Vulnerabilidades CVE

A continuación la lista de las últimas vulnerabilidades publicadas por el instituto NIST:

Borrar filtros
CVE ID Publicado Severidad CVSS Descripción
CVE-2026-68809 2026-08-11 MEDIUM 5.5 Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
CVE-2026-66146 2026-08-11 MEDIUM 6.1 Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions that allow a remote attacker to execute javascript script in a user's browser.
CVE-2026-65777 2026-08-11 MEDIUM 5.3 Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature over a network.
CVE-2026-65769 2026-08-11 MEDIUM 6.5 Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network.
CVE-2026-65660 2026-08-11 MEDIUM 6.5 Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-65655 2026-08-11 N/A 0.0 When OAuth authentication is enabled and browser-facing TLS terminates at a reverse proxy that forwards the callback to Temporal UI Server over HTTP, affected versions derive authentication-cookie Secure…
CVE-2026-64899 2026-08-11 MEDIUM 5.5 Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-63177 2026-08-11 HIGH 7.1 Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Nginx OpenResty Lua layer evaluates the raw, unnormalized `ngx.var.request_uri`, while…
CVE-2026-63134 2026-08-11 MEDIUM 5.4 Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction with libarchive's secure flags, but creates directory entries with a raw `os.makedirs(os.path.join(dest,…
CVE-2026-63531 2026-08-11 MEDIUM 5.5 Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-62915 2026-08-11 MEDIUM 6.5 Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.
CVE-2026-62900 2026-08-11 MEDIUM 5.9 Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.
CVE-2026-62837 2026-08-11 MEDIUM 6.5 Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
CVE-2026-62798 2026-08-11 MEDIUM 5.5 Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally.
CVE-2026-62775 2026-08-11 MEDIUM 5.5 Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally.
CVE-2026-62702 2026-08-11 MEDIUM 6.8 Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.
CVE-2026-61928 2026-08-11 MEDIUM 5.5 Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.
CVE-2026-55676 2026-08-11 HIGH 8.8 Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and stores them in a directory served by the…
CVE-2026-50516 2026-08-11 CRITICAL 9.4 Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-48762 2026-08-11 MEDIUM 5.4 TypeBot is a chatbot builder tool. Prior to version 3.16.0, the OpenAI "Create Transcription" action handler fetches a user-supplied audio URL using `fetch()` without applying the SSRF protection…
CVE-2026-18844 2026-08-11 HIGH 8.1 The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface. These commands are sent without authentication or encryption, and are never…
CVE-2026-18712 2026-08-11 HIGH 8.1 An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileges on one encrypted collection to cause unauthorized modification or destruction of data…
CVE-2026-18711 2026-08-11 HIGH 7.1 An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileges to cause an internal reference to be used after the…
CVE-2026-18709 2026-08-11 MEDIUM 6.4 An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improperly commit or abort an in-progress prepared transaction, bypassing the…
CVE-2026-18708 2026-08-11 MEDIUM 6.4 An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to cause code they control to be executed within the query scope…
CVE-2026-18707 2026-08-11 MEDIUM 4.3 An issue in MongoDB Server could allow an authenticated user, including one with no assigned privileges, to cause the server process to terminate unexpectedly by submitting a specially…
CVE-2026-18706 2026-08-11 MEDIUM 6.6 An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation and memory-management commands to cause an internal reference to be used…
CVE-2026-18705 2026-08-11 MEDIUM 6.5 An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view to retrieve documents from a different, protected view…
CVE-2026-18704 2026-08-11 MEDIUM 6.5 An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perform write operations against collections they should not be able to…
CVE-2026-18703 2026-08-11 MEDIUM 4.2 An issue in MongoDB Server could allow a party with a valid client certificate and a corresponding user account to authenticate using a certificate-based authentication method, even when…
CVE-2026-18702 2026-08-11 MEDIUM 6.4 An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modify diagnostic logging settings that affect the entire server rather than just the…
CVE-2026-18701 2026-08-11 MEDIUM 6.5 An issue in MongoDB Server's query subsystem could allow an authenticated user with read privileges to cause the server process to terminate unexpectedly by submitting a specially formed…
CVE-2026-18700 2026-08-11 MEDIUM 6.5 An issue in MongoDB Server's geospatial validation could allow an authenticated user with write privileges to cause an internal reference to be used after the underlying memory has…
CVE-2026-18699 2026-08-11 MEDIUM 6.5 An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cause the server process to terminate unexpectedly by submitting a specially formed…
CVE-2026-18698 2026-08-11 MEDIUM 5.4 An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that should require more specific…
CVE-2026-18697 2026-08-11 HIGH 7.5 An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) process to terminate unexpectedly by submitting a specially formed aggregation command.…
CVE-2026-18696 2026-08-11 MEDIUM 6.5 An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against…
CVE-2026-18695 2026-08-11 MEDIUM 6.5 An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaField could allow an authenticated user with write access to cause the server…
CVE-2026-18694 2026-08-11 HIGH 7.1 An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges to cause certain malformed geometry data to be stored and later processed…
CVE-2026-18693 2026-08-11 HIGH 7.6 An issue in MongoDB Server's handling of timeseries collections could allow an authenticated user with write privileges to cause an internal data structure to become inconsistent through certain…
CVE-2026-18692 2026-08-11 HIGH 8.8 An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privileges to cause an internal reference to be used after the…
CVE-2026-18691 2026-08-11 HIGH 8.8 An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechanism is used when one replica set member…
CVE-2026-18690 2026-08-11 HIGH 8.1 An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that their assigned privileges should…
CVE-2026-18688 2026-08-11 HIGH 7.1 An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory read by providing a specially formed numeric parameter in a certain…
CVE-2026-18687 2026-08-11 HIGH 7.1 MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection's encrypted field configuration before use. An authenticated user with…
CVE-2026-16230 2026-08-11 CRITICAL 9.8 The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file function in all versions up to, and…
CVE-2026-15563 2026-08-11 HIGH 7.4 A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a…
CVE-2026-15562 2026-08-11 HIGH 7.5 A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and complete an Upgrade: jboss-remoting handshake can cause OOM…
CVE-2026-15561 2026-08-11 HIGH 7.5 A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the…
CVE-2026-15560 2026-08-11 HIGH 8.1 when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes…
« Anterior Página 56 de 4840 Siguiente »