Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3000▲ 369 respecto a la semana anterior
Críticas / altas1450▲ 18 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

18.402 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.1)0.41%—Microsoft Windows Admin Center16/7/202614/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (7)0.20%—Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 24h2Microsoft Windows 11 25h2+116/7/202622/7/2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.
AplazadaBaja (3.5)0.30%—Kerlink Wirnet Istation 868AIKerlink KerosAI16/7/202617/7/2026
Buffer Overflow vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the update URLs component.
AplazadaAlta (7.3)0.85%—Kerlink Wirnet Istation 868AIKerlink KerosAI16/7/202617/7/2026
Directory traversal vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the SNMP update mechanism.
AplazadaAlta (7.1)2.4%—Microsoft KiotaAI16/7/202617/8/2026
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota resolved OpenAPI $ref values by fetching remote http(s) URLs and reading local absolute or out-of-tree file paths, allowing `kiota generate` on an attacker-controlled or attacker-influenced description to perform build-time SSRF,…
AplazadaCrítica (9.3)1.4%—Microsoft KiotaAI16/7/202617/8/2026
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota emitted x-ms-kiota-info clientClassName and clientNamespaceName values without identifier or path sanitization as both generated client class or namespace names and generated output path components when `kiota generate` ran without…
AplazadaCrítica (9.3)4.4%—Microsoft KiotaAI16/7/202617/8/2026
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, `kiota info` read x-ms-kiota-info.languagesInformation.<language>.dependencyInstallCommand plus dependency name and version values from an OpenAPI description and presented the spec-supplied command as Kiota's recommended install…
AplazadaCrítica (9.3)1.3%—Microsoft KiotaAI16/7/202617/8/2026
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, `kiota plugin add` and `kiota plugin generate` (with `-t APIPlugin`) emitted attacker-controlled static_template.file values from x-ai-adaptive-card and x-ai-capabilities into generated Microsoft 365 Copilot and Teams plugin manifests…
AplazadaMedia (6.5)1.3%—Microsoft UFOAI16/7/202616/7/2026
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.7, the COMMAND_RESULTS handler in ufo/server/ws/handler.py called get_or_create_session in ufo/server/services/session_manager.py without owner_client_id, allowing an authenticated client to create an unowned…
Pendiente de análisisCrítica (9.3)0.88%—Moodle Microsoft 365 AND Microsoft Entra ID PluginsAIMoodle Local O365AI16/7/202616/7/2026
The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0.5, and 5.1.1, the Microsoft Office 365 Integration plugin local_o365 Teams SSO endpoint sso_login.php base64-decodes a JWT payload and authenticates users from the upn…
AplazadaMedia (4.3)0.98%—Microsoft UFOAI16/7/202616/7/2026
Microsoft UFO open-source framework for intelligent automation across devices and platforms. From 3.0.0 until 3.0.6, a client connected to the UFO WebSocket server as a DEVICE could call DEVICE_INFO_REQUEST with another device's target_id and receive that device's server-side system_info through…
AplazadaAlta (7)1.4%—Microsoft KiotaAI16/7/202617/8/2026
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota honored a poisoned .kiota/workspace.json workspace configuration without validating per-client or per-plugin outputPath values during kiota client generate and kiota plugin generate, allowing a malicious repository or pull request…
AplazadaAlta (7.5)1.4%—Microsoft KiotaAI16/7/202617/8/2026
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.0, Kiota's Python generator let attacker-controlled enum value descriptions from x-ms-enum.values[].description flow through KiotaBuilder.SetEnumOptions into Documentation.DescriptionTemplate and…
AplazadaAlta (7.5)2.0%—Microsoft KiotaAI16/7/202617/8/2026
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.0, Kiota's Ruby generator embedded OpenAPI default fields, property names, and other schema-derived strings through CodeMethodWriter.cs and SanitizeForQuotedLiteral() in Writers/StringExtensions.cs into Ruby double-quoted literals without…
AplazadaAlta (8.7)1.4%—Microsoft KiotaAI16/7/202617/8/2026
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.3, Kiota is affected by a code-generation injection vulnerability in the C# XML documentation-comment sink (the description, externalDocs label, and externalDocs link fields emitted as /// … comments). When text from an OpenAPI description…
AplazadaAlta (8.7)1.4%—Microsoft KiotaAI16/7/202617/8/2026
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.4, Kiota's PHP generator embedded OpenAPI description, default fields, property names, and other schema-derived strings into PHP double-quoted literals through SanitizeDoubleQuote() in Writers/StringExtensions.cs without escaping $,…
AplazadaMedia (6.9)0.64%—Roskus Prospero Flow CRMAI16/7/202616/7/2026
Authorization Bypass Through User-Controlled Key (CWE-639) in the Order and OrderItem REST API controllers in Roskus Prospero Flow CRM before 5.5.3 allows a remote, authenticated user to read, modify, and delete orders and order items belonging to any other company (tenant) via a sequential numeric {id} supplied to…
Pendiente de análisisAlta (7.5)0.53%—Microsoft AvmlAI15/7/202615/7/2026
Microsoft AVML before 0.17.0 could follow a symlink when opening a destination output path on Unix, allowing truncation/overwrite of the symlink target. The destructive effect is performed at open-time via O_TRUNC, and can happen before full input validation completes (“truncation-before-validation”).
AplazadaMedia (6.9)0.64%—Roskus Prospero Flow CRMAI15/7/202615/7/2026
Authorization Bypass Through User-Controlled Key (CWE-639) in the Excel import handlers (CustomerImport, LeadImport, ProductImport) in Roskus Prospero Flow CRM before 5.14.0 allows a remote, authenticated user of any role or company to create customer, lead, and product records inside another company's tenant via a…
AplazadaAlta (8.7)0.66%—Prospero Flow CRMAI15/7/202615/7/2026
Missing Authorization (CWE-862) in BankAccountListController (app/Http/Controllers/Api/BankAccount/BankAccountListController.php), exposed at GET /api/bank-account, in Prospero Flow CRM <5.5.3, which allows a remote, authenticated attacker holding a low-privileged role (e.g. the "User"/"Usuario" role) to read…
AnalizadaMedia (6.5)0.74%—Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 202614/7/202624/7/2026
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (7.5)1.2%—Microsoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 202614/7/202622/7/2026
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (7.8)0.46%—Microsoft .net FrameworkMicrosoft .net14/7/202624/7/2026
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)4.0%—Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 202614/7/202624/7/2026
Deserialization of untrusted data in .NET allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.5)1.2%—Microsoft .net FrameworkMicrosoft .netMicrosoft Visual Studio 2022Microsoft Visual Studio 202614/7/202624/7/2026
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.