Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
3076 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.65% | — | Microsoft Sharepoint Server | 9/6/2026 | 23/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.4) | 0.58% | — | Microsoft Sharepoint Server | 9/6/2026 | 23/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.8) | 0.57% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+3 | 9/6/2026 | 23/7/2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.57% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+3 | 9/6/2026 | 23/7/2026 | Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (5.4) | 0.58% | — | Microsoft Sharepoint Server | 9/6/2026 | 23/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.4) | 0.58% | — | Microsoft Sharepoint Server | 9/6/2026 | 23/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Modificada | Media (5.4) | 0.59% | — | Microsoft Sharepoint Server | 9/6/2026 | 23/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | |
| Modificada | Media (5.4) | 0.59% | — | Microsoft Sharepoint Server | 9/6/2026 | 20/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.4) | 0.58% | — | Microsoft Sharepoint Server | 9/6/2026 | 23/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Modificada | Alta (8.4) | 0.45% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+3 | 9/6/2026 | 23/7/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (8.4) | 0.45% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+3 | 9/6/2026 | 23/7/2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (8.8) | 1.5% | — | Microsoft Sharepoint Server | 9/6/2026 | 23/7/2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Modificada | Media (5.4) | 0.59% | — | Microsoft Sharepoint Server | 9/6/2026 | 23/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.8) | 0.57% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+3 | 9/6/2026 | 23/7/2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (5.5) | 0.60% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+3 | 9/6/2026 | 23/7/2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (7.8) | 0.57% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+3 | 9/6/2026 | 23/7/2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft ExcelMicrosoft PowerpointMicrosoft WordMicrosoft Windows 10 1607+12 | 9/6/2026 | 23/7/2026 | Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft ExcelMicrosoft PowerpointMicrosoft WordMicrosoft Windows 10 1607+12 | 9/6/2026 | 23/7/2026 | Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. | |
| Modificada | Media (6.1) | 0.60% | — | Microsoft Sharepoint Server | 9/6/2026 | 23/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Crítica (9.3) | 6.4% | ⚠ Explotación activa💥 Exploit | Checkpoint Gaia OSCheckpoint Gaia Embedded | 8/6/2026 | 4/8/2026 | A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password. | |
| Aplazada | Media (4.3) | 0.20% | — | LatepointAI | 6/6/2026 | 23/7/2026 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.6.0. This is due to missing or incorrect nonce validation on the change_status function. This makes it possible for unauthenticated attackers to… | |
| Analizada | Alta (8.5) | 0.10% | — | Forcepoint VPN Client | 4/6/2026 | 22/7/2026 | A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-administrative user to escalate privileges to SYSTEM. This issue affects VPN Client for Windows: versions 6.11.3 and prior. | |
| Modificada | Alta (8) | 1.2% | — | Microsoft Sharepoint Server | 1/6/2026 | 22/7/2026 | Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Aplazada | Media (6.1) | 0.26% | — | Sourcecodester Doctor Appointment SystemAI | 29/5/2026 | 21/7/2026 | SourceCodester Doctor Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) due to improper handling of user supplied input in the user registration functionality in register.php. | |
| Aplazada | Media (5.3) | 0.64% | — | Booking Calendar Simply Schedule AppointmentsAI | 28/5/2026 | 17/6/2026 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.6.11.8 due to the plugin not properly verifying that a user is authorized to perform an action via the bulk appointments REST API endpoint.… |