Vulnerabilidades CVE

A continuación la lista de las últimas vulnerabilidades publicadas por el instituto NIST:

Borrar filtros
CVE ID Publicado Severidad CVSS Descripción
CVE-2026-65658 2026-08-11 HIGH 8.8 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-65656 2026-08-11 HIGH 7.8 Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-64920 2026-08-11 HIGH 7.8 Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
CVE-2026-64914 2026-08-11 HIGH 7.8 Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
CVE-2026-64910 2026-08-11 HIGH 7.8 Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-64908 2026-08-11 HIGH 7.8 Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
CVE-2026-64905 2026-08-11 HIGH 7.8 Buffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-64903 2026-08-11 HIGH 7.8 Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-64898 2026-08-11 HIGH 7.8 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-63532 2026-08-11 HIGH 7.8 Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-63527 2026-08-11 HIGH 7.8 Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-63133 2026-08-11 MEDIUM 6.5 Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` extracts uploaded archives with no limit on entry count, directory depth, total entries, or output…
CVE-2026-63525 2026-08-11 HIGH 7.8 Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-63519 2026-08-11 HIGH 7.8 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-63517 2026-08-11 MEDIUM 5.5 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-63514 2026-08-11 HIGH 8.8 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-62914 2026-08-11 HIGH 7.3 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
CVE-2026-62912 2026-08-11 MEDIUM 6.5 Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.
CVE-2026-62911 2026-08-11 HIGH 8.0 Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-62909 2026-08-11 HIGH 7.8 Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.
CVE-2026-62902 2026-08-11 MEDIUM 6.5 Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.
CVE-2026-62899 2026-08-11 MEDIUM 5.9 Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network.
CVE-2026-62897 2026-08-11 HIGH 7.0 Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2026-62894 2026-08-11 HIGH 7.8 Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2026-62892 2026-08-11 HIGH 7.0 Use after free in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.
CVE-2026-62889 2026-08-11 HIGH 8.1 Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
CVE-2026-62888 2026-08-11 HIGH 7.8 Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2026-62886 2026-08-11 HIGH 7.8 Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
CVE-2026-62880 2026-08-11 HIGH 7.8 Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-62877 2026-08-11 HIGH 7.8 Stack-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-62876 2026-08-11 HIGH 7.8 Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-62871 2026-08-11 HIGH 7.8 Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-62832 2026-08-11 HIGH 7.8 Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.
CVE-2026-62827 2026-08-11 HIGH 8.8 Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
CVE-2026-62824 2026-08-11 HIGH 8.8 Stack-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-62822 2026-08-11 HIGH 8.8 Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network.
CVE-2026-62819 2026-08-11 HIGH 8.1 Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
CVE-2026-62818 2026-08-11 HIGH 8.8 Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network.
CVE-2026-62816 2026-08-11 HIGH 8.8 Heap-based buffer overflow in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over an adjacent network.
CVE-2026-62812 2026-08-11 HIGH 7.8 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
CVE-2026-62807 2026-08-11 HIGH 7.8 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
CVE-2026-62799 2026-08-11 HIGH 7.8 Heap-based buffer overflow in Windows SMB Client allows an authorized attacker to elevate privileges locally.
CVE-2026-62797 2026-08-11 HIGH 7.8 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
CVE-2026-62795 2026-08-11 HIGH 8.8 Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
CVE-2026-62790 2026-08-11 HIGH 8.8 Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.
CVE-2026-62787 2026-08-11 HIGH 7.5 Use after free in Windows DNS allows an authorized attacker to execute code over a network.
CVE-2026-62783 2026-08-11 HIGH 7.8 Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-62778 2026-08-11 HIGH 8.1 Use after free in Windows DNS allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-62777 2026-08-11 HIGH 7.8 Missing authentication for critical function in Windows License Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-62776 2026-08-11 HIGH 7.8 Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
« Anterior Página 47 de 4839 Siguiente »