Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.48% | — | Microsoft Defender FOR Endpoint | 11/8/2026 | 17/8/2026 | Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information locally. | |
| Analizada | Alta (7) | 0.23% | — | Microsoft Defender FOR Endpoint | 14/7/2026 | 22/7/2026 | Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7) | 0.20% | — | Microsoft Defender FOR Endpoint | 14/7/2026 | 22/7/2026 | Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized attacker to elevate privileges locally. | |
| Analizada | Media (5.5) | 0.40% | — | Microsoft Defender FOR Endpoint | 14/7/2026 | 22/7/2026 | Exposure of private personal information to an unauthorized actor in Microsoft Defender allows an authorized attacker to disclose information locally. | |
| Analizada | Alta (7) | 0.23% | — | Microsoft Defender FOR Endpoint | 9/6/2026 | 23/7/2026 | Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (8.8) | 0.53% | — | Microsoft Defender FOR Endpoint | 10/2/2026 | 17/6/2026 | Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adjacent network. | |
| Analizada | Media (4.7) | 0.21% | — | Microsoft Defender FOR Endpoint | 14/10/2025 | 30/9/2026 | Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Linux allows an authorized attacker to deny service locally. | |
| Modificada | Alta (7.8) | 0.80% | — | Microsoft Defender FOR Endpoint | 15/5/2025 | 17/6/2026 | Improper access control in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally. | |
| Analizada | Media (6.7) | 0.42% | — | Microsoft Defender FOR Endpoint | 13/5/2025 | 17/6/2026 | External control of file name or path in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally. | |
| Analizada | Media (6.5) | 1.1% | — | Microsoft Defender FOR Endpoint | 12/12/2024 | 17/6/2026 | Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an authorized attacker to disclose information over a network. | |
| Analizada | Alta (8.1) | 1.7% | — | Microsoft Defender FOR Endpoint | 12/12/2024 | 17/6/2026 | Microsoft Defender for Endpoint on Android Spoofing Vulnerability | |
| Modificada | Media (5.5) | 0.65% | — | Microsoft Defender FOR Endpoint | 8/10/2024 | 17/6/2026 | Relative path traversal in Microsoft Defender for Endpoint allows an authorized attacker to perform spoofing locally. | |
| Modificada | Alta (7.8) | 0.64% | — | Microsoft Defender FOR Endpoint | 13/2/2024 | 10/8/2026 | Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability | |
| Modificada | Media (4.7) | 7.2% | — | Microsoft Windows Defender FOR Endpoint | 21/9/2022 | 17/6/2026 | A time-of-check-time-of-use (TOCTOU) race condition vulnerability was found in networkd-dispatcher. This flaw exists because there is a certain time between the scripts being discovered and them being run. An attacker can abuse this vulnerability to replace scripts that networkd-dispatcher believes to be owned by root… | |
| Modificada | Media (5.5) | 12% | — | Microsoft Windows Defender FOR Endpoint | 21/9/2022 | 17/6/2026 | A vulnerability was found in networkd-dispatcher. This flaw exists because no functions are sanitized by the OperationalState or the AdministrativeState of networkd-dispatcher. This attack leads to a directory traversal to escape from the “/etc/networkd-dispatcher” base directory. | |
| Modificada | Alta (7.8) | 0.53% | — | Microsoft Defender FOR Endpoint | 13/9/2022 | 17/6/2026 | Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability | |
| Modificada | Media (6.5) | 1.7% | — | Microsoft Defender FOR Endpoint | 12/7/2022 | 17/6/2026 | Microsoft Defender for Endpoint Tampering Vulnerability | |
| Modificada | Media (5.9) | 1.9% | — | Microsoft Defender FOR Endpoint EDR SensorMicrosoft Defender FOR Endpoint | 9/3/2022 | 17/6/2026 | Microsoft Defender for Endpoint Spoofing Vulnerability |