Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

3076 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.65%—Microsoft Sharepoint Server9/6/202623/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaMedia (5.4)0.58%—Microsoft Sharepoint Server9/6/202623/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (7.8)0.57%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+39/6/202623/7/2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.57%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+39/6/202623/7/2026
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaMedia (5.4)0.58%—Microsoft Sharepoint Server9/6/202623/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaMedia (5.4)0.58%—Microsoft Sharepoint Server9/6/202623/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
ModificadaMedia (5.4)0.59%—Microsoft Sharepoint Server9/6/202623/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
ModificadaMedia (5.4)0.59%—Microsoft Sharepoint Server9/6/202620/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
AnalizadaMedia (5.4)0.58%—Microsoft Sharepoint Server9/6/202623/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
ModificadaAlta (8.4)0.45%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+39/6/202623/7/2026
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
AnalizadaAlta (8.4)0.45%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+39/6/202623/7/2026
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
AnalizadaAlta (8.8)1.5%—Microsoft Sharepoint Server9/6/202623/7/2026
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
ModificadaMedia (5.4)0.59%—Microsoft Sharepoint Server9/6/202623/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (7.8)0.57%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+39/6/202623/7/2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
AnalizadaMedia (5.5)0.60%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+39/6/202623/7/2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
AnalizadaAlta (7.8)0.57%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+39/6/202623/7/2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.47%—Microsoft ExcelMicrosoft PowerpointMicrosoft WordMicrosoft Windows 10 1607+129/6/202623/7/2026
Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.47%—Microsoft ExcelMicrosoft PowerpointMicrosoft WordMicrosoft Windows 10 1607+129/6/202623/7/2026
Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.
ModificadaMedia (6.1)0.60%—Microsoft Sharepoint Server9/6/202623/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
AnalizadaCrítica (9.3)6.4%⚠ Explotación activa💥 ExploitCheckpoint Gaia OSCheckpoint Gaia Embedded8/6/20264/8/2026
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
AplazadaMedia (4.3)0.20%—LatepointAI6/6/202623/7/2026
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.6.0. This is due to missing or incorrect nonce validation on the change_status function. This makes it possible for unauthenticated attackers to…
AnalizadaAlta (8.5)0.10%—Forcepoint VPN Client4/6/202622/7/2026
A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-administrative user to escalate privileges to SYSTEM. This issue affects VPN Client for Windows: versions 6.11.3 and prior.
ModificadaAlta (8)1.2%—Microsoft Sharepoint Server1/6/202622/7/2026
Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AplazadaMedia (6.1)0.26%—Sourcecodester Doctor Appointment SystemAI29/5/202621/7/2026
SourceCodester Doctor Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) due to improper handling of user supplied input in the user registration functionality in register.php.
AplazadaMedia (5.3)0.64%—Booking Calendar Simply Schedule AppointmentsAI28/5/202617/6/2026
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.6.11.8 due to the plugin not properly verifying that a user is authorized to perform an action via the bulk appointments REST API endpoint.…