Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3232▲ 666 respecto a la semana anterior
Críticas / altas1516▲ 123 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
16.783 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Azure Openai | 2/7/2026 | 7/7/2026 | Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.3) | 0.72% | — | Microsoft 365 Copilot | 2/7/2026 | 7/7/2026 | Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 0.70% | — | Microsoft Azure Synapse | 2/7/2026 | 7/7/2026 | Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.3) | 0.82% | — | Microsoft Edge Chromium | 1/7/2026 | 3/7/2026 | Un uso después de liberar (use-after-free) en Microsoft Edge (Chromium-based) permite a un atacante autorizado ejecutar código a través de una red. | |
| Pendiente de análisis | Alta (7.5) | 1.2% | — | Microsoft Openapi.netAI | 30/6/2026 | 2/7/2026 | The OpenAPI.NET SDK contains a useful object model for OpenAPI documents in .NET along with common serializers to extract raw OpenAPI JSON and YAML documents from the model. From 2.0.0-preview11 until 2.7.5 and 3.5.4, a small OpenAPI document containing a circular schema reference can cause process termination through… | |
| Analizada | Alta (7.8) | 0.27% | — | Hcltech Traveler FOR Microsoft Outlook | 27/6/2026 | 6/7/2026 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of service. Since .NET Framework 4.5 has reached end-of-life and no longer receives security updates, it may expose the application to publicly known security weaknesses through vulnerable third-party… | |
| Analizada | Media (5.5) | 0.15% | — | Hcltech Traveler FOR Microsoft Outlook | 27/6/2026 | 29/9/2026 | HCL Traveler para Microsoft Outlook (HTMO) es susceptible a una vulnerabilidad de exposición de datos sensibles que podría permitir a un atacante explotar información de la aplicación para luego intentar ataques adicionales y causar un comportamiento desconocido en la aplicación. | |
| Aplazada | Alta (8.2) | 0.20% | — | OpenprojectAIMicrosoft OnedriveAIMicrosoft SharepointAIMicrosoft Azure ADAI | 26/6/2026 | 29/6/2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, OpenProject's Storages module writes the OneDrive/SharePoint userless OAuth access_token plaintext to Rails.cache under the deterministic key storage.<id>.httpx_access_token, repopulated continuously by an hourly cron and… | |
| Analizada | Alta (7.8) | 0.09% | — | Hcltech Traveler FOR Microsoft Outlook | 26/6/2026 | 1/10/2026 | Las bibliotecas de HCL Traveler para Microsoft Outlook están siendo marcadas como software potencialmente malicioso o una aplicación no reconocida. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft Github Copilot | 22/6/2026 | 5/10/2026 | GitHub Copilot 1.372.0 permite acceso al sistema de archivos fuera de una carpeta de espacio de trabajo (sin aprobación del usuario) a través de un parámetro URI de gestor de archivos para fetch_webpage. Por lo tanto, podría producirse una exfiltración si hay inyección de prompt indirecta. | |
| Analizada | Alta (7.5) | 0.92% | — | Microsoft Github Copilot Chat | 19/6/2026 | 17/8/2026 | Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (8.8) | 0.91% | — | Microsoft Azure Synapse | 19/6/2026 | 29/6/2026 | Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.6) | 0.69% | — | Microsoft Exchange Online | 19/6/2026 | 24/6/2026 | Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 0.76% | — | Microsoft 365 Copilot | 19/6/2026 | 26/6/2026 | Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (10) | 0.90% | — | Microsoft Azure Active Directory | 19/6/2026 | 24/6/2026 | Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.5) | 0.71% | — | Microsoft 365 Copilot | 19/6/2026 | 26/6/2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network. | |
| Modificada | Media (5.4) | 0.52% | — | Microsoft Edge Chromium | 19/6/2026 | 1/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an authorized attacker to perform spoofing over a network. | |
| Aplazada | Media (5.5) | 1.2% | — | Microsoft Kiota-http-fetchlibraryAI | 19/6/2026 | 23/6/2026 | @microsoft/kiota-http-fetchlibrary provides TypeScript libraries for Kiota-generated API clients. In versions 1.0.0-preview.97 through 1.0.0-preview.101, `@microsoft/kiota-http-fetchlibrary`'s `RedirectHandler` is documented as stripping `Authorization` and `Cookie` from cross-origin redirect targets, but the default… | |
| Analizada | Crítica (9.1) | 1.1% | 💥 PoC | Microsoft Heif Image Extension | 19/6/2026 | 5/10/2026 | Microsoft HEIF Image Extensions 1.2.22.0 tiene una lectura fuera de límites porque CHEIFItemInfoEntry_GetDataSize puede devolver éxito mientras deja el tamaño de datos reportado como 0. Esto provoca que un llamador realice una asignación de 1 byte. Más tarde, CopyPixels calcula copy_size = stride * abs(roi_height)… | |
| Analizada | Alta (7.5) | 1.1% | — | Microsoft 365 Copilot | 18/6/2026 | 25/6/2026 | Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Crítica (9.9) | 0.78% | — | Microsoft Dynamics 365 | 18/6/2026 | 25/6/2026 | Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.5) | 1.0% | — | Microsoft Cost Management | 18/6/2026 | 26/6/2026 | Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (8.8) | 0.77% | — | Microsoft Azure AI BOT Service | 18/6/2026 | 24/6/2026 | Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network. | |
| Modificada | Alta (7) | 0.37% | 💥 PoC | Microsoft Malware Protection Engine | 16/6/2026 | 12/8/2026 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". | |
| Pendiente de análisis | Alta (8.8) | 0.45% | — | Dell Openmanage Integration FOR Microsoft Windows Admin CenterAIMicrosoft Windows Admin CenterAI | 16/6/2026 | 1/10/2026 | Dell OpenManage Integration con Microsoft Windows Admin Center contiene una vulnerabilidad de ejecución remota de código en el plugin de la pasarela. Un usuario remoto autenticado podría potencialmente explotar esta vulnerabilidad para escalar privilegios. El usuario malicioso podría obtener la capacidad de ejecutar… |