Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2543▼ 416 respecto a la semana anterior
Críticas / altas1316▲ 27 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.7) | 0.11% | — | Android SurfaceflingerAI | 7/9/2026 | 8/9/2026 | In SurfaceFlinger, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11123860; Issue ID: MSV-8890. | |
| Analizada | Alta (8.8) | 0.96% | — | Microsoft Surface Management Services | 24/7/2026 | 6/8/2026 | Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (7.8) | 0.30% | — | Microsoft Surface GO 2 1901 FirmwareMicrosoft Surface GO 2 1926 FirmwareMicrosoft Surface GO 2 1927 FirmwareMicrosoft Surface GO 3 1901 Firmware+23 | 14/7/2026 | 24/7/2026 | Insufficient granularity of access control in Microsoft Surface allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.1) | 0.85% | — | Microsoft Surface HUB 2S FirmwareMicrosoft Surface PRO 8 FOR Business 1983 FirmwareMicrosoft Surface Laptop GO FirmwareMicrosoft Surface Laptop GO 2 Firmware+23 | 11/2/2025 | 17/6/2026 | Microsoft Surface Security Feature Bypass Vulnerability | |
| Aplazada | Media (6.5) | 0.41% | — | Wpsurface BloglentorAI | 14/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsurface BlogLentor allows Stored XSS.This issue affects BlogLentor: from n/a through 1.0.8. | |
| Modificada | Crítica (9.8) | 1.1% | — | Festo BUS Module Cpx-e-ep FirmwareFesto BUS Node Cpx-fb32 FirmwareFesto BUS Node Cpx-fb33 FirmwareFesto BUS Node Cpx-fb36 Firmware+95 | 1/12/2022 | 17/6/2026 | In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which could lead to a complete loss of confidentiality, integrity and availability. | |
| Modificada | Media (6.1) | 0.86% | — | Microsoft Surface PRO 3 Firmware | 20/10/2021 | 17/6/2026 | Microsoft Surface Pro 3 Security Feature Bypass Vulnerability | |
| Modificada | Media (6.8) | 0.86% | — | Microsoft Surface HUB Firmware | 11/2/2020 | 17/6/2026 | A security feature bypass vulnerability exists in Surface Hub when prompting for credentials, aka 'Surface Hub Security Feature Bypass Vulnerability'. | |
| Modificada | Media (5.5) | 61% | — | Intel Atom CIntel Atom EIntel Atom X5-e3930Intel Atom X5-e3940+278 | 22/5/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB),… |