Skip to content
Toggle Navigation
Kit ISO 27001
Ingeniería y Consultoría
Recursos
ISO 27001
ISO 27001 – GAP Analysis Tool
Ciberseguridad
Vulnerabilidades CVE
Blog
Contacto
Obtener el Toolkit
Toggle Navigation
Kit ISO 27001
Ingeniería y Consultoría
Recursos
ISO 27001
ISO 27001 – GAP Analysis Tool
Ciberseguridad
Vulnerabilidades CVE
Blog
Contacto
Obtener el Toolkit
Vulnerabilidades CVE
Vulnerabilidades CVE
drmunozcl
2025-06-04T18:44:58-04:00
Vulnerabilidades CVE
A continuación la lista de las últimas vulnerabilidades publicadas por el instituto NIST:
Severidad:
Todas
NONE
LOW
MEDIUM
HIGH
CRITICAL
UNKNOWN
CVE:
Aplicar
Borrar filtros
CVE ID
Publicado
Severidad
CVSS
Descripción
CVE-2026-66808
2026-08-11
HIGH
8.8
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-66807
2026-08-11
HIGH
7.8
Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-66805
2026-08-11
HIGH
8.8
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-66802
2026-08-11
HIGH
8.1
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over…
CVE-2026-66150
2026-08-11
HIGH
7.8
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI…
CVE-2026-66149
2026-08-11
HIGH
7.8
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI…
CVE-2026-65811
2026-08-11
HIGH
8.8
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
CVE-2026-65799
2026-08-11
MEDIUM
6.7
Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-65798
2026-08-11
MEDIUM
6.7
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-65791
2026-08-11
CRITICAL
9.8
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
CVE-2026-65787
2026-08-11
HIGH
7.8
Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-65786
2026-08-11
HIGH
7.8
Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-65775
2026-08-11
HIGH
7.8
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-65774
2026-08-11
HIGH
7.8
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-65678
2026-08-11
HIGH
7.0
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-65665
2026-08-11
HIGH
8.8
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-65663
2026-08-11
HIGH
8.8
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-65657
2026-08-11
HIGH
7.8
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-64954
2026-08-12
HIGH
8.2
Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced…
CVE-2026-64921
2026-08-11
HIGH
8.8
Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
CVE-2026-64919
2026-08-11
HIGH
7.8
Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
CVE-2026-64915
2026-08-11
HIGH
7.8
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-64912
2026-08-11
HIGH
7.8
Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
CVE-2026-64911
2026-08-11
HIGH
7.8
Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-64909
2026-08-11
HIGH
7.8
Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-64907
2026-08-11
HIGH
7.8
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-64906
2026-08-11
HIGH
7.8
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
CVE-2026-64904
2026-08-11
HIGH
7.8
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-64901
2026-08-11
HIGH
8.8
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-63533
2026-08-11
HIGH
7.8
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-63526
2026-08-11
HIGH
7.8
Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-63522
2026-08-11
HIGH
7.8
Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally.
CVE-2026-63520
2026-08-11
HIGH
8.1
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVE-2026-63518
2026-08-11
HIGH
7.8
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-63515
2026-08-11
HIGH
7.8
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-63513
2026-08-11
HIGH
7.8
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-62913
2026-08-11
HIGH
8.8
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
CVE-2026-62910
2026-08-11
HIGH
7.2
Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-62893
2026-08-11
CRITICAL
9.8
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
CVE-2026-62890
2026-08-11
HIGH
7.8
Heap-based buffer overflow in Windows GDI+ allows an authorized attacker to execute code locally.
CVE-2026-62885
2026-08-11
HIGH
7.8
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-62883
2026-08-11
MEDIUM
6.7
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-62881
2026-08-11
MEDIUM
6.7
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-62872
2026-08-11
HIGH
8.8
Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.
CVE-2026-62869
2026-08-11
HIGH
8.8
Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network.
CVE-2026-62823
2026-08-11
HIGH
8.8
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.
CVE-2026-62820
2026-08-11
HIGH
8.1
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network.
CVE-2026-62817
2026-08-11
HIGH
8.8
Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network.
CVE-2026-62815
2026-08-11
CRITICAL
9.8
Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.
CVE-2026-62811
2026-08-11
HIGH
7.8
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
« Anterior
Página 52 de 4840
Siguiente »
Page load link
Go to Top