Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

25.705 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.4)0.10%—NI SystemlinkAINI Systemlink ServerAI10/9/202616/9/2026
There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulnerability may allow an attacker with local access to obtain sensitive information stored by the system in the clear. This vulnerability affects NI SystemLink and NI SystemLink Server versions prior to 2026 Q3.
Pendiente de análisisAlta (8.6)0.35%—NI SystemlinkAINI Systemlink ServerAI10/9/202616/9/2026
There is an improper access control vulnerability in NI SystemLink that may allow an authenticated user with limited privileges to access host operating system files and directories that should be restricted. This vulnerability affects NI SystemLink and NI SystemLink Server versions prior to 2026 Q3.
AplazadaCrítica (9.3)0.53%—Avideo AD ServerAIWwbn AvideoAI10/9/202610/9/2026
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the AD_Server plugin's log.php endpoint that fails to escape the label parameter before storage. An unauthenticated attacker can inject malicious HTML through the label parameter, which is later…
AplazadaAlta (7.1)0.31%—Countly ServerAI10/9/202610/9/2026
An authorization bypass vulnerability exists in the Countly Server DBViewer due to flawed sub-pipeline detection in the aggregation stage sanitizer. The /o/db aggregation endpoint parses user-controlled aggregation JSON and passes it through a stage sanitizer that determines whether a nested array is a sub-pipeline by…
AplazadaAlta (8.8)0.51%—Siam Ordering Siam-serverAI9/9/202610/9/2026
A SQL Injection vulnerability in Siam Ordering (siam-server) 1.0.0 allows remote authenticated attackers to execute arbitrary SQL commands via the ${} string concatenation in AdminMapper.java and multiple other Mapper files (including MerchantWithdrawRecordMapper.java and MemberWithdrawRecordMapper.java).
AplazadaCrítica (9.8)0.79%—S-pms Spms-serverAI9/9/202614/9/2026
An issue was discovered in s-pms SPMS-Server through v1.0. The application contains a hardcoded default access token secret within its core configuration file, which is not overridden or removed in the production environment profile. A remote, unauthenticated attacker can locally forge valid administrative session…
AplazadaCrítica (9)1.7%—Amazon Awslabs Postgres-mcp-serverAI9/9/202610/9/2026
An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a self-managed PostgreSQL server by placing a crafted COPY ... TO PROGRAM statement…
Pendiente de análisisMedia (5.7)0.18%—Amazon Awslabs Mysql-mcp-serverAI9/9/20269/9/2026
Incomplete list of disallowed inputs in the mutable SQL detector component in Amazon awslabs mysql-mcp-server might allow context-dependent actors to bypass the read-only enforcement gate and reach file-read and file-write SQL sinks via SQL inline comments that the regex engine does not treat as whitespace. To…
AnalizadaAlta (8.3)0.32%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.
AnalizadaMedia (6.1)0.41%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
AnalizadaMedia (6.5)1.1%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network.
AnalizadaAlta (7.5)1.2%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.
AnalizadaMedia (6.5)0.92%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (7.1)0.53%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (7.5)0.97%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.
AnalizadaMedia (6.5)1.1%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.
AnalizadaCrítica (9.8)0.97%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.
AnalizadaMedia (6.1)0.55%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (7)0.28%—Microsoft Windows 11 24h2Microsoft Windows 11 25h2Microsoft Windows 11 26h1Microsoft Windows Server 20258/9/202611/9/2026
Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (8.1)0.71%—Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 23h2Microsoft Windows 11 24h2+48/9/202611/9/2026
Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
AnalizadaMedia (5.5)0.30%💥 PoCMicrosoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 23h2+68/9/20269/9/2026
Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally.
AnalizadaAlta (7.8)0.33%—Microsoft Windows 11 23h2Microsoft Windows 11 24h2Microsoft Windows 11 25h2Microsoft Windows 11 26h1+28/9/202611/9/2026
Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.33%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+88/9/202611/9/2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.33%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+88/9/202612/9/2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.33%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+88/9/20269/9/2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.