Vulnerabilidades CVE

A continuación la lista de las últimas vulnerabilidades publicadas por el instituto NIST:

Borrar filtros
CVE ID Publicado Severidad CVSS Descripción
CVE-2026-65679 2026-08-11 HIGH 8.1 Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
CVE-2026-65671 2026-08-11 HIGH 7.8 Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.
CVE-2026-63530 2026-08-11 MEDIUM 5.5 Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-62908 2026-08-11 HIGH 7.0 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.
CVE-2026-62887 2026-08-11 MEDIUM 5.5 Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
CVE-2026-62814 2026-08-11 MEDIUM 6.5 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
CVE-2026-62796 2026-08-11 MEDIUM 5.5 Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
CVE-2026-62793 2026-08-11 MEDIUM 5.5 Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
CVE-2026-62786 2026-08-11 MEDIUM 5.5 Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
CVE-2026-62781 2026-08-11 HIGH 8.1 Heap-based buffer overflow in RPC Runtime allows an unauthorized attacker to execute code over a network.
CVE-2026-62746 2026-08-11 MEDIUM 5.5 Buffer over-read in Windows Win32K allows an authorized attacker to disclose information locally.
CVE-2026-62745 2026-08-11 MEDIUM 6.5 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
CVE-2026-62743 2026-08-11 MEDIUM 5.5 Out-of-bounds read in Windows Win32K allows an authorized attacker to disclose information locally.
CVE-2026-62742 2026-08-11 MEDIUM 6.5 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
CVE-2026-62740 2026-08-11 MEDIUM 5.5 Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.
CVE-2026-62738 2026-08-11 MEDIUM 5.5 Out-of-bounds read in Windows Management Instrumentation allows an authorized attacker to disclose information locally.
CVE-2026-62730 2026-08-11 MEDIUM 5.5 Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.
CVE-2026-62720 2026-08-11 MEDIUM 6.5 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
CVE-2026-62719 2026-08-11 HIGH 7.8 Heap-based buffer overflow in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
CVE-2026-62718 2026-08-11 MEDIUM 6.5 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
CVE-2026-62715 2026-08-11 MEDIUM 6.5 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
CVE-2026-62714 2026-08-11 MEDIUM 6.5 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
CVE-2026-62709 2026-08-11 MEDIUM 5.5 Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.
CVE-2026-62698 2026-08-11 HIGH 7.8 Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally.
CVE-2026-61924 2026-08-11 MEDIUM 6.5 Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-61921 2026-08-11 MEDIUM 6.5 Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
CVE-2026-61366 2026-08-11 HIGH 7.0 Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.
CVE-2026-61360 2026-08-11 MEDIUM 5.5 Untrusted pointer dereference in Windows GDI allows an authorized attacker to disclose information locally.
CVE-2026-61350 2026-08-11 MEDIUM 4.6 Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
CVE-2026-61347 2026-08-11 MEDIUM 5.5 Buffer over-read in Windows Event Logging Service allows an authorized attacker to disclose information locally.
CVE-2026-61345 2026-08-11 MEDIUM 6.5 Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.
CVE-2026-59138 2026-08-11 MEDIUM 6.5 Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.
CVE-2026-59137 2026-08-11 MEDIUM 5.5 Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.
CVE-2026-59136 2026-08-11 MEDIUM 5.5 Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.
CVE-2026-59135 2026-08-11 MEDIUM 5.5 Weak authentication in Microsoft Windows Search Component allows an authorized attacker to disclose information locally.
CVE-2026-59132 2026-08-11 HIGH 7.5 Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network.
CVE-2026-59131 2026-08-11 MEDIUM 5.6 No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.
CVE-2026-59128 2026-08-11 MEDIUM 5.5 Out-of-bounds read in Windows Encrypting File System (EFS) allows an authorized attacker to disclose information locally.
CVE-2026-58612 2026-08-11 HIGH 7.4 Server-side request forgery (ssrf) in Microsoft PowerShell Core allows an unauthorized attacker to disclose information over a network.
CVE-2026-40375 2026-08-11 MEDIUM 6.5 Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.
CVE-2026-29036 2026-08-11 HIGH 7.5 cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointer_inplace() function within cJSON_Utils.c that allows unauthenticated attackers to cause JSON Patch operations to…
CVE-2026-19579 2026-08-11 MEDIUM 5.4 Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The cancel_by_admin and requestingUser values are read from user-controlled URL path…
CVE-2026-73283 2026-08-11 LOW 2.5 In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.
CVE-2026-73282 2026-08-11 MEDIUM 4.8 In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.
CVE-2026-73281 2026-08-11 LOW 3.5 In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is…
CVE-2026-73243 2026-08-11 MEDIUM 5.8 kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated GET /addTask endpoint in kkFileView is omitted from TrustHostFilter and TrustDirFilter…
CVE-2026-71290 2026-08-11 N/A 0.0 Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can…
CVE-2026-73233 2026-08-11 N/A 0.0 FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the FEM Displacement Constraint task dialog in src/Mod/Fem/Gui/TaskFemConstraintDisplacement.cpp passes the xDisplacementFormula, yDisplacementFormula, and zDisplacementFormula fields…
CVE-2026-71467 2026-08-11 HIGH 7.5 A flaw was found in search-v2-api. The authentication middleware in the affected component unconditionally skips authentication when a request includes an `Upgrade: websocket` header. An unauthenticated attacker can…
CVE-2026-70316 2026-08-11 MEDIUM 5.5 Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
« Anterior Página 55 de 4840 Siguiente »