Vulnerabilidades CVE

A continuación la lista de las últimas vulnerabilidades publicadas por el instituto NIST:

Borrar filtros
CVE ID Publicado Severidad CVSS Descripción
CVE-2026-71386 2026-08-11 HIGH 8.8 is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability…
CVE-2026-71362 2026-08-11 CRITICAL 9.1 Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources.…
CVE-2026-70355 2026-08-11 HIGH 7.3 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
CVE-2026-70348 2026-08-11 MEDIUM 5.5 Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally.
CVE-2026-70339 2026-08-11 MEDIUM 5.4 Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
CVE-2026-70346 2026-08-11 HIGH 7.8 Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-70340 2026-08-11 HIGH 8.1 Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
CVE-2026-70330 2026-08-11 MEDIUM 6.7 Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-70328 2026-08-11 MEDIUM 6.5 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
CVE-2026-70323 2026-08-11 MEDIUM 5.5 Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-70318 2026-08-11 MEDIUM 5.5 Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-70313 2026-08-11 HIGH 7.8 Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
CVE-2026-69320 2026-08-11 HIGH 8.8 Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
CVE-2026-69278 2026-08-11 HIGH 7.8 Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-68819 2026-08-11 MEDIUM 5.9 Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.
CVE-2026-68816 2026-08-11 HIGH 7.8 Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68815 2026-08-11 HIGH 7.8 Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68811 2026-08-11 HIGH 7.8 Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68810 2026-08-11 HIGH 7.8 Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68806 2026-08-11 HIGH 7.8 Out-of-bounds write in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68805 2026-08-11 HIGH 7.8 Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68803 2026-08-11 HIGH 7.8 Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68796 2026-08-11 HIGH 7.8 Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68067 2026-08-11 CRITICAL 9.8 The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the…
CVE-2026-67568 2026-08-11 CRITICAL 9.1 The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which could result in forgery, deletion, or destruction of…
CVE-2026-66832 2026-08-11 MEDIUM 6.5 When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is appended to the URL as a query string parameter,…
CVE-2026-68795 2026-08-11 HIGH 7.8 Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68792 2026-08-11 HIGH 7.8 Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2026-66340 2026-08-11 MEDIUM 5.3 The Mira cloud authentication endpoints do not enforce per-account rate limiting, per-IP throttling, or account lockout after repeated failed login attempts. An attacker can use brute-force methods to…
CVE-2026-65815 2026-08-11 HIGH 8.8 Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
CVE-2026-65814 2026-08-11 HIGH 7.8 Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-65810 2026-08-11 HIGH 7.8 Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.
CVE-2026-65807 2026-08-11 HIGH 8.8 Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.
CVE-2026-65797 2026-08-11 MEDIUM 6.7 Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-65795 2026-08-11 MEDIUM 6.7 No cwe for this issue in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-65790 2026-08-11 HIGH 7.8 Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
CVE-2026-65789 2026-08-11 HIGH 8.1 Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
CVE-2026-65788 2026-08-11 HIGH 7.0 Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-65785 2026-08-11 MEDIUM 6.5 Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network.
CVE-2026-65784 2026-08-11 MEDIUM 5.5 Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
CVE-2026-65780 2026-08-11 HIGH 7.0 Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
CVE-2026-65776 2026-08-11 HIGH 7.0 Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-65680 2026-08-11 MEDIUM 6.7 Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally.
CVE-2026-65773 2026-08-11 HIGH 7.8 Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-65768 2026-08-11 HIGH 8.8 Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.
CVE-2026-65675 2026-08-11 HIGH 7.1 No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-65664 2026-08-11 HIGH 7.8 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-64934 2026-08-11 MEDIUM 4.3 The Mira cloud API accepts the firmware version reported by the companion app as authoritative for a given device, without independently attesting the version from the device itself.…
CVE-2026-65662 2026-08-11 MEDIUM 5.5 Out-of-bounds read in Windows GDI allows an authorized attacker to disclose information locally.
CVE-2026-65661 2026-08-11 HIGH 7.8 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
« Anterior Página 46 de 4839 Siguiente »