Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2886▲ 262 respecto a la semana anterior
Críticas / altas1344▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

18.402 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)1.1%—Microsoft Edge Chromium4/8/20266/8/2026
Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
AnalizadaMedia (6.2)0.40%—Microsoft Edge Chromium4/8/20266/8/2026
Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.
AnalizadaAlta (7.1)0.36%—Microsoft Edge4/8/202617/9/2026
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
AnalizadaMedia (6.1)0.41%—Microsoft Edge Chromium4/8/20266/8/2026
Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (7.4)0.92%—Microsoft Edge Chromium4/8/20267/8/2026
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (8.8)0.82%—Microsoft 365 AppsMicrosoft ExcelMicrosoft Office 2019Microsoft Office 2021+14/8/20269/8/2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.
AplazadaAlta (8.4)0.24%—OuroborosAI3/8/202610/9/2026
Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. Versions prior to 0.42.1 have an incomplete denylist. Several execution-routing keys of the same RCE class were omitted, so a malicious cloned repo can still reach arbitrary…
AplazadaAlta (8.4)0.19%—OuroborosAI3/8/202610/9/2026
Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. In versions prior to 0.39.0, if a user clones a malicious repository and runs Ouroboros commands within that directory, it can lead to arbitrary code execution and potential…
Pendiente de análisisAlta (8.6)2.4%💥 PoCClearosAI3/8/202624/9/2026
ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attackers to execute arbitrary commands by submitting unsanitized input through the filter parameter, which is interpolated directly into a shell command in File.php. Attackers can inject command…
AplazadaMedia (5.3)0.53%—Roskus Prospero Flow CRMAI31/7/20261/9/2026
Cross-site Scripting in the lead index view in Roskus Prospero Flow CRM before 5.3.7 allows authenticated users holding the create or update lead permission to execute arbitrary JavaScript in the application origin via HTML markup stored in the lead name field, which the view renders through Blade's unescaped output…
AnalizadaCrítica (10)0.90%—Microsoft Azure Cosmos DB30/7/20264/8/2026
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
AplazadaMedia (6.9)0.38%—Mikrotik RouterosAI30/7/20268/9/2026
An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Session Expiration vulnerability. This could allow active sessions to retain their previous permission set after inactivity timeouts or user‑group changes. As a result, an authenticated user whose…
AplazadaAlta (8.7)0.37%—Microsoft WindowsAIGladinet CentrestackAI30/7/202631/7/2026
CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accounts by supplying a crafted base64-encoded XML string to exposed API endpoints. Attackers can send a malicious StorageConfigure parameter to…
AplazadaAlta (7.1)0.27%—LG Electronics SmartshareAIMicrosoft Windows 10AI30/7/202630/7/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in LG Electronics SmartShare allows SQL Injection. This issue affects SmartShare: through 2.3.1712.1202, which is supported on Microsoft Windows 10 and earlier versions.
AplazadaAlta (8.7)0.39%—Mikrotik RouterosAI28/7/202630/7/2026
MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system does not enforce meaningful rate-limiting, account lockout, or source-based restrictions, allowing repeated authentication failures to proceed without defensive…
AnalizadaMedia (5.4)0.41%—Microsoft Edge28/7/20265/8/2026
Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform tampering over a network.
AplazadaAlta (7.5)0.36%—Microsoft ViridianAI28/7/202628/7/2026
The logic to handle periodic Viridian STIMERs performs a division with an unchecked user-controlled divisor value, that can be set to zero to cause a #DE fault.
Pendiente de análisisBaja (3.3)0.12%—Gstreamer Gst-plugins-goodAIMatroskaAIWebmAI28/7/202628/7/2026
A flaw was found in GStreamer's gst-plugins-good. A heap-based out-of-bounds read of 4 bytes can occur when parsing FLAC audio stream headers embedded in a Matroska or WebM container file. The vulnerability is triggered by a boundary check that does not account for the full size of the data being copied, allowing a…
AplazadaAlta (8.6)0.67%—Roskus Prospero Flow CRMAI27/7/20261/9/2026
Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authenticated low-privileged user to execute arbitrary JavaScript in another user's browser, including administrators, leading to session compromise and account takeover, via a payload stored in an email…
AplazadaAlta (8.7)1.1%—Nitroshare DesktopAI27/7/202628/7/2026
NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer server that allows unauthenticated attackers on the same network to write arbitrary files by sending a crafted filename containing directory traversal sequences in the JSON item header name field. Attackers can exploit…
AnalizadaAlta (7.4)0.92%—Microsoft Edge Chromium26/7/20263/8/2026
Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (7.4)0.43%—Microsoft Edge Chromium26/7/20263/8/2026
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
AnalizadaMedia (5.4)0.21%—Microsoft Edge Chromium26/7/20263/8/2026
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (7.5)0.97%—Microsoft Azure Portal24/7/202629/7/2026
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
AplazadaAlta (8.4)0.51%—Pulumi CrossguardAI24/7/202628/7/2026
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers running drift detection in CI / cron could see transient adapter failures silently cached as "all clear" — masking real attacks for up to six hours — or see ordinary…