Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2632▼ 455 respecto a la semana anterior
Críticas / altas1285▼ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 275 respecto a la semana anterior
–

9287 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.7)0.47%—Openclaw Windows NodeAI30/9/20261/10/2026
OpenClaw Windows Node before 2026.7.1 contains an incomplete environment-variable sanitizer in system.run that fails to block GIT_CONFIG_*, DOTNET_STARTUP_HOOKS, and JAVA_TOOL_OPTIONS variables. Attackers with gateway or agent access can supply these variables to allowlisted tools like git, dotnet, or java to load…
AplazadaMedia (5.3)0.21%—Openclaw Windows NodeAI30/9/20262/10/2026
OpenClaw Windows Node through 2026.9.4 contains a server-side request forgery vulnerability in the canvas.present capability that bypasses URL risk evaluation enforced by canvas.navigate. Attackers with gateway or agent access can issue canvas.present to make the node's WebView send requests to localhost, private…
AplazadaAlta (8.7)0.53%—Openclaw Windows NodeAI30/9/20261/10/2026
OpenClaw Windows Node before 2026.7.1 contains an incomplete validation vulnerability in system.execApprovals.set that accepts wildcard-executable rules and abusable system binaries like mshta, rundll32, and certutil. Remote callers can add broad allow rules to execute arbitrary commands on the Windows host through…
AplazadaAlta (7.1)0.37%—Openclaw Windows NodeAI30/9/20261/10/2026
OpenClaw Windows Node before 2026.7.1 contains an allocation of resources without limits vulnerability in the gateway WebSocket transport that allows connected gateways to exhaust node memory. Attackers can send an unending sequence of WebSocket continuation frames without EndOfMessage to cause unbounded memory growth…
AplazadaAlta (8.7)0.69%—Openclaw Windows NodeAI30/9/20261/10/2026
OpenClaw Windows Node before 2026.7.1 contains an incorrect authorization vulnerability in the system.run exec-approval policy where ExecShellWrapperParser fails to split commands on pipe operators or extract command substitutions. Connected gateways or agents can bypass approval rules by placing denied commands…
AplazadaAlta (7.1)0.28%—Openclaw Windows NodeAI30/9/20262/10/2026
OpenClaw Windows Node before 2026.7.1-3 contains a missing authorization vulnerability in NodeService capture handlers that allows connected gateways or agents to perform screen snapshots, camera snaps, and location captures without consent prompts. Attackers can invoke screen.snapshot, camera.snap, and location.get…
Pendiente de análisisMedia (6.8)0.06%—Cato Windows SDP ClientAI30/9/202630/9/2026
Cato Windows SDP Client before version 6.12.6 contains an arbitrary file disclosure vulnerability. A low-privileged local user can cause the Windows service, running as Local System, to read and disclose arbitrary local files due to improper file path validation and missing TLS certificate enforcement.
AplazadaMedia (6.9)0.14%—Watchdog AntivirusAIMicrosoft WindowsAI20/9/202622/9/2026
Missing Authorization in the IOCTL handlers of the wsdkd.sys kernel drivers in Watchdog WatchDog Antivirus 1.8.640 (driver versions 1.3.0.0 and earlier) on Microsoft Windows allows local, low-privileged attackers to delete arbitrary files with SYSTEM privileges, bypassing NTFS access controls and potentially disabling…
AnalizadaAlta (8.2)0.35%—Microsoft Windows 11 26h114/9/202629/9/2026
Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
Pendiente de análisisMedia (4.4)0.15%—Citrix Workspace APP FOR WindowsAI11/9/202616/9/2026
Out-of-bounds write vulnerability in Citrix Citrix Workspace app for Windows. This issue affects Citrix Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607.
Pendiente de análisisMedia (4.8)0.14%—Citrix Workspace APP FOR WindowsAI11/9/202616/9/2026
Out-of-bounds read vulnerability in Citirx Workspace app for Windows. This issue affects Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, and before LTSR 2607.
Pendiente de análisisMedia (6.9)0.13%—Microsoft Windows 8AISilabs Cp210x DriverAI10/9/202610/9/2026
In the silabser.sys Windows 8 driver for CP210x devices, a local unprivileged user can use incorrect driver settings to cause a kernel crash.
Pendiente de análisisMedia (6)0.13%—Okta Verify FOR WindowsAI8/9/202610/9/2026
The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before deleting its contents with elevated privileges. The delete operation follows the junction target, resulting in recursive deletion of unintended directory contents.
AnalizadaAlta (8.8)0.82%—Microsoft Windows 11 24h28/9/20269/9/2026
Heap-based buffer overflow in Windows Print Spooler Components allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (7)0.28%—Microsoft Windows 11 24h2Microsoft Windows 11 25h2Microsoft Windows 11 26h1Microsoft Windows Server 20258/9/202611/9/2026
Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (8.1)0.71%—Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 23h2Microsoft Windows 11 24h2+48/9/202611/9/2026
Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
AnalizadaMedia (5.5)0.30%—Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2Microsoft Windows 11 23h2+68/9/20269/9/2026
Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally.
AnalizadaAlta (7.8)0.33%—Microsoft Windows 11 23h2Microsoft Windows 11 24h2Microsoft Windows 11 25h2Microsoft Windows 11 26h1+28/9/202611/9/2026
Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.33%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+88/9/202611/9/2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.33%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+88/9/202612/9/2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.33%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+88/9/20269/9/2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.33%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+88/9/202612/9/2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.33%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+88/9/202612/9/2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.33%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+88/9/202612/9/2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.33%—Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2Microsoft Windows 10 22h2+88/9/202612/9/2026
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.