Skip to content
Toggle Navigation
Kit ISO 27001
Ingeniería y Consultoría
Recursos
ISO 27001
ISO 27001 – GAP Analysis Tool
Ciberseguridad
Vulnerabilidades CVE
Blog
Contacto
Obtener el Toolkit
Toggle Navigation
Kit ISO 27001
Ingeniería y Consultoría
Recursos
ISO 27001
ISO 27001 – GAP Analysis Tool
Ciberseguridad
Vulnerabilidades CVE
Blog
Contacto
Obtener el Toolkit
Vulnerabilidades CVE
Vulnerabilidades CVE
drmunozcl
2025-06-04T18:44:58-04:00
Vulnerabilidades CVE
A continuación la lista de las últimas vulnerabilidades publicadas por el instituto NIST:
Severidad:
Todas
NONE
LOW
MEDIUM
HIGH
CRITICAL
UNKNOWN
CVE:
Aplicar
Borrar filtros
CVE ID
Publicado
Severidad
CVSS
Descripción
CVE-2026-45618
2026-08-11
CRITICAL
10.0
LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches the issue.
CVE-2026-19091
2026-08-11
HIGH
8.1
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the…
CVE-2026-18860
2026-08-11
HIGH
8.7
Velociraptor allows multi-tenant deployments named "Orgs". By default Velociraptor, uses the ROOT org, but users can create child orgs for other tenants within the same deployment. Users can…
CVE-2026-18636
2026-08-11
MEDIUM
6.8
The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users from reading sensitive files or accessing other orgs, the requested…
CVE-2026-17535
2026-08-11
MEDIUM
6.2
Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by maliciously crafted NTFS images. Typically Velociraptor's NTFS parser is used…
CVE-2026-17061
2026-08-11
CRITICAL
10.0
A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthenticated remote code execution.
CVE-2026-73228
2026-08-11
MEDIUM
5.3
Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing in rest_framework/request.py Request._parse() passes the underlying HttpRequest stream to JSONParser…
CVE-2026-73227
2026-08-11
HIGH
8.1
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious RDP server to write attacker-controlled content outside the selected save directory because the RDP clipboard…
CVE-2026-73224
2026-08-11
HIGH
8.8
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FTP or SFTP server to execute arbitrary commands when a user downloads a crafted folder…
CVE-2026-73223
2026-08-11
HIGH
8.1
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious SFTP server to write attacker-controlled content outside the temporary directory because the server-controlled filename name…
CVE-2026-73222
2026-08-11
HIGH
8.8
Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js…
CVE-2026-73085
2026-08-11
N/A
0.0
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.36.0, the jwtAuthCheck function in server/auth/TokenManager.js treats JWTs with the refresh token type as bearer access tokens on…
CVE-2026-73077
2026-08-11
N/A
0.0
Vim is an open source, command line text editor. Prior to 9.2.0839, the runtime/ftplugin/sh.vim, runtime/ftplugin/zsh.vim, and runtime/ftplugin/ps1.vim filetype plugins pass attacker-controlled Visual-mode selections from K through keywordprg commands…
CVE-2026-73075
2026-08-11
N/A
0.0
Vim is an open source, command line text editor. From 9.2.0469 until 9.2.0843, popup_mark_opacity_zindex() in src/popupwin.c can use a negative w_winrow for a text-property-anchored popup with clipwindow and…
CVE-2026-73069
2026-08-11
CRITICAL
9.1
Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty allowed a workspace administrator with the DATA_MODEL permission to supply settings.asExpression for the system TS_VECTOR…
CVE-2026-72925
2026-08-11
MEDIUM
6.1
SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_minifier 59.0.0, the minifyJson processing in crates/swc_html_minifier/src/lib.rs parsed and serialized attacker-controlled JSON in…
CVE-2026-72713
2026-08-11
HIGH
7.5
XAgent contains a path traversal vulnerability in the workspace file endpoint that allows self-registered or default-credential users to read arbitrary files on the host by supplying parent-directory segments…
CVE-2026-71383
2026-08-11
HIGH
7.3
is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited…
CVE-2026-70335
2026-08-11
HIGH
7.8
Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
CVE-2026-70311
2026-08-11
HIGH
7.8
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-69117
2026-08-11
MEDIUM
6.5
NetBox 4.5.8 contains an ORM injection vulnerability that allows authenticated attackers, including those with read-only API tokens, to inject arbitrary Django ORM lookup expressions into nested object references…
CVE-2026-65782
2026-08-11
HIGH
7.0
Use after free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
CVE-2026-61923
2026-08-11
HIGH
7.8
Heap-based buffer overflow in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.
CVE-2026-48802
2026-08-11
HIGH
7.5
python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an attacker can cause the creation of unnecessary background threads in the…
CVE-2026-48483
2026-08-11
MEDIUM
5.4
TypeBot is a chatbot builder tool. Prior to version 3.17.0, Typebot's WhatsApp status forwarding feature stores a workspace-configured webhook forwarding URL and later POSTs WhatsApp marketing/error status events…
CVE-2026-48381
2026-08-11
CRITICAL
9.0
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution…
CVE-2026-48445
2026-08-11
MEDIUM
6.2
CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the…
CVE-2026-48438
2026-08-11
HIGH
7.5
CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application,…
CVE-2026-48387
2026-08-11
MEDIUM
6.2
CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the…
CVE-2026-48376
2026-08-11
MEDIUM
5.4
is affected by an Improper Encoding or Escaping of Output vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass…
CVE-2026-48056
2026-08-11
CRITICAL
10.0
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 improperly validate executable paths supplied to the run-download IPC handler, allowing…
CVE-2026-21279
2026-08-11
HIGH
8.2
is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain…
CVE-2026-14180
2026-08-11
MEDIUM
5.3
A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding. The issue…
CVE-2026-62882
2026-08-11
MEDIUM
4.3
Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-62703
2026-08-11
MEDIUM
5.5
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
CVE-2026-61936
2026-08-11
MEDIUM
5.5
Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.
CVE-2026-61368
2026-08-11
MEDIUM
5.0
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to disclose information locally.
CVE-2026-61357
2026-08-11
HIGH
7.8
Use after free in Application Information Services allows an authorized attacker to elevate privileges locally.
CVE-2026-56179
2026-08-11
HIGH
8.3
Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network.
CVE-2026-70354
2026-08-11
HIGH
7.8
Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.
CVE-2026-70336
2026-08-11
HIGH
8.8
Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
CVE-2026-70327
2026-08-11
MEDIUM
6.5
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
CVE-2026-70322
2026-08-11
MEDIUM
5.5
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
CVE-2026-70317
2026-08-11
MEDIUM
5.5
Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-70312
2026-08-11
MEDIUM
5.5
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
CVE-2026-70306
2026-08-11
CRITICAL
9.3
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-68821
2026-08-11
HIGH
7.3
Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally.
CVE-2026-66810
2026-08-11
MEDIUM
5.5
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-66809
2026-08-11
MEDIUM
5.5
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-66804
2026-08-11
HIGH
7.8
Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.
« Anterior
Página 58 de 4840
Siguiente »
Page load link
Go to Top