Skip to content
Toggle Navigation
Kit ISO 27001
Ingeniería y Consultoría
Recursos
ISO 27001
ISO 27001 – GAP Analysis Tool
Ciberseguridad
Vulnerabilidades CVE
Blog
Contacto
Obtener el Toolkit
Toggle Navigation
Kit ISO 27001
Ingeniería y Consultoría
Recursos
ISO 27001
ISO 27001 – GAP Analysis Tool
Ciberseguridad
Vulnerabilidades CVE
Blog
Contacto
Obtener el Toolkit
Vulnerabilidades CVE
Vulnerabilidades CVE
drmunozcl
2025-06-04T18:44:58-04:00
Vulnerabilidades CVE
A continuación la lista de las últimas vulnerabilidades publicadas por el instituto NIST:
Severidad:
Todas
NONE
LOW
MEDIUM
HIGH
CRITICAL
UNKNOWN
CVE:
Aplicar
Borrar filtros
CVE ID
Publicado
Severidad
CVSS
Descripción
CVE-2026-62803
2026-08-11
HIGH
7.8
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
CVE-2026-62800
2026-08-11
HIGH
8.8
Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.
CVE-2026-62792
2026-08-11
HIGH
8.1
Stack-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
CVE-2026-62788
2026-08-11
HIGH
7.0
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-62785
2026-08-11
HIGH
8.8
Heap-based buffer overflow in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
CVE-2026-62784
2026-08-11
HIGH
8.8
Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network.
CVE-2026-62780
2026-08-11
HIGH
7.0
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-62779
2026-08-11
HIGH
7.8
Use after free in Windows Schannel allows an authorized attacker to elevate privileges locally.
CVE-2026-62770
2026-08-11
HIGH
7.8
Heap-based buffer overflow in Windows Shell allows an authorized attacker to elevate privileges locally.
CVE-2026-62769
2026-08-11
MEDIUM
6.7
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.
CVE-2026-62758
2026-08-11
HIGH
7.8
Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-62752
2026-08-11
HIGH
7.8
Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.
CVE-2026-62751
2026-08-11
HIGH
7.8
Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.
CVE-2026-62749
2026-08-11
HIGH
7.0
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-62747
2026-08-11
HIGH
7.8
Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.
CVE-2026-62741
2026-08-11
HIGH
7.8
Integer underflow (wrap or wraparound) in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
CVE-2026-62736
2026-08-11
HIGH
7.8
Heap-based buffer overflow in Windows DHCP Client allows an authorized attacker to elevate privileges locally.
CVE-2026-62735
2026-08-11
HIGH
7.8
Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
CVE-2026-62733
2026-08-11
HIGH
7.8
Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-62729
2026-08-11
HIGH
7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-62724
2026-08-11
HIGH
7.0
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-62723
2026-08-11
HIGH
7.0
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-62713
2026-08-11
HIGH
7.8
Heap-based buffer overflow in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-62701
2026-08-11
HIGH
7.8
Use after free in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
CVE-2026-62696
2026-08-11
HIGH
7.8
Integer underflow (wrap or wraparound) in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.
CVE-2026-62695
2026-08-11
HIGH
7.8
Heap-based buffer overflow in Windows Storage allows an authorized attacker to elevate privileges locally.
CVE-2026-62688
2026-08-11
HIGH
7.8
Heap-based buffer overflow in Windows MIDI Service Module allows an authorized attacker to elevate privileges locally.
CVE-2026-61939
2026-08-11
HIGH
7.0
Use after free in Winlogon allows an authorized attacker to elevate privileges locally.
CVE-2026-61934
2026-08-11
HIGH
7.8
Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-61927
2026-08-11
HIGH
7.0
Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-61367
2026-08-11
HIGH
7.8
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
CVE-2026-61361
2026-08-11
HIGH
7.0
Use after free in Windows DHCP Client allows an authorized attacker to execute code locally.
CVE-2026-61356
2026-08-11
HIGH
7.8
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
CVE-2026-61355
2026-08-11
HIGH
7.8
Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
CVE-2026-61349
2026-08-11
HIGH
7.8
Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.
CVE-2026-61348
2026-08-11
HIGH
7.0
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-59133
2026-08-11
HIGH
8.8
Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network.
CVE-2026-59127
2026-08-11
HIGH
7.8
Integer overflow or wraparound in Windows Installer allows an authorized attacker to elevate privileges locally.
CVE-2026-59126
2026-08-11
HIGH
7.0
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Event Logging Service allows an authorized attacker to elevate privileges locally.
CVE-2026-59119
2026-08-11
HIGH
7.3
Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
CVE-2026-58651
2026-08-11
HIGH
7.8
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-57105
2026-08-11
HIGH
8.0
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-56174
2026-08-11
HIGH
7.8
Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
CVE-2026-58231
2026-08-11
CRITICAL
10.0
SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable…
CVE-2026-54981
2026-08-11
HIGH
7.8
Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-53413
2026-08-11
HIGH
8.3
Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code execution of another participant via…
CVE-2026-49179
2026-08-11
HIGH
8.8
Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.
CVE-2026-48441
2026-08-11
HIGH
8.6
Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker…
CVE-2026-48412
2026-08-11
LOW
2.7
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker with high privileges could exploit this vulnerability to gain elevated access…
CVE-2026-48409
2026-08-11
HIGH
7.8
Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires…
« Anterior
Página 53 de 4840
Siguiente »
Page load link
Go to Top