Media (6.5) | 1.3% | — | Microsoft UFOAI | 16/7/2026 | 16/7/2026 | Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.7, the COMMAND_RESULTS handler in ufo/server/ws/handler.py called get_or_create_session in ufo/server/services/session_manager.py without owner_client_id, allowing an authenticated client to create an unowned… | |
| Pendiente de análisis | Crítica (9.3) | 0.88% | — | Moodle Microsoft 365 AND Microsoft Entra ID PluginsAIMoodle Local O365AI | 16/7/2026 | 16/7/2026 | The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0.5, and 5.1.1, the Microsoft Office 365 Integration plugin local_o365 Teams SSO endpoint sso_login.php base64-decodes a JWT payload and authenticates users from the upn… | |
| Aplazada | Media (4.3) | 0.98% | — | Microsoft UFOAI | 16/7/2026 | 16/7/2026 | Microsoft UFO open-source framework for intelligent automation across devices and platforms. From 3.0.0 until 3.0.6, a client connected to the UFO WebSocket server as a DEVICE could call DEVICE_INFO_REQUEST with another device's target_id and receive that device's server-side system_info through… | |
| Aplazada | Alta (7) | 1.4% | — | Microsoft KiotaAI | 16/7/2026 | 17/8/2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota honored a poisoned .kiota/workspace.json workspace configuration without validating per-client or per-plugin outputPath values during kiota client generate and kiota plugin generate, allowing a malicious repository or pull request… | |
| Aplazada | Alta (7.5) | 1.4% | — | Microsoft KiotaAI | 16/7/2026 | 17/8/2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.0, Kiota's Python generator let attacker-controlled enum value descriptions from x-ms-enum.values[].description flow through KiotaBuilder.SetEnumOptions into Documentation.DescriptionTemplate and… | |
| Aplazada | Alta (7.5) | 2.0% | — | Microsoft KiotaAI | 16/7/2026 | 17/8/2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.0, Kiota's Ruby generator embedded OpenAPI default fields, property names, and other schema-derived strings through CodeMethodWriter.cs and SanitizeForQuotedLiteral() in Writers/StringExtensions.cs into Ruby double-quoted literals without… | |
| Aplazada | Alta (8.7) | 1.4% | — | Microsoft KiotaAI | 16/7/2026 | 17/8/2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.3, Kiota is affected by a code-generation injection vulnerability in the C# XML documentation-comment sink (the description, externalDocs label, and externalDocs link fields emitted as /// … comments). When text from an OpenAPI description… |