Vulnerabilidades CVE

A continuación la lista de las últimas vulnerabilidades publicadas por el instituto NIST:

Borrar filtros
CVE ID Publicado Severidad CVSS Descripción
CVE-2026-11735 2026-08-11 N/A 0.0 A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality.
CVE-2026-11734 2026-08-11 N/A 0.0 A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable.
CVE-2026-11733 2026-08-11 N/A 0.0 A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the normal operation of the affected device.
CVE-2025-41769 2026-08-12 CRITICAL 9.8 The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the…
CVE-2026-14857 2026-08-12 N/A 0.0 The WP Crowdfunding WordPress plugin before 2.2.1 does not verify ownership of a campaign before allowing its update history to be modified and a notification email sent to…
CVE-2026-13612 2026-08-12 N/A 0.0 The KiviCare WordPress plugin before 4.5.2 does not verify that the requesting user owns the records being accessed, allowing authenticated patient-level users to read other patients' bills, invoices…
CVE-2026-13177 2026-08-12 N/A 0.0 The Eventin WordPress plugin before 4.1.20 does not properly restrict access to individual order records, allowing users with contributor-level access and above to read other customers' order data…
CVE-2026-71387 2026-08-11 HIGH 8.8 ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability…
CVE-2026-71331 2026-08-11 HIGH 8.1 Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.
CVE-2026-70338 2026-08-11 HIGH 7.8 Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-70337 2026-08-11 HIGH 8.8 Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.
CVE-2026-70329 2026-08-11 HIGH 8.8 Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
CVE-2026-70326 2026-08-11 HIGH 8.8 Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
CVE-2026-70324 2026-08-11 HIGH 8.8 Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
CVE-2026-70321 2026-08-11 HIGH 8.8 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-70307 2026-08-11 HIGH 7.0 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-70130 2026-08-11 HIGH 8.4 Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-68817 2026-08-11 HIGH 7.8 Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68814 2026-08-11 HIGH 7.8 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68812 2026-08-11 HIGH 7.8 Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68807 2026-08-11 HIGH 7.8 Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68804 2026-08-11 HIGH 7.8 Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68794 2026-08-11 HIGH 7.8 Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-68793 2026-08-11 HIGH 7.8 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-66808 2026-08-11 HIGH 8.8 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-66807 2026-08-11 HIGH 7.8 Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-66805 2026-08-11 HIGH 8.8 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-66802 2026-08-11 HIGH 8.1 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over…
CVE-2026-66150 2026-08-11 HIGH 7.8 Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI…
CVE-2026-66149 2026-08-11 HIGH 7.8 Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI…
CVE-2026-65811 2026-08-11 HIGH 8.8 Improper input validation in Power BI allows an authorized attacker to execute code over a network.
CVE-2026-65799 2026-08-11 MEDIUM 6.7 Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-65798 2026-08-11 MEDIUM 6.7 Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-65791 2026-08-11 CRITICAL 9.8 Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
CVE-2026-65787 2026-08-11 HIGH 7.8 Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-65786 2026-08-11 HIGH 7.8 Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-65775 2026-08-11 HIGH 7.8 Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-65774 2026-08-11 HIGH 7.8 Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-65678 2026-08-11 HIGH 7.0 Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-65665 2026-08-11 HIGH 8.8 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-65663 2026-08-11 HIGH 8.8 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-65657 2026-08-11 HIGH 7.8 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-64954 2026-08-12 HIGH 8.2 Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced…
CVE-2026-64921 2026-08-11 HIGH 8.8 Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
CVE-2026-64919 2026-08-11 HIGH 7.8 Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
CVE-2026-64915 2026-08-11 HIGH 7.8 Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-64912 2026-08-11 HIGH 7.8 Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
CVE-2026-64911 2026-08-11 HIGH 7.8 Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-64909 2026-08-11 HIGH 7.8 Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-64907 2026-08-11 HIGH 7.8 Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
« Anterior Página 51 de 4839 Siguiente »