Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3241▲ 698 respecto a la semana anterior
Críticas / altas1519▲ 132 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
9290 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.47% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 11/11/2025 | 17/6/2026 | Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to disclose information locally. | |
| Modificada | Alta (7.8) | 2.9% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 11/11/2025 | 17/6/2026 | Improper access control in Customer Experience Improvement Program (CEIP) allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.38% | — | Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 23h2+6 | 11/11/2025 | 17/6/2026 | External control of file name or path in Windows WLAN Service allows an authorized attacker to elevate privileges locally. | |
| Analizada | Media (5.5) | 0.50% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 11/11/2025 | 17/6/2026 | Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service locally. | |
| Analizada | Media (5.5) | 0.55% | — | Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 23h2+6 | 11/11/2025 | 17/6/2026 | Insertion of sensitive information into sent data in Windows Speech allows an authorized attacker to disclose information locally. | |
| Analizada | Alta (7) | 0.25% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+8 | 11/11/2025 | 17/6/2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7) | 0.25% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+8 | 11/11/2025 | 17/6/2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7) | 0.25% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 11/11/2025 | 17/6/2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.40% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 11/11/2025 | 17/6/2026 | Double free in Windows Smart Card allows an authorized attacker to elevate privileges locally. | |
| Aplazada | Media (5.4) | 0.12% | — | Display Virtualization FOR Windows OSAI | 11/11/2025 | 17/6/2026 | Uncontrolled search path for some Display Virtualization for Windows OS software before version 1797 within Ring 2: Device Drivers may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may… | |
| Aplazada | Alta (8.4) | 0.12% | — | Axis OptimizerAIMicrosoft WindowsAI | 11/11/2025 | 17/6/2026 | AXIS Optimizer was vulnerable to an unquoted search path vulnerability, which could potentially lead to privilege escalation within Microsoft Windows operating system. This vulnerability can only be exploited if the attacker has access to the local Windows machine and sufficient access rights (administrator) to write… | |
| Aplazada | Media (5.5) | 0.11% | — | SAP GUI FOR WindowsAI | 11/11/2025 | 17/6/2026 | SAP GUI for Windows may allow a highly privileged user on the affected client PC to locally access sensitive information stored in process memory during runtime.This vulnerability has a high impact on confidentiality, with no impact on integrity and availability. | |
| Modificada | Alta (7.8) | 0.18% | — | Veeam Agent FOR Windows | 30/10/2025 | 7/10/2026 | Esta vulnerabilidad en Veeam Agent para Microsoft Windows permite la escalada de privilegios local si un administrador de sistemas es engañado para restaurar un archivo malicioso. | |
| Aplazada | Crítica (9.8) | 0.46% | 💥 PoC | Microsoft Windows 10AI | 20/10/2025 | 17/6/2026 | Hatching Triage Sandbox Windows 10 build 2004 (2025-08-14) and Windows 10 LTSC 2021(2025-08-14) contains a vulnerability in its Windows behavioral analysis engine that allows a submitted malware sample to evade detection and cause denial-of-analysis. The vulnerability is triggered when a sample recursively spawns a… | |
| Analizada | Alta (7.5) | 1.1% | — | Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 22h2+6 | 14/10/2025 | 17/6/2026 | Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over a network. | |
| Analizada | Alta (8.8) | 1.9% | — | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+12 | 14/10/2025 | 17/6/2026 | Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network. | |
| Analizada | Media (4.6) | 0.63% | — | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+10 | 14/10/2025 | 17/6/2026 | Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unauthorized attacker to disclose information with a physical attack. | |
| Analizada | Alta (7.8) | 0.40% | — | Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 22h2Microsoft Windows 11 23h2+4 | 14/10/2025 | 17/6/2026 | Un uso después de liberar (use-after-free) en Windows Bluetooth Service permite a un atacante autorizado elevar privilegios localmente. | |
| Analizada | Alta (7) | 0.24% | — | Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 22h2Microsoft Windows 11 23h2+4 | 14/10/2025 | 17/6/2026 | Double free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Microsoft Windows Server 2012Microsoft Windows Server 2016Microsoft Windows Server 2019Microsoft Windows Server 2022+2 | 14/10/2025 | 17/6/2026 | Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network. | |
| Analizada | Media (5.5) | 1.0% | 💥 PoC | Microsoft Windows 11 22h2Microsoft Windows 11 23h2Microsoft Windows 11 24h2Microsoft Windows 11 25h2+1 | 14/10/2025 | 17/6/2026 | Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing locally. | |
| Modificada | Alta (7) | 0.61% | — | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+12 | 14/10/2025 | 17/6/2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally. | |
| Analizada | Baja (3.1) | 0.46% | — | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+11 | 14/10/2025 | 17/6/2026 | Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network. | |
| Analizada | Alta (7.8) | 0.27% | — | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+11 | 14/10/2025 | 17/6/2026 | Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.38% | — | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+11 | 14/10/2025 | 17/6/2026 | Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally. |