Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 223 respecto a la semana anterior
Críticas / altas1373▲ 144 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
103 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.7) | 0.84% | — | Microsoft 365 Copilot | 17/9/2026 | 28/9/2026 | Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network. | |
| Analizada | Alta (8.8) | 0.72% | — | Microsoft 365 Copilot | 17/9/2026 | 25/9/2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network. | |
| Pendiente de análisis | Alta (7.4) | 0.89% | — | Microsoft 365 CopilotAI | 17/9/2026 | 18/9/2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (5.9) | 0.39% | — | Microsoft Copilot | 17/9/2026 | 25/9/2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Crítica (10) | 0.49% | — | Microsoft Copilot Studio | 3/9/2026 | 8/9/2026 | Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Media (6.5) | 0.84% | — | Microsoft Azure Copilot | 20/8/2026 | 8/9/2026 | Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network. | |
| Analizada | Alta (7.5) | 4.1% | — | Microsoft Copilot | 18/8/2026 | 10/9/2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network. | |
| Modificada | Media (6.5) | 0.64% | — | Microsoft Github Copilot Chat | 11/8/2026 | 24/9/2026 | No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network. | |
| Aplazada | Crítica (9.8) | 0.91% | — | AI Copilot Content GeneratorAI | 8/8/2026 | 12/8/2026 | The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to create a new… | |
| Analizada | Crítica (9.9) | 1.7% | — | Microsoft 365 Copilot | 24/7/2026 | 29/7/2026 | Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network. | |
| Aplazada | Media (6.5) | 0.45% | — | AI Copilot Content GeneratorAI | 23/7/2026 | 23/7/2026 | The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Crítica (9.8) | 0.50% | — | AI CopilotAI | 17/7/2026 | 17/7/2026 | The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator session, allowing unauthenticated attackers who complete the public OAuth flow to execute privileged MCP tools as an administrator, including arbitrary user creation and… | |
| Analizada | Crítica (9.8) | 0.79% | — | Microsoft 365 Copilot | 14/7/2026 | 16/7/2026 | Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.1) | 0.53% | — | Microsoft Copilot | 14/7/2026 | 22/7/2026 | Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized attacker to perform tampering over a network. | |
| Analizada | Alta (7.8) | 0.36% | — | Microsoft Github Copilot | 14/7/2026 | 22/7/2026 | Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft 365 CopilotMicrosoft 365Microsoft Office 2021Microsoft Office 2024+12 | 14/7/2026 | 22/7/2026 | Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally. | |
| Modificada | Crítica (9.6) | 0.86% | — | Microsoft 365 Copilot | 14/7/2026 | 26/7/2026 | Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Sergey Aiwu Ai-copilot-content-generatorAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sergey AIWU ai-copilot-content-generator allows Blind SQL Injection.This issue affects AIWU: from n/a through <= 1.5.4. | |
| Analizada | Crítica (9.3) | 0.72% | — | Microsoft 365 Copilot | 2/7/2026 | 7/7/2026 | Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Baja (1.3) | 0.36% | — | Aidc-ai Comfyui-copilotAI | 28/6/2026 | 29/6/2026 | A flaw has been found in AIDC-AI ComfyUI-Copilot up to 2.0.28. This issue affects some unknown processing of the file backend/controller/conversation_api.py of the component Workflow Checkpoint Restore Handler. Executing a manipulation can lead to improper control of resource identifiers. The attack may be performed… | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft Github Copilot | 22/6/2026 | 30/6/2026 | GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpage. Therefore, exfiltration could occur if there is indirect prompt injection. | |
| Analizada | Alta (7.5) | 0.92% | — | Microsoft Github Copilot Chat | 19/6/2026 | 17/8/2026 | Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (8.8) | 0.76% | — | Microsoft 365 Copilot | 19/6/2026 | 26/6/2026 | Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.5) | 0.71% | — | Microsoft 365 Copilot | 19/6/2026 | 26/6/2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network. | |
| Analizada | Alta (7.5) | 1.1% | — | Microsoft 365 Copilot | 18/6/2026 | 25/6/2026 | Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network. |