Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7) | 0.28% | — | Microsoft Power Automate FOR Desktop | 8/9/2026 | 29/9/2026 | Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally. | |
| Analizada | Media (6.5) | 1.00% | — | Microsoft Power Automate FOR Desktop | 12/5/2026 | 17/6/2026 | Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose information over a network. | |
| Analizada | Crítica (9.8) | 1.2% | — | Microsoft Power Automate FOR Desktop | 5/6/2025 | 17/6/2026 | Exposure of sensitive information to an unauthorized actor in Power Automate allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Media (5.7) | 0.90% | — | Microsoft Power Automate FOR Desktop | 15/4/2025 | 17/6/2026 | Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network. | |
| Analizada | Alta (7.8) | 0.75% | — | Microsoft Power Automate FOR Desktop | 14/1/2025 | 17/6/2026 | Microsoft Power Automate Remote Code Execution Vulnerability | |
| Analizada | Alta (8.5) | 0.88% | — | Microsoft Power Automate | 10/9/2024 | 10/8/2026 | Microsoft Power Automate Desktop Remote Code Execution Vulnerability |