Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3000▲ 369 respecto a la semana anterior
Críticas / altas1450▲ 18 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
18.402 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.41% | — | Microsoft Windows Admin Center | 16/7/2026 | 14/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7) | 0.20% | — | Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 24h2Microsoft Windows 11 25h2+1 | 16/7/2026 | 22/7/2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally. | |
| Aplazada | Baja (3.5) | 0.30% | — | Kerlink Wirnet Istation 868AIKerlink KerosAI | 16/7/2026 | 17/7/2026 | Buffer Overflow vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the update URLs component. | |
| Aplazada | Alta (7.3) | 0.85% | — | Kerlink Wirnet Istation 868AIKerlink KerosAI | 16/7/2026 | 17/7/2026 | Directory traversal vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the SNMP update mechanism. | |
| Aplazada | Alta (7.1) | 2.4% | — | Microsoft KiotaAI | 16/7/2026 | 17/8/2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota resolved OpenAPI $ref values by fetching remote http(s) URLs and reading local absolute or out-of-tree file paths, allowing `kiota generate` on an attacker-controlled or attacker-influenced description to perform build-time SSRF,… | |
| Aplazada | Crítica (9.3) | 1.4% | — | Microsoft KiotaAI | 16/7/2026 | 17/8/2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota emitted x-ms-kiota-info clientClassName and clientNamespaceName values without identifier or path sanitization as both generated client class or namespace names and generated output path components when `kiota generate` ran without… | |
| Aplazada | Crítica (9.3) | 4.4% | — | Microsoft KiotaAI | 16/7/2026 | 17/8/2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, `kiota info` read x-ms-kiota-info.languagesInformation.<language>.dependencyInstallCommand plus dependency name and version values from an OpenAPI description and presented the spec-supplied command as Kiota's recommended install… | |
| Aplazada | Crítica (9.3) | 1.3% | — | Microsoft KiotaAI | 16/7/2026 | 17/8/2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, `kiota plugin add` and `kiota plugin generate` (with `-t APIPlugin`) emitted attacker-controlled static_template.file values from x-ai-adaptive-card and x-ai-capabilities into generated Microsoft 365 Copilot and Teams plugin manifests… | |
| Aplazada | Media (6.5) | 1.3% | — | Microsoft UFOAI | 16/7/2026 | 16/7/2026 | Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.7, the COMMAND_RESULTS handler in ufo/server/ws/handler.py called get_or_create_session in ufo/server/services/session_manager.py without owner_client_id, allowing an authenticated client to create an unowned… | |
| Pendiente de análisis | Crítica (9.3) | 0.88% | — | Moodle Microsoft 365 AND Microsoft Entra ID PluginsAIMoodle Local O365AI | 16/7/2026 | 16/7/2026 | The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0.5, and 5.1.1, the Microsoft Office 365 Integration plugin local_o365 Teams SSO endpoint sso_login.php base64-decodes a JWT payload and authenticates users from the upn… | |
| Aplazada | Media (4.3) | 0.98% | — | Microsoft UFOAI | 16/7/2026 | 16/7/2026 | Microsoft UFO open-source framework for intelligent automation across devices and platforms. From 3.0.0 until 3.0.6, a client connected to the UFO WebSocket server as a DEVICE could call DEVICE_INFO_REQUEST with another device's target_id and receive that device's server-side system_info through… | |
| Aplazada | Alta (7) | 1.4% | — | Microsoft KiotaAI | 16/7/2026 | 17/8/2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota honored a poisoned .kiota/workspace.json workspace configuration without validating per-client or per-plugin outputPath values during kiota client generate and kiota plugin generate, allowing a malicious repository or pull request… | |
| Aplazada | Alta (7.5) | 1.4% | — | Microsoft KiotaAI | 16/7/2026 | 17/8/2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.0, Kiota's Python generator let attacker-controlled enum value descriptions from x-ms-enum.values[].description flow through KiotaBuilder.SetEnumOptions into Documentation.DescriptionTemplate and… | |
| Aplazada | Alta (7.5) | 2.0% | — | Microsoft KiotaAI | 16/7/2026 | 17/8/2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.0, Kiota's Ruby generator embedded OpenAPI default fields, property names, and other schema-derived strings through CodeMethodWriter.cs and SanitizeForQuotedLiteral() in Writers/StringExtensions.cs into Ruby double-quoted literals without… | |
| Aplazada | Alta (8.7) | 1.4% | — | Microsoft KiotaAI | 16/7/2026 | 17/8/2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.3, Kiota is affected by a code-generation injection vulnerability in the C# XML documentation-comment sink (the description, externalDocs label, and externalDocs link fields emitted as /// … comments). When text from an OpenAPI description… | |
| Aplazada | Alta (8.7) | 1.4% | — | Microsoft KiotaAI | 16/7/2026 | 17/8/2026 | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.4, Kiota's PHP generator embedded OpenAPI description, default fields, property names, and other schema-derived strings into PHP double-quoted literals through SanitizeDoubleQuote() in Writers/StringExtensions.cs without escaping $,… | |
| Aplazada | Media (6.9) | 0.64% | — | Roskus Prospero Flow CRMAI | 16/7/2026 | 16/7/2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in the Order and OrderItem REST API controllers in Roskus Prospero Flow CRM before 5.5.3 allows a remote, authenticated user to read, modify, and delete orders and order items belonging to any other company (tenant) via a sequential numeric {id} supplied to… | |
| Pendiente de análisis | Alta (7.5) | 0.53% | — | Microsoft AvmlAI | 15/7/2026 | 15/7/2026 | Microsoft AVML before 0.17.0 could follow a symlink when opening a destination output path on Unix, allowing truncation/overwrite of the symlink target. The destructive effect is performed at open-time via O_TRUNC, and can happen before full input validation completes (“truncation-before-validation”). | |
| Aplazada | Media (6.9) | 0.64% | — | Roskus Prospero Flow CRMAI | 15/7/2026 | 15/7/2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in the Excel import handlers (CustomerImport, LeadImport, ProductImport) in Roskus Prospero Flow CRM before 5.14.0 allows a remote, authenticated user of any role or company to create customer, lead, and product records inside another company's tenant via a… | |
| Aplazada | Alta (8.7) | 0.66% | — | Prospero Flow CRMAI | 15/7/2026 | 15/7/2026 | Missing Authorization (CWE-862) in BankAccountListController (app/Http/Controllers/Api/BankAccount/BankAccountListController.php), exposed at GET /api/bank-account, in Prospero Flow CRM <5.5.3, which allows a remote, authenticated attacker holding a low-privileged role (e.g. the "User"/"Usuario" role) to read… | |
| Analizada | Media (6.5) | 0.74% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/7/2026 | 24/7/2026 | Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/7/2026 | 22/7/2026 | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | |
| Analizada | Alta (7.8) | 0.46% | — | Microsoft .net FrameworkMicrosoft .net | 14/7/2026 | 24/7/2026 | Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 4.0% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2026 | 14/7/2026 | 24/7/2026 | Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 14/7/2026 | 24/7/2026 | Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network. |