Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2861▲ 226 respecto a la semana anterior
Críticas / altas1331▼ 99 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

25.772 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.49%—Nvidia Triton Inference ServerAI14/7/202615/7/2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory after effective lifetime. A successful exploit of this vulnerability might lead to denial of service.
AplazadaMedia (6.5)0.44%—Nvidia Triton Inference ServerAI14/7/202615/7/2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an authentication bypass through an alternative path or channel. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
AplazadaAlta (7.5)0.49%—Nvidia Triton Inference ServerAI14/7/202615/7/2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an uncaught exception. A successful exploit of this vulnerability might lead to denial of service.
AplazadaAlta (7.5)0.49%—Nvidia Triton Inference ServerAI14/7/202615/7/2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.
AplazadaAlta (7.5)0.53%—Nvidia Triton Inference ServerAI14/7/202615/7/2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause the use of an expired file descriptor. A successful exploit of this vulnerability might lead to denial of service.
AplazadaAlta (7.5)0.53%—Nvidia Triton Inference ServerAI14/7/202615/7/2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a stack-based buffer overflow. A successful exploit of this vulnerability might lead to denial of service.
AnalizadaAlta (7.5)0.54%—Nvidia Triton Inference Server14/7/20264/9/2026
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.
AnalizadaBaja (3.3)0.15%—Devolutions Server14/7/202615/7/2026
Insertion of sensitive information into a file in the Recovery Kit response file generation feature in Devolutions Server 2026.1.22.0, 2026.2.11.0 allows an attacker with access to the generated response file to obtain the Azure Key Vault client secret in cleartext, even when the option to exclude sensitive data is…
AnalizadaAlta (7.1)0.29%—Devolutions Server14/7/202630/7/2026
Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve their own pending access request via a direct call to the request status endpoint, bypassing the required approver review.
AnalizadaAlta (7.5)0.25%—Devolutions Server14/7/202630/7/2026
Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to disclose the private key of an SSH key or certificate PAM credential via a direct object reference to the credential identifier.
AnalizadaBaja (3.1)0.21%—Devolutions Server14/7/202630/7/2026
Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated user to delete another user's messages via a direct object reference to the message identifier.
AnalizadaMedia (5.5)0.24%—Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 23h2+814/7/202622/7/2026
Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.
AnalizadaAlta (7)0.26%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+814/7/202622/7/2026
Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.33%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+714/7/202622/7/2026
Un uso después de liberar (use-after-free) en Windows Win32K permite a un atacante autorizado elevar privilegios localmente.
AnalizadaAlta (7)0.26%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+914/7/202629/7/2026
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.20%—Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 24h2+514/7/202622/7/2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.5)1.2%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows Server 2012Microsoft Windows Server 2016+314/7/202617/7/2026
Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (8.8)0.91%—Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 24h2Microsoft Windows 11 25h2+314/7/202622/7/2026
Un uso después de liberar (use-after-free) en Windows Remote Desktop Services permite a un atacante autorizado ejecutar código a través de una red.
AnalizadaAlta (7)0.26%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+714/7/202622/7/2026
Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.38%—Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 24h2+514/7/202622/7/2026
Un uso después de liberar (use-after-free) en Windows Cloud Files Mini Filter Driver permite a un atacante autorizado elevar privilegios localmente.
AnalizadaCrítica (9.8)0.82%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+814/7/202622/7/2026
Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (7.8)0.41%—Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 24h2+514/7/202622/7/2026
Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.
AnalizadaMedia (6.5)0.92%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+814/7/202622/7/2026
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
AnalizadaMedia (5.5)0.35%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+814/7/202622/7/2026
Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally.
AnalizadaAlta (7)0.26%—Microsoft Windows 11 24h2Microsoft Windows 11 25h2Microsoft Windows 11 26h1Microsoft Windows Server 202514/7/202622/7/2026
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.