Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2861▲ 226 respecto a la semana anterior
Críticas / altas1331▼ 99 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
25.772 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.49% | — | Nvidia Triton Inference ServerAI | 14/7/2026 | 15/7/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory after effective lifetime. A successful exploit of this vulnerability might lead to denial of service. | |
| Aplazada | Media (6.5) | 0.44% | — | Nvidia Triton Inference ServerAI | 14/7/2026 | 15/7/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an authentication bypass through an alternative path or channel. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering. | |
| Aplazada | Alta (7.5) | 0.49% | — | Nvidia Triton Inference ServerAI | 14/7/2026 | 15/7/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an uncaught exception. A successful exploit of this vulnerability might lead to denial of service. | |
| Aplazada | Alta (7.5) | 0.49% | — | Nvidia Triton Inference ServerAI | 14/7/2026 | 15/7/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service. | |
| Aplazada | Alta (7.5) | 0.53% | — | Nvidia Triton Inference ServerAI | 14/7/2026 | 15/7/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause the use of an expired file descriptor. A successful exploit of this vulnerability might lead to denial of service. | |
| Aplazada | Alta (7.5) | 0.53% | — | Nvidia Triton Inference ServerAI | 14/7/2026 | 15/7/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a stack-based buffer overflow. A successful exploit of this vulnerability might lead to denial of service. | |
| Analizada | Alta (7.5) | 0.54% | — | Nvidia Triton Inference Server | 14/7/2026 | 4/9/2026 | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service. | |
| Analizada | Baja (3.3) | 0.15% | — | Devolutions Server | 14/7/2026 | 15/7/2026 | Insertion of sensitive information into a file in the Recovery Kit response file generation feature in Devolutions Server 2026.1.22.0, 2026.2.11.0 allows an attacker with access to the generated response file to obtain the Azure Key Vault client secret in cleartext, even when the option to exclude sensitive data is… | |
| Analizada | Alta (7.1) | 0.29% | — | Devolutions Server | 14/7/2026 | 30/7/2026 | Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve their own pending access request via a direct call to the request status endpoint, bypassing the required approver review. | |
| Analizada | Alta (7.5) | 0.25% | — | Devolutions Server | 14/7/2026 | 30/7/2026 | Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to disclose the private key of an SSH key or certificate PAM credential via a direct object reference to the credential identifier. | |
| Analizada | Baja (3.1) | 0.21% | — | Devolutions Server | 14/7/2026 | 30/7/2026 | Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated user to delete another user's messages via a direct object reference to the message identifier. | |
| Analizada | Media (5.5) | 0.24% | — | Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 23h2+8 | 14/7/2026 | 22/7/2026 | Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally. | |
| Analizada | Alta (7) | 0.26% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+8 | 14/7/2026 | 22/7/2026 | Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+7 | 14/7/2026 | 22/7/2026 | Un uso después de liberar (use-after-free) en Windows Win32K permite a un atacante autorizado elevar privilegios localmente. | |
| Analizada | Alta (7) | 0.26% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 14/7/2026 | 29/7/2026 | Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.20% | — | Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 24h2+5 | 14/7/2026 | 22/7/2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows Server 2012Microsoft Windows Server 2016+3 | 14/7/2026 | 17/7/2026 | Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | |
| Analizada | Alta (8.8) | 0.91% | — | Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 24h2Microsoft Windows 11 25h2+3 | 14/7/2026 | 22/7/2026 | Un uso después de liberar (use-after-free) en Windows Remote Desktop Services permite a un atacante autorizado ejecutar código a través de una red. | |
| Analizada | Alta (7) | 0.26% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+7 | 14/7/2026 | 22/7/2026 | Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.38% | — | Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 24h2+5 | 14/7/2026 | 22/7/2026 | Un uso después de liberar (use-after-free) en Windows Cloud Files Mini Filter Driver permite a un atacante autorizado elevar privilegios localmente. | |
| Analizada | Crítica (9.8) | 0.82% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+8 | 14/7/2026 | 22/7/2026 | Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.8) | 0.41% | — | Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 24h2+5 | 14/7/2026 | 22/7/2026 | Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally. | |
| Analizada | Media (6.5) | 0.92% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+8 | 14/7/2026 | 22/7/2026 | Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (5.5) | 0.35% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+8 | 14/7/2026 | 22/7/2026 | Improper access control in Windows Kernel allows an authorized attacker to bypass a security feature locally. | |
| Analizada | Alta (7) | 0.26% | — | Microsoft Windows 11 24h2Microsoft Windows 11 25h2Microsoft Windows 11 26h1Microsoft Windows Server 2025 | 14/7/2026 | 22/7/2026 | Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally. |