431 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2026-33874
app-Authenticator General
7.8
HIGH
EPSS
0.1%
2026 CWE-78 1 PoC

Gematik Authenticator securely authenticates users for login to digital health applications. Starting in version 4.12.0 and prior to version 4.16.0, the Mac OS version of the Authenticator is vulnerable to remote code execution, triggered when victims open a malicious file. Update the gematik Authenticator to version 4.16.0 or greater to receive a patch. There are no known workarounds.

CVE-2026-5403
Wireshark General
7.8
HIGH
EPSS
0.0%
2026 CWE-122 1 PoC

SBC codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service and possible code execution

CVE-2026-27750
Avira Internet Security General
7.8
HIGH
EPSS
0.0%
2026 CWE-367 2 PoCs

Avira Internet Security contains a time-of-check time-of-use (TOCTOU) vulnerability in the Optimizer component. A privileged service running as SYSTEM identifies directories for cleanup during a scan phase and subsequently deletes them during a separate cleanup phase without revalidating the target path. A local attacker can replace a previously scanned directory with a junction or reparse point before deletion occurs, causing the privileged process to delete an unintended system location. This may result in deletion of protected files or directories and can lead to local privilege escalation,

CVE-2026-21509
🔥 KEV Microsoft 365 Apps for Enterprise General
7.8
HIGH
EPSS
12.5%
2026 CWE-807 2 PoCs

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

CVE-2026-26738
Software Genérico General
7.8
HIGH
EPSS
0.1%
2026 2 PoCs

Buffer Overflow vulnerability in Uderzo Software SpaceSniffer v.2.0.5.18 allows a remote attacker to execute arbitrary code via a crafted .sns snapshot file.

CVE-2026-31431
🔥 KEV Linux General
7.8
HIGH
EPSS
2.6%
2026 22 PoCs

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.

CVE-2026-3888
Software Genérico General
7.8
HIGH
EPSS
0.0%
2026 CWE-268 1 PoC

Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private /tmp directory when systemd-tmpfiles is configured to automatically clean up this directory. This issue affects Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, and 24.04 LTS.

CVE-2026-24071
Native Access General
7.8
HIGH
EPSS
0.0%
2026 CWE-367 1 PoC

It was found that the XPC service offered by the privileged helper of Native Access uses the PID of the connecting client to verify its code signature. This is considered insecure and can be exploited by PID reuse attacks. The connection handler function uses _xpc_connection_get_pid(arg2) as argument for the hasValidSignature function. This value can not be trusted since it is vulnerable to PID reuse attacks.

CVE-2026-7270
FreeBSD General
7.8
HIGH
EPSS
0.0%
2026 CWE-783 2 PoCs

An operator precedence bug in the kernel results in a scenario where a buffer overflow causes attacker-controlled data to overwrite adjacent execve(2) argument buffers. The bug may be exploitable by an unprivileged user to obtain superuser privileges.

CVE-2026-23268
Linux General
7.8
HIGH
EPSS
0.0%
2026 1 PoC

In the Linux kernel, the following vulnerability has been resolved: apparmor: fix unprivileged local user can do privileged policy management An unprivileged local user can load, replace, and remove profiles by opening the apparmorfs interfaces, via a confused deputy attack, by passing the opened fd to a privileged process, and getting the privileged process to write to the interface. This does require a privileged target that can be manipulated to do the write for the unprivileged process, but once such access is achieved full policy management is possible and all the possible implications

CVE-2026-24062
Software Center General
7.8
HIGH
EPSS
0.0%
2026 CWE-306 1 PoC

The "Privileged Helper" component of the Arturia Software Center (MacOS) does not perform sufficient client code signature validation when a client connects. This leads to an attacker being able to connect to the helper and execute privileged actions leading to local privilege escalation.

CVE-2026-27748
Avira Internet Security General
7.8
HIGH
EPSS
0.0%
2026 CWE-59 2 PoCs

Avira Internet Security contains an improper link resolution vulnerability in the Software Updater component. During the update process, a privileged service running as SYSTEM deletes a file under C:\\ProgramData without validating whether the path resolves through a symbolic link or reparse point. A local attacker can create a malicious link to redirect the delete operation to an arbitrary file, resulting in deletion of attacker-chosen files with SYSTEM privileges. This may lead to local privilege escalation, denial of service, or system integrity compromise depending on the targeted file and

CVE-2026-3775
Foxit PDF Editor General
7.8
HIGH
EPSS
0.0%
2026 CWE-427 1 PoC

The application's update service, when checking for updates, loads certain system libraries from a search path that includes directories writable by low‑privileged users and is not strictly restricted to trusted system locations. Because these libraries may be resolved and loaded from user‑writable locations, a local attacker can place a malicious library there and have it loaded with SYSTEM privileges, resulting in local privilege escalation and arbitrary code execution.

CVE-2026-27749
Avira Internet Security General
7.8
HIGH
EPSS
0.1%
2026 CWE-502 2 PoCs

Avira Internet Security contains a deserialization of untrusted data vulnerability in the System Speedup component. The Avira.SystemSpeedup.RealTimeOptimizer.exe process, which runs with SYSTEM privileges, deserializes data from a file located in C:\\ProgramData using .NET BinaryFormatter without implementing input validation or deserialization safeguards. Because the file can be created or modified by a local user in default configurations, an attacker can supply a crafted serialized payload that is deserialized by the privileged process, resulting in arbitrary code execution as SYSTEM.

CVE-2026-22163
Graphics DDK General
7.8
HIGH
EPSS
0.0%
2026 CWE-820 1 PoC

Requires malware code to misuse the DDK kernel module IOCTL interface. Such code can use the interface in an unsupported way that allows subversion of the GPU to perform writes to arbitrary physical memory pages. The product utilises a shared resource in a concurrent manner but does not attempt to synchronise access to the resource.

CVE-2026-3989
SGLang General
7.8
HIGH
EPSS
0.0%
2026 1 PoC

SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An attacker can take advantage of this by providing a malicious .pkl file, which will execute the attackers code on the device running the script.

CVE-2026-3779
Foxit PDF Editor General
7.8
HIGH
EPSS
0.0%
2026 CWE-416 2 PoCs

The application's list box calculate array logic keeps stale references to page or form objects after they are deleted or re-created, which allows crafted documents to trigger a use-after-free when the calculation runs and can potentially lead to arbitrary code execution.

CVE-2026-33825
🔥 KEV Microsoft Defender Antimalware Platform General
7.8
HIGH
EPSS
4.9%
2026 CWE-1220 1 PoC

Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.

CVE-2026-34222
open-webui General
7.7
HIGH
EPSS
0.0%
2026 CWE-285 1 PoC

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8.11, there is a broken access control vulnerability in tool values. This issue has been patched in version 0.8.11.

CVE-2026-31851
Nebula 300+ General
7.7
HIGH
EPSS
0.1%
2026 CWE-307 1 PoC

Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout mechanisms on authentication interfaces. An attacker can perform unlimited authentication attempts against endpoints that rely on credential validation, enabling brute-force attacks to guess administrative credentials without restriction.