Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

3073 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.60%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+314/7/202616/7/2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
AnalizadaAlta (8.4)0.45%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+314/7/202616/7/2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+214/7/202616/7/2026
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
AnalizadaCrítica (9.1)70%⚠ Explotación activa💥 ExploitMicrosoft Sharepoint Server14/7/202619/8/2026
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
AnalizadaAlta (7.8)0.57%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+314/7/202616/7/2026
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaBaja (3.3)0.57%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+314/7/202616/7/2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
AnalizadaAlta (8.7)0.95%—Microsoft Sharepoint Server14/7/202615/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (7.8)0.57%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+314/7/202616/7/2026
Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.57%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+314/7/202616/7/2026
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaMedia (5.4)0.58%—Microsoft Sharepoint Server14/7/202615/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaMedia (5.5)0.60%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+314/7/202616/7/2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
AnalizadaMedia (5.5)0.60%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+314/7/202616/7/2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
AnalizadaMedia (5.5)0.45%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+314/7/202616/7/2026
Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.
AnalizadaMedia (5.5)0.60%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+314/7/202616/7/2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
AnalizadaAlta (8.7)0.95%—Microsoft Sharepoint Server14/7/202615/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaMedia (5.4)0.58%—Microsoft Sharepoint Server14/7/202616/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaMedia (5.4)0.58%—Microsoft Sharepoint Server14/7/202615/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaMedia (5.4)0.58%—Microsoft Sharepoint Server14/7/202615/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (7)0.20%—Microsoft Defender FOR Endpoint14/7/202622/7/2026
Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized attacker to elevate privileges locally.
AnalizadaMedia (5.5)0.40%💥 PoCMicrosoft Defender FOR Endpoint14/7/202622/7/2026
Exposure of private personal information to an unauthorized actor in Microsoft Defender allows an authorized attacker to disclose information locally.
AnalizadaCrítica (9.8)16%⚠ Explotación activa💥 ExploitMicrosoft Sharepoint Server14/7/202617/7/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
AnalizadaCrítica (9.8)1.0%⚠ Explotación activa💥 PoCMicrosoft Sharepoint Server14/7/202614/7/2026
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
AnalizadaMedia (6.5)1.1%—Microsoft Sharepoint Server14/7/202615/7/2026
External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaCrítica (9.8)3.0%⚠ Explotación activa💥 PoCMicrosoft Sharepoint Server14/7/202623/7/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
AplazadaAlta (7.1)0.32%—EasyappointmentsAI14/7/202614/7/2026
Easy!Appointments is a self hosted appointment scheduler. In version 1.5.2, an Excessive Data Exposure vulnerability in the customers search endpoint allows an authenticated user to obtain appointment hashes belonging to other users. Using these hashes, an attacker can modify or delete appointments of other providers,…