Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
3073 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.24% | — | Appointment Booking CalendarAI | 15/6/2026 | 17/6/2026 | WordPress appointment-booking-calendar 1.1.24 contains multiple privilege escalation vulnerabilities that allow unauthenticated attackers to modify calendar settings and inject persistent cross-site scripting payloads through the admin.php page parameters. Attackers can inject malicious JavaScript into the 'ict' and… | |
| Analizada | Media (6.1) | 0.37% | — | Aqara Cloud Oauth Authorization Endpoint | 12/6/2026 | 9/7/2026 | The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due to lax controls on domain matching, which is an instance of "CWE-1289: Improper Validation of Unsafe Equivalence in Input" and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N… | |
| Aplazada | Alta (8.7) | 0.45% | — | Cellopoint CelloosAI | 12/6/2026 | 17/6/2026 | The SSH service of CelloOS developed by Cellopoint has an Improper Access Control vulnerability, allowing authenticated remote attackers to bypass the enforced command restrictions and execute operating system commands outside the originally authorized scope. | |
| Analizada | Alta (8.5) | 0.17% | — | Paloaltonetworks Idira Endpoint Privilege Manager | 11/6/2026 | 22/6/2026 | Idira Endpoint Privilege Manager Linux Agent versions prior to 26.5 allow a local attacker to potentially compromise the agent daemon initialization. CyberArk Security Bulletin: CA26-19 | |
| Analizada | Alta (8.5) | 0.17% | — | Paloaltonetworks Idira Endpoint Privilege Manager | 11/6/2026 | 22/6/2026 | Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security controls or cryptographic validations. Under specific circumstances, this could allow the attacker to circumvent agent… | |
| Analizada | Alta (8.9) | 0.17% | — | Paloaltonetworks Idira Endpoint Privilege Manager | 11/6/2026 | 22/6/2026 | Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged agent components. A local, low-privileged attacker could exploit this by manipulating an internal communication mechanism or file operation. Under specific circumstances, this could potentially allow… | |
| Aplazada | Alta (7.8) | 0.12% | — | Checkpoint Identity AgentAI | 11/6/2026 | 17/6/2026 | A local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS. An authenticated local user may be able to execute arbitrary code with SYSTEM privileges due to improper handling of executable resolution during the log collection process. Successful exploitation could allow an… | |
| Analizada | Media (4.6) | 0.58% | — | Microsoft Sharepoint Server | 9/6/2026 | 23/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Modificada | Media (5.4) | 1.1% | — | Microsoft Sharepoint Server | 9/6/2026 | 23/7/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Modificada | Media (5.4) | 0.58% | — | Microsoft Sharepoint Server | 9/6/2026 | 23/7/2026 | Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.4) | 0.58% | — | Microsoft Sharepoint Server | 9/6/2026 | 23/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Modificada | Media (5.4) | 0.59% | — | Microsoft Sharepoint Server | 9/6/2026 | 23/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.4) | 0.58% | — | Microsoft Sharepoint Server | 9/6/2026 | 23/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.4) | 0.58% | — | Microsoft Sharepoint Server | 9/6/2026 | 23/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Modificada | Media (5.4) | 0.59% | — | Microsoft Sharepoint Server | 9/6/2026 | 23/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | |
| Modificada | Media (5.4) | 0.53% | — | Microsoft Sharepoint Server | 9/6/2026 | 23/7/2026 | Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Alta (8) | 0.98% | — | Microsoft Sharepoint Server | 9/6/2026 | 23/7/2026 | Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (7.1) | 0.44% | — | Microsoft ExcelMicrosoft PowerpointMicrosoft Word | 9/6/2026 | 23/7/2026 | Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally. | |
| Analizada | Alta (7) | 0.23% | — | Microsoft Defender FOR Endpoint | 9/6/2026 | 23/7/2026 | Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally. | |
| Analizada | Baja (3.3) | 0.56% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+3 | 9/6/2026 | 23/7/2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (8.8) | 2.3% | — | Microsoft Sharepoint Server | 9/6/2026 | 23/7/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Media (5.4) | 0.58% | — | Microsoft Sharepoint Server | 9/6/2026 | 23/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.4) | 0.65% | — | Microsoft Sharepoint Server | 9/6/2026 | 23/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.4) | 0.58% | — | Microsoft Sharepoint Server | 9/6/2026 | 23/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.8) | 0.57% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+3 | 9/6/2026 | 23/7/2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |