Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.61% | — | Microsoft Windows Admin Center | 7/8/2026 | 7/8/2026 | Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.5) | 0.66% | — | Microsoft Remote Desktop WEB ClientMicrosoft Windows Admin Center | 17/7/2026 | 22/7/2026 | Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (6.1) | 0.41% | — | Microsoft Windows Admin Center | 16/7/2026 | 14/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network. | |
| Pendiente de análisis | Alta (8.8) | 1.2% | — | Lenovo Xclarity Integrator FOR Windows Admin CenterAI | 16/7/2026 | 16/7/2026 | The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vulnerable to Powershell Command Injection when establishing remote PowerShell commands. | |
| Analizada | Alta (8.8) | 0.99% | — | Microsoft Windows Admin Center | 14/7/2026 | 24/7/2026 | Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 1.0% | — | Microsoft Windows Admin Center | 14/7/2026 | 24/7/2026 | Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (7.8) | 0.30% | — | Microsoft Windows Admin Center | 14/7/2026 | 17/7/2026 | Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.30% | — | Microsoft Windows Admin Center | 14/7/2026 | 21/7/2026 | Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally. | |
| Analizada | Media (6.5) | 0.84% | — | Microsoft Windows Admin Center | 14/7/2026 | 21/7/2026 | Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network. | |
| Analizada | Alta (8.8) | 0.75% | — | Microsoft Windows Admin Center | 14/7/2026 | 21/7/2026 | Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network. | |
| Pendiente de análisis | Alta (8.8) | 0.45% | — | Dell Openmanage Integration FOR Microsoft Windows Admin CenterAIMicrosoft Windows Admin CenterAI | 16/6/2026 | 1/10/2026 | Dell OpenManage Integration with Microsoft Windows Admin Center contains a Remote Code Execution vulnerability in the gateway plugin. A remote authenticated user could potentially exploit this vulnerability to escalate privileges. The malicious user may gain the ability to run arbitrary code remotely. This is a high… | |
| Modificada | Alta (7.8) | 0.37% | — | Microsoft Windows Admin Center | 20/5/2026 | 23/7/2026 | Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Windows Admin Center | 12/5/2026 | 17/6/2026 | Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.3) | 0.63% | — | Microsoft Windows Admin Center | 12/5/2026 | 17/6/2026 | Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Media (6.1) | 0.41% | — | Microsoft Windows Admin Center | 14/4/2026 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.8) | 0.31% | — | Microsoft Windows Admin Center | 10/3/2026 | 17/6/2026 | Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (8.8) | 0.83% | 💥 PoC | Microsoft Windows Admin Center | 17/2/2026 | 17/6/2026 | Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.5) | 0.23% | — | Microsoft Windows Admin Center | 13/1/2026 | 17/6/2026 | Improper verification of cryptographic signature in Windows Admin Center allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft Windows Admin Center | 11/12/2025 | 17/6/2026 | Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges locally. | |
| Analizada | Media (6.2) | 1.1% | — | Microsoft Windows Admin Center | 8/4/2025 | 17/6/2026 | External control of file name or path in Azure Portal Windows Admin Center allows an unauthorized attacker to disclose information locally. | |
| Modificada | Media (6.8) | 1.9% | — | Microsoft Windows Admin Center | 11/7/2023 | 17/6/2026 | Windows Admin Center Spoofing Vulnerability | |
| Modificada | Media (4.3) | 3.0% | — | Microsoft Windows Admin Center | 11/3/2021 | 19/8/2026 | Windows Admin Center Security Feature Bypass Vulnerability | |
| Modificada | Crítica (9.8) | 3.5% | — | Microsoft Windows Admin Center | 9/4/2019 | 17/6/2026 | An elevation of privilege vulnerability exists when Windows Admin Center improperly impersonates operations in certain situations, aka 'Windows Admin Center Elevation of Privilege Vulnerability'. |