Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2886▲ 262 respecto a la semana anterior
Críticas / altas1344▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
18.402 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 1.1% | — | Microsoft Edge Chromium | 4/8/2026 | 6/8/2026 | Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. | |
| Analizada | Media (6.2) | 0.40% | — | Microsoft Edge Chromium | 4/8/2026 | 6/8/2026 | Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. | |
| Analizada | Alta (7.1) | 0.36% | — | Microsoft Edge | 4/8/2026 | 17/9/2026 | External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. | |
| Analizada | Media (6.1) | 0.41% | — | Microsoft Edge Chromium | 4/8/2026 | 6/8/2026 | Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.4) | 0.92% | — | Microsoft Edge Chromium | 4/8/2026 | 7/8/2026 | External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft Office 2019Microsoft Office 2021+1 | 4/8/2026 | 9/8/2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. | |
| Aplazada | Alta (8.4) | 0.24% | — | OuroborosAI | 3/8/2026 | 10/9/2026 | Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. Versions prior to 0.42.1 have an incomplete denylist. Several execution-routing keys of the same RCE class were omitted, so a malicious cloned repo can still reach arbitrary… | |
| Aplazada | Alta (8.4) | 0.19% | — | OuroborosAI | 3/8/2026 | 10/9/2026 | Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. In versions prior to 0.39.0, if a user clones a malicious repository and runs Ouroboros commands within that directory, it can lead to arbitrary code execution and potential… | |
| Pendiente de análisis | Alta (8.6) | 2.4% | 💥 PoC | ClearosAI | 3/8/2026 | 24/9/2026 | ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attackers to execute arbitrary commands by submitting unsanitized input through the filter parameter, which is interpolated directly into a shell command in File.php. Attackers can inject command… | |
| Aplazada | Media (5.3) | 0.53% | — | Roskus Prospero Flow CRMAI | 31/7/2026 | 1/9/2026 | Cross-site Scripting in the lead index view in Roskus Prospero Flow CRM before 5.3.7 allows authenticated users holding the create or update lead permission to execute arbitrary JavaScript in the application origin via HTML markup stored in the lead name field, which the view renders through Blade's unescaped output… | |
| Analizada | Crítica (10) | 0.90% | — | Microsoft Azure Cosmos DB | 30/7/2026 | 4/8/2026 | Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. | |
| Aplazada | Media (6.9) | 0.38% | — | Mikrotik RouterosAI | 30/7/2026 | 8/9/2026 | An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Session Expiration vulnerability. This could allow active sessions to retain their previous permission set after inactivity timeouts or user‑group changes. As a result, an authenticated user whose… | |
| Aplazada | Alta (8.7) | 0.37% | — | Microsoft WindowsAIGladinet CentrestackAI | 30/7/2026 | 31/7/2026 | CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accounts by supplying a crafted base64-encoded XML string to exposed API endpoints. Attackers can send a malicious StorageConfigure parameter to… | |
| Aplazada | Alta (7.1) | 0.27% | — | LG Electronics SmartshareAIMicrosoft Windows 10AI | 30/7/2026 | 30/7/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in LG Electronics SmartShare allows SQL Injection. This issue affects SmartShare: through 2.3.1712.1202, which is supported on Microsoft Windows 10 and earlier versions. | |
| Aplazada | Alta (8.7) | 0.39% | — | Mikrotik RouterosAI | 28/7/2026 | 30/7/2026 | MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system does not enforce meaningful rate-limiting, account lockout, or source-based restrictions, allowing repeated authentication failures to proceed without defensive… | |
| Analizada | Media (5.4) | 0.41% | — | Microsoft Edge | 28/7/2026 | 5/8/2026 | Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform tampering over a network. | |
| Aplazada | Alta (7.5) | 0.36% | — | Microsoft ViridianAI | 28/7/2026 | 28/7/2026 | The logic to handle periodic Viridian STIMERs performs a division with an unchecked user-controlled divisor value, that can be set to zero to cause a #DE fault. | |
| Pendiente de análisis | Baja (3.3) | 0.12% | — | Gstreamer Gst-plugins-goodAIMatroskaAIWebmAI | 28/7/2026 | 28/7/2026 | A flaw was found in GStreamer's gst-plugins-good. A heap-based out-of-bounds read of 4 bytes can occur when parsing FLAC audio stream headers embedded in a Matroska or WebM container file. The vulnerability is triggered by a boundary check that does not account for the full size of the data being copied, allowing a… | |
| Aplazada | Alta (8.6) | 0.67% | — | Roskus Prospero Flow CRMAI | 27/7/2026 | 1/9/2026 | Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authenticated low-privileged user to execute arbitrary JavaScript in another user's browser, including administrators, leading to session compromise and account takeover, via a payload stored in an email… | |
| Aplazada | Alta (8.7) | 1.1% | — | Nitroshare DesktopAI | 27/7/2026 | 28/7/2026 | NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer server that allows unauthenticated attackers on the same network to write arbitrary files by sending a crafted filename containing directory traversal sequences in the JSON item header name field. Attackers can exploit… | |
| Analizada | Alta (7.4) | 0.92% | — | Microsoft Edge Chromium | 26/7/2026 | 3/8/2026 | Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (7.4) | 0.43% | — | Microsoft Edge Chromium | 26/7/2026 | 3/8/2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (5.4) | 0.21% | — | Microsoft Edge Chromium | 26/7/2026 | 3/8/2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.5) | 0.97% | — | Microsoft Azure Portal | 24/7/2026 | 29/7/2026 | Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network. | |
| Aplazada | Alta (8.4) | 0.51% | — | Pulumi CrossguardAI | 24/7/2026 | 28/7/2026 | Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers running drift detection in CI / cron could see transient adapter failures silently cached as "all clear" — masking real attacks for up to six hours — or see ordinary… |