Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2632▼ 455 respecto a la semana anterior
Críticas / altas1285▼ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 275 respecto a la semana anterior
9287 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.7) | 0.47% | — | Openclaw Windows NodeAI | 30/9/2026 | 1/10/2026 | OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS variables. Attackers with gateway or agent access can supply these variables to allowlisted tools like git, dotnet, or java to load… | |
| Aplazada | Media (5.3) | 0.21% | — | Openclaw Windows NodeAI | 30/9/2026 | 2/10/2026 | OpenClaw Windows Node through 2026.9.4 contains a server-side request forgery vulnerability in the canvas.present capability that bypasses URL risk evaluation enforced by canvas.navigate. Attackers with gateway or agent access can issue canvas.present to make the node's WebView send requests to localhost, private… | |
| Aplazada | Alta (8.7) | 0.53% | — | Openclaw Windows NodeAI | 30/9/2026 | 1/10/2026 | OpenClaw Windows Node before 2026.7.1 contains an incomplete validation vulnerability in system.execApprovals.set that accepts wildcard-executable rules and abusable system binaries like mshta, rundll32, and certutil. Remote callers can add broad allow rules to execute arbitrary commands on the Windows host through… | |
| Aplazada | Alta (7.1) | 0.37% | — | Openclaw Windows NodeAI | 30/9/2026 | 1/10/2026 | OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits vulnerability in the gateway WebSocket transport that allows connected gateways to exhaust node memory. Attackers can send an unending sequence of WebSocket continuation frames without EndOfMessage to cause unbounded memory growth… | |
| Aplazada | Alta (8.7) | 0.69% | — | Openclaw Windows NodeAI | 30/9/2026 | 1/10/2026 | OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval policy where ExecShellWrapperParser fails to split commands on pipe operators or extract command substitutions. Connected gateways or agents can bypass approval rules by placing denied commands… | |
| Aplazada | Alta (7.1) | 0.28% | — | Openclaw Windows NodeAI | 30/9/2026 | 2/10/2026 | OpenClaw Windows Node before 2026.7.1-3 contains a missing authorization vulnerability in NodeService capture handlers that allows connected gateways or agents to perform screen snapshots, camera snaps, and location captures without consent prompts. Attackers can invoke screen.snapshot, camera.snap, and location.get… | |
| Pendiente de análisis | Media (6.8) | 0.06% | — | Cato Windows SDP ClientAI | 30/9/2026 | 30/9/2026 | Cato Windows SDP Client before version 6.12.6 contains an arbitrary file disclosure vulnerability. A low-privileged local user can cause the Windows service, running as Local System, to read and disclose arbitrary local files due to improper file path validation and missing TLS certificate enforcement. | |
| Aplazada | Media (6.9) | 0.14% | — | Watchdog AntivirusAIMicrosoft WindowsAI | 20/9/2026 | 22/9/2026 | Missing Authorization in the IOCTL handlers of the wsdkd.sys kernel drivers in Watchdog WatchDog Antivirus 1.8.640 (driver versions 1.3.0.0 and earlier) on Microsoft Windows allows local, low-privileged attackers to delete arbitrary files with SYSTEM privileges, bypassing NTFS access controls and potentially disabling… | |
| Analizada | Alta (8.2) | 0.35% | — | Microsoft Windows 11 26h1 | 14/9/2026 | 29/9/2026 | Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. | |
| Pendiente de análisis | Media (4.4) | 0.15% | — | Citrix Workspace APP FOR WindowsAI | 11/9/2026 | 16/9/2026 | Out-of-bounds write vulnerability in Citrix Citrix Workspace app for Windows. This issue affects Citrix Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607. | |
| Pendiente de análisis | Media (4.8) | 0.14% | — | Citrix Workspace APP FOR WindowsAI | 11/9/2026 | 16/9/2026 | Out-of-bounds read vulnerability in Citirx Workspace app for Windows. This issue affects Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607. | |
| Pendiente de análisis | Media (6.9) | 0.13% | — | Microsoft Windows 8AISilabs Cp210x DriverAI | 10/9/2026 | 10/9/2026 | In the silabser.sys Windows 8 driver for CP210x devices, a local unprivileged user can use incorrect driver settings to cause a kernel crash. | |
| Pendiente de análisis | Media (6) | 0.13% | — | Okta Verify FOR WindowsAI | 8/9/2026 | 10/9/2026 | The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before deleting its contents with elevated privileges. The delete operation follows the junction target, resulting in recursive deletion of unintended directory contents. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft Windows 11 24h2 | 8/9/2026 | 9/9/2026 | Heap-based buffer overflow in Windows Print Spooler Components allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7) | 0.28% | — | Microsoft Windows 11 24h2Microsoft Windows 11 25h2Microsoft Windows 11 26h1Microsoft Windows Server 2025 | 8/9/2026 | 11/9/2026 | Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (8.1) | 0.71% | — | Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 23h2Microsoft Windows 11 24h2+4 | 8/9/2026 | 11/9/2026 | Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network. | |
| Analizada | Media (5.5) | 0.30% | — | Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 23h2+6 | 8/9/2026 | 9/9/2026 | Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft Windows 11 23h2Microsoft Windows 11 24h2Microsoft Windows 11 25h2Microsoft Windows 11 26h1+2 | 8/9/2026 | 11/9/2026 | Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+8 | 8/9/2026 | 11/9/2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+8 | 8/9/2026 | 12/9/2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+8 | 8/9/2026 | 9/9/2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+8 | 8/9/2026 | 12/9/2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+8 | 8/9/2026 | 12/9/2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+8 | 8/9/2026 | 12/9/2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+8 | 8/9/2026 | 12/9/2026 | Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally. |