Skip to content
Toggle Navigation
Kit ISO 27001
Ingeniería y Consultoría
Recursos
ISO 27001
ISO 27001 – GAP Analysis Tool
Ciberseguridad
Vulnerabilidades CVE
Blog
Contacto
Obtener el Toolkit
Toggle Navigation
Kit ISO 27001
Ingeniería y Consultoría
Recursos
ISO 27001
ISO 27001 – GAP Analysis Tool
Ciberseguridad
Vulnerabilidades CVE
Blog
Contacto
Obtener el Toolkit
Vulnerabilidades CVE
Vulnerabilidades CVE
drmunozcl
2025-06-04T18:44:58-04:00
Vulnerabilidades CVE
A continuación la lista de las últimas vulnerabilidades publicadas por el instituto NIST:
Severidad:
Todas
NONE
LOW
MEDIUM
HIGH
CRITICAL
UNKNOWN
CVE:
Aplicar
Borrar filtros
CVE ID
Publicado
Severidad
CVSS
Descripción
CVE-2026-68809
2026-08-11
MEDIUM
5.5
Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
CVE-2026-66146
2026-08-11
MEDIUM
6.1
Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions that allow a remote attacker to execute javascript script in a user's browser.
CVE-2026-65777
2026-08-11
MEDIUM
5.3
Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature over a network.
CVE-2026-65769
2026-08-11
MEDIUM
6.5
Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network.
CVE-2026-65660
2026-08-11
MEDIUM
6.5
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-65655
2026-08-11
N/A
0.0
When OAuth authentication is enabled and browser-facing TLS terminates at a reverse proxy that forwards the callback to Temporal UI Server over HTTP, affected versions derive authentication-cookie Secure…
CVE-2026-64899
2026-08-11
MEDIUM
5.5
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-63177
2026-08-11
HIGH
7.1
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Nginx OpenResty Lua layer evaluates the raw, unnormalized `ngx.var.request_uri`, while…
CVE-2026-63134
2026-08-11
MEDIUM
5.4
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction with libarchive's secure flags, but creates directory entries with a raw `os.makedirs(os.path.join(dest,…
CVE-2026-63531
2026-08-11
MEDIUM
5.5
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-62915
2026-08-11
MEDIUM
6.5
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.
CVE-2026-62900
2026-08-11
MEDIUM
5.9
Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.
CVE-2026-62837
2026-08-11
MEDIUM
6.5
Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
CVE-2026-62798
2026-08-11
MEDIUM
5.5
Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally.
CVE-2026-62775
2026-08-11
MEDIUM
5.5
Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally.
CVE-2026-62702
2026-08-11
MEDIUM
6.8
Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.
CVE-2026-61928
2026-08-11
MEDIUM
5.5
Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.
CVE-2026-55676
2026-08-11
HIGH
8.8
Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and stores them in a directory served by the…
CVE-2026-50516
2026-08-11
CRITICAL
9.4
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-48762
2026-08-11
MEDIUM
5.4
TypeBot is a chatbot builder tool. Prior to version 3.16.0, the OpenAI "Create Transcription" action handler fetches a user-supplied audio URL using `fetch()` without applying the SSRF protection…
CVE-2026-18844
2026-08-11
HIGH
8.1
The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface. These commands are sent without authentication or encryption, and are never…
CVE-2026-18712
2026-08-11
HIGH
8.1
An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileges on one encrypted collection to cause unauthorized modification or destruction of data…
CVE-2026-18711
2026-08-11
HIGH
7.1
An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileges to cause an internal reference to be used after the…
CVE-2026-18709
2026-08-11
MEDIUM
6.4
An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improperly commit or abort an in-progress prepared transaction, bypassing the…
CVE-2026-18708
2026-08-11
MEDIUM
6.4
An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to cause code they control to be executed within the query scope…
CVE-2026-18707
2026-08-11
MEDIUM
4.3
An issue in MongoDB Server could allow an authenticated user, including one with no assigned privileges, to cause the server process to terminate unexpectedly by submitting a specially…
CVE-2026-18706
2026-08-11
MEDIUM
6.6
An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation and memory-management commands to cause an internal reference to be used…
CVE-2026-18705
2026-08-11
MEDIUM
6.5
An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view to retrieve documents from a different, protected view…
CVE-2026-18704
2026-08-11
MEDIUM
6.5
An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perform write operations against collections they should not be able to…
CVE-2026-18703
2026-08-11
MEDIUM
4.2
An issue in MongoDB Server could allow a party with a valid client certificate and a corresponding user account to authenticate using a certificate-based authentication method, even when…
CVE-2026-18702
2026-08-11
MEDIUM
6.4
An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modify diagnostic logging settings that affect the entire server rather than just the…
CVE-2026-18701
2026-08-11
MEDIUM
6.5
An issue in MongoDB Server's query subsystem could allow an authenticated user with read privileges to cause the server process to terminate unexpectedly by submitting a specially formed…
CVE-2026-18700
2026-08-11
MEDIUM
6.5
An issue in MongoDB Server's geospatial validation could allow an authenticated user with write privileges to cause an internal reference to be used after the underlying memory has…
CVE-2026-18699
2026-08-11
MEDIUM
6.5
An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cause the server process to terminate unexpectedly by submitting a specially formed…
CVE-2026-18698
2026-08-11
MEDIUM
5.4
An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that should require more specific…
CVE-2026-18697
2026-08-11
HIGH
7.5
An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) process to terminate unexpectedly by submitting a specially formed aggregation command.…
CVE-2026-18696
2026-08-11
MEDIUM
6.5
An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against…
CVE-2026-18695
2026-08-11
MEDIUM
6.5
An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaField could allow an authenticated user with write access to cause the server…
CVE-2026-18694
2026-08-11
HIGH
7.1
An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges to cause certain malformed geometry data to be stored and later processed…
CVE-2026-18693
2026-08-11
HIGH
7.6
An issue in MongoDB Server's handling of timeseries collections could allow an authenticated user with write privileges to cause an internal data structure to become inconsistent through certain…
CVE-2026-18692
2026-08-11
HIGH
8.8
An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privileges to cause an internal reference to be used after the…
CVE-2026-18691
2026-08-11
HIGH
8.8
An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechanism is used when one replica set member…
CVE-2026-18690
2026-08-11
HIGH
8.1
An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that their assigned privileges should…
CVE-2026-18688
2026-08-11
HIGH
7.1
An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory read by providing a specially formed numeric parameter in a certain…
CVE-2026-18687
2026-08-11
HIGH
7.1
MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection's encrypted field configuration before use. An authenticated user with…
CVE-2026-16230
2026-08-11
CRITICAL
9.8
The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file function in all versions up to, and…
CVE-2026-15563
2026-08-11
HIGH
7.4
A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a…
CVE-2026-15562
2026-08-11
HIGH
7.5
A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and complete an Upgrade: jboss-remoting handshake can cause OOM…
CVE-2026-15561
2026-08-11
HIGH
7.5
A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the…
CVE-2026-15560
2026-08-11
HIGH
8.1
when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes…
« Anterior
Página 56 de 4840
Siguiente »
Page load link
Go to Top