Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3234▲ 671 respecto a la semana anterior
Críticas / altas1517▲ 124 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
25.772 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.54% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+8 | 14/7/2026 | 23/7/2026 | Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network. | |
| Analizada | Alta (8.1) | 0.54% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+7 | 14/7/2026 | 23/7/2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Media (5.5) | 0.48% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+7 | 14/7/2026 | 22/7/2026 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | |
| Analizada | Media (5.5) | 0.40% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+7 | 14/7/2026 | 22/7/2026 | Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally. | |
| Analizada | Alta (8) | 0.87% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+8 | 14/7/2026 | 17/9/2026 | Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 14/7/2026 | 22/7/2026 | Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network. | |
| Analizada | Media (5.5) | 0.48% | — | Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 24h2+5 | 14/7/2026 | 22/7/2026 | Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally. | |
| Analizada | Media (6.5) | 1.00% | 💥 PoC | Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 23h2+6 | 14/7/2026 | 22/7/2026 | Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network. | |
| Analizada | Media (5.5) | 0.27% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 14/7/2026 | 22/7/2026 | Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally. | |
| Analizada | Media (5.5) | 0.48% | — | Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 23h2+6 | 14/7/2026 | 22/7/2026 | Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally. | |
| Analizada | Media (5.5) | 0.48% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+9 | 14/7/2026 | 22/7/2026 | Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. | |
| Pendiente de análisis | Crítica (9) | 0.68% | — | Eclipse Basyx Java Server SDKAI | 14/7/2026 | 14/7/2026 | In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to an unauthenticated arbitrary file write through the AAS thumbnail API. The AAS thumbnail upload path accepted a client-controlled fileName request parameter and passed it through… | |
| Pendiente de análisis | Media (4.7) | 0.23% | — | SAP Netweaver Application Server AbapAI | 14/7/2026 | 14/7/2026 | Due to a Cross-Site Scripting (XSS) vulnerability, applications based on Business Server Pages framework in SAP NetWeaver Application Server ABAP reflects unsanitized input into the HTTP response which allows an attacker to inject and execute arbitrary JavaScript code under certain conditions. Successful exploitation… | |
| Pendiente de análisis | Alta (8.2) | 0.36% | — | SAP Netweaver Application Server JavaAI | 14/7/2026 | 14/7/2026 | SAP NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScript through crafted URLs. When a victim accesses such a URL, the script executes in the user's browser, allowing the attacker to access sensitive session information and modify non-sensitive data displayed in the… | |
| Pendiente de análisis | Crítica (9.9) | 0.56% | — | SAP Netweaver Application Server AbapAI | 14/7/2026 | 29/7/2026 | SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability. This has high impact on confidentiality, integrity, and availability of the… | |
| Aplazada | Alta (7.7) | 0.48% | — | Vmware Boot Admin ServerAI | 13/7/2026 | 15/7/2026 | Spring Boot Admin Server before 4.1.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers to register instances with attacker-controlled healthUrl and managementUrl parameters without validation against private IP ranges or metadata endpoints. Attackers can force the server to… | |
| Pendiente de análisis | Alta (8.6) | 0.46% | — | Argo CD Helm ChartAIArgo Repo-serverAI | 13/7/2026 | 15/7/2026 | Argo CD Helm Chart before 10.0.0 fails to install network policies by default, allowing any pod on a cluster to access repo-server and other Argo APIs. Attackers can exploit this unrestricted network access through combined attacks to achieve cluster compromise and remote code execution. | |
| Analizada | Media (4.3) | 0.27% | — | Mattermost Server | 13/7/2026 | 13/7/2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to check the manage_shared_channels permission in the /share-channel autocomplete handler, which allows an authenticated user without that permission to enumerate configured remote cluster connection metadata via slash command… | |
| Analizada | Baja (3.8) | 0.26% | — | Mattermost Server | 13/7/2026 | 13/7/2026 | Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams endpoint, which allows a user with the User Manager role to obtain invite links for private teams and use them to join or share access to those teams via the scheme teams API endpoint.. Mattermost… | |
| Analizada | Media (4.3) | 0.25% | — | Mattermost Server | 13/7/2026 | 13/7/2026 | Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric configuration changes to the playbook being saved, which allows an authenticated user with team access to alter another user’s playbook metric settings via a crafted import or update request with a foreign metric ID.… | |
| Analizada | Media (4.9) | 0.36% | — | Mattermost Server | 13/7/2026 | 13/7/2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming webhook user has access to the target team or channel, which allows a requester with webhook management permissions to create posts or direct messages attributed to another user via crafted incoming… | |
| Analizada | Media (5.4) | 0.23% | — | Mattermost Server | 13/7/2026 | 13/7/2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, which allows a deactivated guest user to obtain a fully functional session via a magic-link token issued prior to deactivation.. Mattermost Advisory… | |
| Analizada | Media (6.5) | 0.30% | — | Mattermost Server | 13/7/2026 | 15/7/2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, which allows a deactivated user or an attacker in possession of a valid refresh token to obtain new functional access tokens via the OAuth refresh token grant endpoint..… | |
| Analizada | Media (6.5) | 0.42% | — | Mattermost Server | 13/7/2026 | 13/7/2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the length and content of message attachment field values, which allows an authenticated attacker to cause a denial of service for all users in a channel via a post containing a specially crafted payload that triggers… | |
| Analizada | Media (6.5) | 0.30% | — | Mattermost Server | 13/7/2026 | 13/7/2026 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the channel referenced in an action cookie matches the channel of the target post, which allows an authenticated user without access to a private channel to trigger interactive post actions on posts in that channel via a… |