Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
25.705 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.4) | 0.10% | — | NI SystemlinkAINI Systemlink ServerAI | 10/9/2026 | 16/9/2026 | There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulnerability may allow an attacker with local access to obtain sensitive information stored by the system in the clear. This vulnerability affects NI SystemLink and NI SystemLink Server versions prior to 2026 Q3. | |
| Pendiente de análisis | Alta (8.6) | 0.35% | — | NI SystemlinkAINI Systemlink ServerAI | 10/9/2026 | 16/9/2026 | There is an improper access control vulnerability in NI SystemLink that may allow an authenticated user with limited privileges to access host operating system files and directories that should be restricted. This vulnerability affects NI SystemLink and NI SystemLink Server versions prior to 2026 Q3. | |
| Aplazada | Crítica (9.3) | 0.53% | — | Avideo AD ServerAIWwbn AvideoAI | 10/9/2026 | 10/9/2026 | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the AD_Server plugin's log.php endpoint that fails to escape the label parameter before storage. An unauthenticated attacker can inject malicious HTML through the label parameter, which is later… | |
| Aplazada | Alta (7.1) | 0.31% | — | Countly ServerAI | 10/9/2026 | 10/9/2026 | An authorization bypass vulnerability exists in the Countly Server DBViewer due to flawed sub-pipeline detection in the aggregation stage sanitizer. The /o/db aggregation endpoint parses user-controlled aggregation JSON and passes it through a stage sanitizer that determines whether a nested array is a sub-pipeline by… | |
| Aplazada | Alta (8.8) | 0.51% | — | Siam Ordering Siam-serverAI | 9/9/2026 | 10/9/2026 | A SQL Injection vulnerability in Siam Ordering (siam-server) 1.0.0 allows remote authenticated attackers to execute arbitrary SQL commands via the ${} string concatenation in AdminMapper.java and multiple other Mapper files (including MerchantWithdrawRecordMapper.java and MemberWithdrawRecordMapper.java). | |
| Aplazada | Crítica (9.8) | 0.79% | — | S-pms Spms-serverAI | 9/9/2026 | 14/9/2026 | An issue was discovered in s-pms SPMS-Server through v1.0. The application contains a hardcoded default access token secret within its core configuration file, which is not overridden or removed in the production environment profile. A remote, unauthenticated attacker can locally forge valid administrative session… | |
| Aplazada | Crítica (9) | 1.7% | — | Amazon Awslabs Postgres-mcp-serverAI | 9/9/2026 | 10/9/2026 | An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a self-managed PostgreSQL server by placing a crafted COPY ... TO PROGRAM statement… | |
| Pendiente de análisis | Media (5.7) | 0.18% | — | Amazon Awslabs Mysql-mcp-serverAI | 9/9/2026 | 9/9/2026 | Incomplete list of disallowed inputs in the mutable SQL detector component in Amazon awslabs mysql-mcp-server might allow context-dependent actors to bypass the read-only enforcement gate and reach file-read and file-write SQL sinks via SQL inline comments that the regex engine does not treat as whitespace. To… | |
| Analizada | Alta (8.3) | 0.32% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network. | |
| Analizada | Media (6.1) | 0.41% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Media (6.5) | 1.1% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network. | |
| Analizada | Media (6.5) | 0.92% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (7.1) | 0.53% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.5) | 0.97% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (6.5) | 1.1% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network. | |
| Analizada | Crítica (9.8) | 0.97% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network. | |
| Analizada | Media (6.1) | 0.55% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7) | 0.28% | — | Microsoft Windows 11 24h2Microsoft Windows 11 25h2Microsoft Windows 11 26h1Microsoft Windows Server 2025 | 8/9/2026 | 11/9/2026 | Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (8.1) | 0.71% | — | Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 23h2Microsoft Windows 11 24h2+4 | 8/9/2026 | 11/9/2026 | Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network. | |
| Analizada | Media (5.5) | 0.30% | 💥 PoC | Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 23h2+6 | 8/9/2026 | 9/9/2026 | Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft Windows 11 23h2Microsoft Windows 11 24h2Microsoft Windows 11 25h2Microsoft Windows 11 26h1+2 | 8/9/2026 | 11/9/2026 | Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+8 | 8/9/2026 | 11/9/2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+8 | 8/9/2026 | 12/9/2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+8 | 8/9/2026 | 9/9/2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |