Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

58 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.3)0.32%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.
AnalizadaMedia (6.1)0.41%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
AnalizadaMedia (6.5)1.1%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network.
AnalizadaAlta (7.5)1.2%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.
AnalizadaMedia (6.5)0.92%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (7.1)0.53%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (7.5)0.97%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.
AnalizadaMedia (6.5)1.1%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.
AnalizadaCrítica (9.8)0.97%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.
AnalizadaMedia (6.1)0.55%—Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition8/9/202616/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
ModificadaMedia (5.7)0.56%—Microsoft Skype FOR Business Server13/2/202410/8/2026
Skype for Business Information Disclosure Vulnerability
ModificadaAlta (7.8)1.2%—Microsoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Powerpoint+413/2/202410/8/2026
Microsoft Office Remote Code Execution Vulnerability
AnalizadaMedia (5.3)90%⚠ Explotación activa💥 ExploitMicrosoft Skype FOR Business Server10/10/202317/6/2026
Skype for Business Elevation of Privilege Vulnerability
ModificadaAlta (7.2)2.4%—Microsoft Skype FOR Business Server10/10/202317/6/2026
Skype for Business Remote Code Execution Vulnerability
ModificadaAlta (7.2)2.5%—Microsoft Skype FOR Business Server10/10/202317/6/2026
Skype for Business Remote Code Execution Vulnerability
ModificadaAlta (7.2)2.6%—Microsoft Skype FOR Business Server10/10/202317/6/2026
Skype for Business Remote Code Execution Vulnerability
ModificadaAlta (7.2)2.3%—Microsoft Lync ServerMicrosoft Skype FOR Business12/7/202217/6/2026
Skype for Business and Lync Remote Code Execution Vulnerability
ModificadaMedia (6.5)3.6%—Microsoft Lync ServerMicrosoft Skype FOR Business Server15/4/202217/6/2026
Skype for Business Information Disclosure Vulnerability
ModificadaMedia (5.3)2.5%—Microsoft Skype FOR Business Server15/4/202217/6/2026
Skype for Business and Lync Spoofing Vulnerability
ModificadaAlta (7.2)2.2%—Microsoft Lync ServerMicrosoft Skype FOR Business Server11/5/202117/6/2026
Skype for Business and Lync Remote Code Execution Vulnerability
ModificadaAlta (7.1)1.4%—Microsoft Lync ServerMicrosoft Skype FOR Business Server11/5/202117/6/2026
Skype for Business and Lync Spoofing Vulnerability
ModificadaMedia (6.5)3.2%—Microsoft Lync ServerMicrosoft Skype FOR Business Server25/2/202117/6/2026
Skype for Business and Lync Denial of Service Vulnerability
ModificadaAlta (7.1)1.8%—Microsoft Lync ServerMicrosoft Skype FOR Business Server25/2/202117/6/2026
Skype for Business and Lync Spoofing Vulnerability
ModificadaCrítica (9.8)5.9%—Microsoft LyncMicrosoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server+114/7/202017/6/2026
An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation. An attacker who successfully exploited the vulnerability could bypass authentication and achieve improper access. To exploit this vulnerability, an attacker would need…
ModificadaMedia (5.4)1.5%—Microsoft Skype FOR Business10/12/201917/6/2026
A spoofing vulnerability exists when a Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for Business Server Spoofing Vulnerability'.
Orbitaley — Vulnerabilidades