Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2558▼ 318 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
18.383 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Crítica (9.3) | 0.95% | — | Mikrotik RouterosAI | 2/10/2026 | 3/10/2026 | The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single… | |
| Recibida | Alta (8.8) | 0.50% | — | Microsoft Exchange ServerAI | 2/10/2026 | 3/10/2026 | Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network. | |
| Pendiente de análisis | Alta (8.5) | 0.30% | — | Prosemirror-viewAI | 2/10/2026 | 2/10/2026 | ProseMirror's view component renders and manages the editable browser interface for ProseMirror documents. Prior to 1.42.3, prosemirror-view paste handling accepts attacker-provided HTML whose clipboard slice context contains attributes that are not passed through schema attribute validation. When a user pastes the… | |
| Pendiente de análisis | Crítica (9.3) | 0.25% | — | Microsoft Netx DUOAI | 29/9/2026 | 30/9/2026 | NetX Duo's WebSocket client resets the unmasking cursor to the first `NX_PACKET` each time it advances through a chained packet, while the loop's upper bound belongs to the current packet. With the standard contiguous packet-pool layout, a masked server frame split across two packets therefore drives the XOR loop… | |
| Pendiente de análisis | Alta (7.5) | 0.17% | — | Microsoft Netx SecureAI | 29/9/2026 | 30/9/2026 | The `_nx_secure_x509_asn1_tlv_block_parse()` function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate parsing in NetX Secure, and therefore runs on certificates supplied by a remote peer during the TLS handshake. The function reads the one-byte… | |
| Pendiente de análisis | Alta (8.5) | 0.10% | — | Microsoft ThreadxAI | 29/9/2026 | 2/10/2026 | An unprivileged, memory-protected ThreadX module can have the kernel read and write memory at addresses of its choosing, in privileged mode, and can use that to clear the MPU enable bit and remove its own isolation boundary. The Module Manager decided whether a privileged service could dereference an object address a… | |
| Pendiente de análisis | Alta (8.6) | 0.12% | — | Microsoft LevelxAI | 29/9/2026 | 29/9/2026 | Mounting an attacker-controlled NAND flash image (`lx_nand_flash_open()`) triggers an unbounded out-of-bounds heap **write** in LevelX's NAND flash-translation-layer metadata parser that overwrites a driver function pointer in the control block, giving a demonstrated control-flow hijack — RIP set to a full 8-byte… | |
| Pendiente de análisis | Alta (8.7) | 0.25% | — | Microsoft NetxAI | 29/9/2026 | 29/9/2026 | An unauthenticated client can drain the RTSP server's packet pool with a couple of dozen requests that carry a Session header the parser cannot convert. The Session branch returns the raw NetX error code instead of an RTSP status code: ```c /* addons/rtsp/nx_rtsp_server.c:2754 */ if (status) ``` Every other branch of… | |
| Pendiente de análisis | Media (4.7) | 0.14% | — | Microsoft Network MonitorAI | 29/9/2026 | 29/9/2026 | Microsoft Network Monitor file parser large loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | |
| Pendiente de análisis | Alta (8.6) | 0.16% | — | Ros2AI | 28/9/2026 | 30/9/2026 | A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) 'ros2topic' command-line tool, affecting all ROS 2 distributions from Crystal Clemmys up to and including Lyrical Luth and Rolling Ridley. The vulnerability lies in the 'hz' verb, which reports the publishing rate of a topic and… | |
| En análisis | Alta (7.5) | 0.35% | — | Microsoft Office OutlookAI | 25/9/2026 | 29/9/2026 | Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | |
| Externa | Sin puntuar | — | — | Microsoft OfficeAI | 25/9/2026 | — | Microsoft Office vulnerability that allows information disclosure. The vulnerability was addressed by updates released in July 2026, though the CVE was inadvertently omitted from the initial security bulletin. This is an informational update for tracking purposes. | |
| En análisis | Alta (8.8) | 0.44% | — | Microsoft OutlookAI | 23/9/2026 | 30/9/2026 | Microsoft Office Outlook Remote Code Execution Vulnerability | |
| Aplazada | Alta (7.1) | 0.24% | — | AlbatrossAI | 23/9/2026 | 24/9/2026 | Robur Albatross 1.0.0 through 2.x before 2.7.2 does not limit use of the ring buffer, leading to an albatross-console loop with no recognized termination condition. This is only exploitable by users who can send console subscription commands to unikernels that produce sufficient log output to fill the ring buffer… | |
| Aplazada | Media (6.1) | 0.13% | — | Acer NitrosenseAI | 23/9/2026 | 25/9/2026 | An unauthenticated local attacker can connect to the Electron DevTools endpoint exposed by Acer NitroSense software (versions up to and including 5.2.63) on localhost TCP port 9993. Because Chromium remote debugging is enabled in the production application, the attacker can execute JavaScript in the privileged… | |
| Aplazada | Media (6.1) | 0.35% | — | Acer NitrosenseAI | 23/9/2026 | 25/9/2026 | An unauthenticated local attacker can connect to the MQTT broker over its localhost WebSocket endpoint in Acer NitroSense software (versions up to and including 5.2.62). This allows the attacker to invoke exposed ddsc RPC functions, including child_process.execSync(), resulting in arbitrary command execution in the… | |
| Pendiente de análisis | Alta (8.7) | 0.49% | — | Mikrotik RouterosAI | 22/9/2026 | 25/9/2026 | MikroTik RouterOS before 7.25beta4 contains an improper input validation vulnerability in the labelled-VPN NLRI iterators of the routing service that allows an unauthenticated on-path attacker to crash the BGP service by sending a malformed MP_REACH_NLRI UPDATE message with a prefix-length value below the minimum… | |
| Aplazada | Alta (7.8) | 0.19% | — | Crosswire XiphosAI | 21/9/2026 | 22/9/2026 | An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menu_popup.c components | |
| Aplazada | Alta (8.7) | 0.44% | — | ZaprosAI | 21/9/2026 | 24/9/2026 | Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service via memory exhaustion. The issue affects all callers who streamed compressed responses relying on the chunk size — explicit (`iter_bytes(chunk_size=...)`) or the default — to bound memory. The decoder ignored that bound, so a… | |
| Aplazada | Media (6.9) | 0.43% | — | ZaprosAI | 21/9/2026 | 30/9/2026 | Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service when an application requests content from an untrusted server, or follows a redirect to one, because a malicious response containing an excessive number of chained `Content-Encoding` values causes Zapros to construct a deeply… | |
| Aplazada | Media (6.9) | 0.14% | — | Watchdog AntivirusAIMicrosoft WindowsAI | 20/9/2026 | 22/9/2026 | Missing Authorization in the IOCTL handlers of the wsdkd.sys kernel drivers in Watchdog WatchDog Antivirus 1.8.640 (driver versions 1.3.0.0 and earlier) on Microsoft Windows allows local, low-privileged attackers to delete arbitrary files with SYSTEM privileges, bypassing NTFS access controls and potentially disabling… | |
| Analizada | Alta (7.8) | 0.26% | — | Microsoft Edge Chromium | 18/9/2026 | 24/9/2026 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally. | |
| Aplazada | Media (6.5) | 0.11% | — | MicrosandboxAI | 18/9/2026 | 24/9/2026 | microsandbox is an easy, fast, local-first microVM runtime and library. Prior to 0.5.10, sdk/rust/lib/runtime/spawn.rs serializes NetworkConfig secret values into the --network-config argument and passes per-sandbox secrets through repeated --env arguments accepted by crates/cli/lib/sandbox_cmd.rs. Other local users… | |
| Analizada | Alta (7.7) | 0.84% | — | Microsoft 365 Copilot | 17/9/2026 | 28/9/2026 | Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network. | |
| Analizada | Crítica (9.9) | 0.78% | — | Microsoft Azure Horizondb | 17/9/2026 | 25/9/2026 | Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network. |