Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2792▲ 39 respecto a la semana anterior
Críticas / altas1284▼ 238 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
16.783 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 1.4% | — | Microsoft KiotaAI | 16/7/2026 | 17/8/2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.4, Kiota's PHP generator embedded OpenAPI description, default fields, property names, and other schema-derived strings into PHP double-quoted literals through SanitizeDoubleQuote() in Writers/StringExtensions.cs without escaping $,… | |
| Pendiente de análisis | Alta (7.5) | 0.53% | — | Microsoft AvmlAI | 15/7/2026 | 15/7/2026 | Microsoft AVML before 0.17.0 could follow a symlink when opening a destination output path on Unix, allowing truncation/overwrite of the symlink target. The destructive effect is performed at open-time via O_TRUNC, and can happen before full input validation completes (“truncation-before-validation”). | |
| Analizada | Media (6.5) | 0.74% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/7/2026 | 24/7/2026 | Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/7/2026 | 22/7/2026 | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | |
| Analizada | Alta (7.8) | 0.46% | — | Microsoft .net FrameworkMicrosoft .net | 14/7/2026 | 24/7/2026 | Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 4.0% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2026 | 14/7/2026 | 24/7/2026 | Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/7/2026 | 24/7/2026 | Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network. | |
| Analizada | Alta (7.8) | 4.0% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/7/2026 | 24/7/2026 | Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (8.2) | 0.61% | — | Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/7/2026 | 22/7/2026 | Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/7/2026 | 24/7/2026 | Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network. | |
| Analizada | Media (5.5) | 0.22% | — | Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/7/2026 | 22/7/2026 | Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/7/2026 | 24/7/2026 | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/7/2026 | 22/7/2026 | Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/7/2026 | 16/7/2026 | Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally. | |
| Analizada | Crítica (9.8) | 0.29% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2017Microsoft Visual Studio 2019+2 | 14/7/2026 | 24/7/2026 | Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network. | |
| Analizada | Alta (8.8) | 0.84% | — | Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/7/2026 | 22/7/2026 | Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/7/2026 | 24/7/2026 | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | |
| Analizada | Alta (8.8) | 0.78% | 💥 PoC | Microsoft Configuration Manager 2503Microsoft Configuration Manager 2509Microsoft Configuration Manager 2603 | 14/7/2026 | 30/7/2026 | Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/7/2026 | 22/7/2026 | Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Media (5.5) | 0.24% | — | Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 23h2+8 | 14/7/2026 | 22/7/2026 | Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally. | |
| Analizada | Alta (7) | 0.26% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+8 | 14/7/2026 | 22/7/2026 | Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft Windows 11 26h1 | 14/7/2026 | 15/7/2026 | Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft Windows 11 26h1 | 14/7/2026 | 15/7/2026 | Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+7 | 14/7/2026 | 22/7/2026 | Un uso después de liberar (use-after-free) en Windows Win32K permite a un atacante autorizado elevar privilegios localmente. | |
| Analizada | Alta (7) | 0.26% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 14/7/2026 | 29/7/2026 | Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. |