Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3241▲ 698 respecto a la semana anterior
Críticas / altas1519▲ 132 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
–

9290 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.47%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/11/202517/6/2026
Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to disclose information locally.
ModificadaAlta (7.8)2.9%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/11/202517/6/2026
Improper access control in Customer Experience Improvement Program (CEIP) allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.38%—Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 23h2+611/11/202517/6/2026
External control of file name or path in Windows WLAN Service allows an authorized attacker to elevate privileges locally.
AnalizadaMedia (5.5)0.50%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/11/202517/6/2026
Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service locally.
AnalizadaMedia (5.5)0.55%—Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 23h2+611/11/202517/6/2026
Insertion of sensitive information into sent data in Windows Speech allows an authorized attacker to disclose information locally.
AnalizadaAlta (7)0.25%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+811/11/202517/6/2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7)0.25%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+811/11/202517/6/2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7)0.25%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/11/202517/6/2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.40%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+911/11/202517/6/2026
Double free in Windows Smart Card allows an authorized attacker to elevate privileges locally.
AplazadaMedia (5.4)0.12%—Display Virtualization FOR Windows OSAI11/11/202517/6/2026
Uncontrolled search path for some Display Virtualization for Windows OS software before version 1797 within Ring 2: Device Drivers may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may…
AplazadaAlta (8.4)0.12%—Axis OptimizerAIMicrosoft WindowsAI11/11/202517/6/2026
AXIS Optimizer was vulnerable to an unquoted search path vulnerability, which could potentially lead to privilege escalation within Microsoft Windows operating system. This vulnerability can only be exploited if the attacker has access to the local Windows machine and sufficient access rights (administrator) to write…
AplazadaMedia (5.5)0.11%—SAP GUI FOR WindowsAI11/11/202517/6/2026
SAP GUI for Windows may allow a highly privileged user on the affected client PC to locally access sensitive information stored in process memory during runtime.This vulnerability has a high impact on confidentiality, with no impact on integrity and availability.
ModificadaAlta (7.8)0.18%—Veeam Agent FOR Windows30/10/20257/10/2026
Esta vulnerabilidad en Veeam Agent para Microsoft Windows permite la escalada de privilegios local si un administrador de sistemas es engañado para restaurar un archivo malicioso.
AplazadaCrítica (9.8)0.46%💥 PoCMicrosoft Windows 10AI20/10/202517/6/2026
Hatching Triage Sandbox Windows 10 build 2004 (2025-08-14) and Windows 10 LTSC 2021(2025-08-14) contains a vulnerability in its Windows behavioral analysis engine that allows a submitted malware sample to evade detection and cause denial-of-analysis. The vulnerability is triggered when a sample recursively spawns a…
AnalizadaAlta (7.5)1.1%—Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 22h2+614/10/202517/6/2026
Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over a network.
AnalizadaAlta (8.8)1.9%—Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+1214/10/202517/6/2026
Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network.
AnalizadaMedia (4.6)0.63%—Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+1014/10/202517/6/2026
Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unauthorized attacker to disclose information with a physical attack.
AnalizadaAlta (7.8)0.40%—Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 22h2Microsoft Windows 11 23h2+414/10/202517/6/2026
Un uso después de liberar (use-after-free) en Windows Bluetooth Service permite a un atacante autorizado elevar privilegios localmente.
AnalizadaAlta (7)0.24%—Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 22h2Microsoft Windows 11 23h2+414/10/202517/6/2026
Double free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitMicrosoft Windows Server 2012Microsoft Windows Server 2016Microsoft Windows Server 2019Microsoft Windows Server 2022+214/10/202517/6/2026
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
AnalizadaMedia (5.5)1.0%💥 PoCMicrosoft Windows 11 22h2Microsoft Windows 11 23h2Microsoft Windows 11 24h2Microsoft Windows 11 25h2+114/10/202517/6/2026
Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing locally.
ModificadaAlta (7)0.61%—Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+1214/10/202517/6/2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally.
AnalizadaBaja (3.1)0.46%—Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+1114/10/202517/6/2026
Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network.
AnalizadaAlta (7.8)0.27%—Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+1114/10/202517/6/2026
Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.38%—Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+1114/10/202517/6/2026
Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.