Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2871▲ 236 respecto a la semana anterior
Críticas / altas1338▼ 92 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
18.402 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.6) | 0.69% | — | Microsoft Teams | 7/8/2026 | 7/8/2026 | Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 0.61% | — | Microsoft Windows Admin Center | 7/8/2026 | 7/8/2026 | Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (10) | 0.65% | — | Microsoft Azure SQL Managed Instance | 7/8/2026 | 12/8/2026 | Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.9) | 0.78% | — | Microsoft Azure SRE Agent | 7/8/2026 | 7/8/2026 | La falta de autorización en Azure SRE Agent permite a un atacante autorizado elevar privilegios a través de una red. | |
| Modificada | Crítica (9.3) | 0.72% | — | Microsoft Power Apps | 7/8/2026 | 11/8/2026 | Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.9) | 1.0% | — | Microsoft Entra Provisioning Service | 7/8/2026 | 7/8/2026 | '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (10) | 0.90% | — | Microsoft Azure SQL Database | 7/8/2026 | 8/8/2026 | Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.6) | 0.69% | — | Microsoft Azure Logic Apps | 7/8/2026 | 7/8/2026 | Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. | |
| Analizada | Crítica (9.9) | 1.7% | — | Microsoft Azure Service BUS | 7/8/2026 | 7/8/2026 | Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. | |
| Analizada | Crítica (9.9) | 0.82% | — | Microsoft Azure Active Directory | 7/8/2026 | 7/8/2026 | Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 1.0% | — | Microsoft Application Insights Profiler | 7/8/2026 | 17/8/2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network. | |
| Pendiente de análisis | Alta (8.5) | 0.17% | — | National Instruments Ni-palAIMicrosoft WindowsAI | 5/8/2026 | 28/8/2026 | There is a local privilege escalation vulnerability recently discovered in the NI-PAL kernel driver. This may allow a local, authenticated user to escalate privileges and execute arbitrary code. This vulnerability affects NI-PAL 26.3.1 and prior versions running on Microsoft Windows. | |
| Aplazada | Alta (8.4) | 0.19% | — | Frostming PDMAI | 4/8/2026 | 8/9/2026 | PDM is a Python package and dependency manager. In versions up to and including 2.26.9, PDM automatically loads project-local plugins from a .pdm-plugins directory during initialization, allowing an attacker-controlled file in an untrusted repository checkout to execute arbitrary Python code before any command is… | |
| Aplazada | Alta (8.4) | 0.20% | — | Frostming PDMAI | 4/8/2026 | 8/9/2026 | pdm is a Python package and dependency manager supporting the latest PEP standards. Versions prior to 2.27.0 are vulnerable to path traversal through write_to_fs. InstallDestination.write_to_fs() in src/pdm/installers/installers.py overrides the base class to add symlink/hardlink support but replaces the safe… | |
| Aplazada | Media (6.8) | 0.20% | — | Frostming PDMAI | 4/8/2026 | 8/9/2026 | pdm is a Python package and dependency manager supporting the latest PEP standards. In versions prior to 2.27.0, pdm writes several project-local state or configuration files without symlink protection. If a malicious repository places those files as symlinks, local PDM operations can overwrite the symlink targets.… | |
| Analizada | Alta (8.8) | 0.77% | — | Microsoft Edge Chromium | 4/8/2026 | 6/8/2026 | Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | |
| Analizada | Media (6.1) | 0.39% | — | Microsoft Edge Chromium | 4/8/2026 | 6/8/2026 | Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.4) | 0.23% | — | Microsoft Edge Chromium | 4/8/2026 | 6/8/2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Crítica (9.6) | 1.1% | — | Microsoft Edge Chromium | 4/8/2026 | 6/8/2026 | El acceso a un recurso usando un tipo incompatible ('confusión de tipos') en Microsoft Edge (basado en Chromium) permite a un atacante no autorizado ejecutar código a través de una red. | |
| Analizada | Alta (8.1) | 0.36% | — | Microsoft Edge Chromium | 4/8/2026 | 6/8/2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (5.4) | 0.21% | — | Microsoft Edge Chromium | 4/8/2026 | 6/8/2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network. | |
| Analizada | Media (5.4) | 0.21% | — | Microsoft Edge Chromium | 4/8/2026 | 6/8/2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.5) | 0.61% | — | Microsoft Edge Chromium | 4/8/2026 | 6/8/2026 | Un uso después de liberar (use-after-free) en Microsoft Edge (basado en Chromium) permite a un atacante no autorizado ejecutar código a través de una red. | |
| Analizada | Media (5.3) | 0.57% | — | Microsoft Edge Chromium | 4/8/2026 | 6/8/2026 | Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (6.8) | 0.23% | — | Microsoft Edge Chromium | 4/8/2026 | 6/8/2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. |