Skip to content
Toggle Navigation
Kit ISO 27001
Ingeniería y Consultoría
Recursos
ISO 27001
ISO 27001 – GAP Analysis Tool
Ciberseguridad
Vulnerabilidades CVE
Blog
Contacto
Obtener el Toolkit
Toggle Navigation
Kit ISO 27001
Ingeniería y Consultoría
Recursos
ISO 27001
ISO 27001 – GAP Analysis Tool
Ciberseguridad
Vulnerabilidades CVE
Blog
Contacto
Obtener el Toolkit
Vulnerabilidades CVE
Vulnerabilidades CVE
drmunozcl
2025-06-04T18:44:58-04:00
Vulnerabilidades CVE
A continuación la lista de las últimas vulnerabilidades publicadas por el instituto NIST:
Severidad:
Todas
NONE
LOW
MEDIUM
HIGH
CRITICAL
UNKNOWN
CVE:
Aplicar
Borrar filtros
CVE ID
Publicado
Severidad
CVSS
Descripción
CVE-2026-67287
2026-08-12
N/A
0.0
Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on instances with disabled guest commenting by…
CVE-2026-66379
2026-08-12
MEDIUM
4.3
An authenticated user may view private Puppet module metadata without repository read access.
CVE-2026-66378
2026-08-12
MEDIUM
4.3
An authenticated user without repository read permission may access private NuGet metadata under specific conditions.
CVE-2026-66377
2026-08-12
MEDIUM
5.3
An unauthenticated user may access restricted repository information under specific conditions.
CVE-2026-66154
2026-08-11
HIGH
8.3
An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044) and earlier versions which, under a successful MitM attack and…
CVE-2026-66147
2026-08-11
CRITICAL
9.4
An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through…
CVE-2026-66145
2026-08-11
CRITICAL
9.1
An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file…
CVE-2026-65813
2026-08-11
MEDIUM
6.5
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-65673
2026-08-11
HIGH
7.8
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Entra Connect Sync allows an authorized attacker to elevate privileges locally.
CVE-2026-63516
2026-08-11
MEDIUM
6.5
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-63512
2026-08-11
MEDIUM
6.5
Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.
CVE-2026-62878
2026-08-11
CRITICAL
9.8
Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
CVE-2026-62757
2026-08-11
MEDIUM
5.3
Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-62699
2026-08-11
MEDIUM
6.8
Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to execute code with a physical attack.
CVE-2026-61346
2026-08-11
HIGH
7.0
Use after free in Windows Graphics Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-59130
2026-08-11
MEDIUM
5.6
No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.
CVE-2026-58650
2026-08-11
HIGH
7.8
Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-50561
2026-08-12
CRITICAL
9.4
Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent development platform. Prior to version 0.6.2, the project's authentication mechanism contains a flaw. In affected versions, the…
CVE-2026-54113
2026-08-11
HIGH
7.5
Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.
CVE-2026-49349
2026-08-12
MEDIUM
6.8
regclient is a Docker and OCI Registry Client in Go. Prior to version 0.11.5, credentials for a registry may be inadvertently leaked to external servers. A prerequisite for…
CVE-2026-48446
2026-08-11
MEDIUM
5.5
CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An…
CVE-2026-48444
2026-08-11
MEDIUM
6.2
CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the…
CVE-2026-48439
2026-08-11
HIGH
7.5
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting…
CVE-2026-48437
2026-08-11
MEDIUM
5.5
CAI Content Credentials is affected by an Improper Certificate Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security…
CVE-2026-48434
2026-08-11
MEDIUM
6.2
CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting…
CVE-2026-48384
2026-08-11
MEDIUM
4.9
ColdFusion is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker with high privileges could exploit this vulnerability to crash the…
CVE-2026-48375
2026-08-11
MEDIUM
6.5
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in an application denial-of-service. A low-privileged attacker could exploit this vulnerability to crash the application, leading to…
CVE-2026-47922
2026-08-11
MEDIUM
4.7
CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue requires user interaction in that a…
CVE-2026-47299
2026-08-11
HIGH
7.2
Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network.
CVE-2026-47285
2026-08-11
MEDIUM
6.5
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose information over a network.
CVE-2026-47233
2026-08-12
MEDIUM
6.5
Admidio is an open-source user management solution. Version 5.0.9 added a missing `isAdministratorInventory()` gate to `case 'item_delete':` in `modules/inventory.php`. The same fix was not applied to the sibling…
CVE-2026-39452
2026-08-11
N/A
0.0
Protection mechanism failure for some Intel(R) Transfer Learning Tool before version v0.7 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an…
CVE-2026-35502
2026-08-11
N/A
0.0
Deserialization of untrusted data for some Intel(R) Extension for PyTorch before version 2.8.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with…
CVE-2026-34175
2026-08-11
N/A
0.0
Uncontrolled search path for some Hardware-Aware-Automated-MachineLearning NA before version 45cd723 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user…
CVE-2026-32791
2026-08-11
N/A
0.0
Untrusted search path for some Intel(R) Performance Counter Monitor (Intel(R) PCM) before version tag 202604 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software…
CVE-2026-21273
2026-08-11
HIGH
8.7
is affected by an Improper Input Validation vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain unauthorized read and write access.…
CVE-2026-20898
2026-08-11
N/A
0.0
Improper access control in the firmware for some in Alias Checking Trusted Module for some Intel(R) Xeon(R) processors may allow an escalation of privilege. Startup code and SMM…
CVE-2025-59324
2026-08-12
N/A
0.0
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped.
CVE-2026-11814
2026-08-11
N/A
0.0
A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality…
CVE-2025-59323
2026-08-12
N/A
0.0
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataStore, a non-partitioned filesystem, responsible for storing configuration and cryptographic details. Crafted DataStore…
CVE-2025-59322
2026-08-12
N/A
0.0
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted volumes to be mounted as plaintext.
CVE-2025-59321
2026-08-12
N/A
0.0
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider the system boot state. This allows the TPM to be…
CVE-2026-20349
2026-08-11
HIGH
8.6
A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow…
CVE-2026-68820
2026-08-11
HIGH
7.0
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-73248
2026-08-11
N/A
0.0
calibre is an e-book manager. Prior to 9.12.0, calibre processes attacker-controlled composite_template metadata from a malicious EPUB, OPF, PDF, or similar file through program: and a nested template()…
CVE-2026-71408
2026-08-12
MEDIUM
5.3
A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions may allow attacker to denial…
CVE-2026-73242
2026-08-11
N/A
0.0
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos/kerberos.c kerberos_DecryptMessage function fails to bound the peer-controlled GSS Wrap-token EC field before using…
CVE-2026-73232
2026-08-11
HIGH
7.5
ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a malicious target server to cause an out-of-memory denial of service because the response…
CVE-2026-73036
2026-08-11
MEDIUM
4.4
Bash-it 3.2.0 contains a terminal escape sequence injection vulnerability in the barbuk theme's Python virtualenv prompt segment that allows local attackers to inject arbitrary terminal control sequences by…
CVE-2026-71474
2026-08-11
MEDIUM
6.3
A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.openshift.com pull-secret token. A local user…
« Anterior
Página 45 de 4839
Siguiente »
Page load link
Go to Top