Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
3076 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.4) | 0.45% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+1 | 12/5/2026 | 17/6/2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Modificada | Alta (8.8) | 1.1% | — | Microsoft Sharepoint Server | 12/5/2026 | 17/6/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 2.3% | — | Microsoft Sharepoint Server | 12/5/2026 | 17/6/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 2.3% | — | Microsoft Sharepoint Server | 12/5/2026 | 17/6/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 2.3% | — | Microsoft Sharepoint Server | 12/5/2026 | 17/6/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 2.3% | — | Microsoft Sharepoint Server | 12/5/2026 | 17/6/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.7) | 0.22% | — | Intel Endpoint Management Assistant | 12/5/2026 | 21/7/2026 | Improper input validation for some Intel Endpoint Management Assistant (EMA) software before version 1.14.5 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable escalation of privilege. This… | |
| Analizada | Alta (8.8) | 1.6% | — | Ivanti Endpoint Manager | 12/5/2026 | 17/6/2026 | SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code execution. | |
| Analizada | Alta (7.8) | 0.37% | — | Ivanti Endpoint Manager | 12/5/2026 | 17/6/2026 | Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenticated attacker to escalate their privileges. | |
| Analizada | Media (6.5) | 1.1% | — | Ivanti Endpoint Manager | 12/5/2026 | 17/6/2026 | An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to leak access credentials. | |
| Aplazada | Media (5.3) | 0.39% | — | Smart Appointment BookingAI | 12/5/2026 | 17/6/2026 | The Smart Appointment & Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and a nonce validation logic flaw in the saab_cancel_booking() function in all versions up to, and including, 1.0.8. The nonce check uses && (AND) instead of || (OR), which means… | |
| Aplazada | Media (5.3) | 0.66% | — | LatepointAI | 9/5/2026 | 24/7/2026 | The LatePoint plugin for WordPress is vulnerable to Account Takeover via Weak Password Recovery Mechanism in the unauthenticated guest booking flow in versions up to, and including, 5.5.0 This is due to the save_connected_wordpress_user() function propagating a LatePoint customer's email address to its linked… | |
| Analizada | Crítica (9.1) | 0.86% | — | Ivanti Endpoint Manager Mobile | 7/5/2026 | 17/6/2026 | Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a device belonging to a restricted set of unenrolled devices, leading to information disclosure about EPMM appliance and impacting on the integrity of the newly enrolled… | |
| Analizada | Alta (7.2) | 2.5% | ⚠ Explotación activa | Ivanti Endpoint Manager Mobile | 7/5/2026 | 17/6/2026 | An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution. | |
| Analizada | Crítica (9.8) | 1.5% | — | Ivanti Endpoint Manager Mobile | 7/5/2026 | 17/6/2026 | An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitrary methods. | |
| Analizada | Crítica (9.1) | 0.85% | — | Ivanti Endpoint Manager Mobile | 7/5/2026 | 17/6/2026 | An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-signed client certificates. | |
| Analizada | Alta (8.8) | 1.2% | — | Ivanti Endpoint Manager Mobile | 7/5/2026 | 17/6/2026 | An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to gain administrative access. | |
| Aplazada | Media (6.5) | 0.48% | — | Appointment Booking CalendarAI | 7/5/2026 | 17/6/2026 | The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.6.10.6. This is due to a flawed authorization logic in the nonce_permissions_check() method combined with the public exposure of a site-wide reusable nonce. The plugin exposes a public_nonce… | |
| Aplazada | Media (6.4) | 0.45% | — | LatepointAI | 6/5/2026 | 17/6/2026 | The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to and including 5.5.0. This is due to insufficient input sanitization on the customer cabinet profile update endpoint — where raw POST parameters (first_name, last_name, phone, notes) bypass sanitization because… | |
| Aplazada | Alta (7.2) | 0.51% | — | LatepointAI | 6/5/2026 | 17/6/2026 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'booking_form_page_url' parameter in all versions up to, and including, 5.5.0 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Analizada | Alta (8.8) | 0.29% | — | Sailpoint Identityiq | 29/4/2026 | 17/6/2026 | This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the definition of a role without having an assigned capability that would allow role editing. | |
| Aplazada | Alta (8.8) | 0.56% | 💥 PoC | LatepointAI | 27/4/2026 | 17/6/2026 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 5.4.1. This is due to a missing authorization check in the execute() method of the connect-customer-to-wp-user ability, which only requires the customer__edit… | |
| Analizada | Alta (8.5) | 0.33% | — | Guardsix LogpointGuardsix Odbc | 22/4/2026 | 17/6/2026 | An issue was discovered in guardsix (formerly Logpoint) ODBC Enrichment Plugins before 5.2.1 (5.2.1 is used in guardsix 7.9.0.0). A logic flaw allowed stored database credentials to be reused after modification of the target Host, IP address, or Port. When editing an existing Enrichment Source, previously stored… | |
| Analizada | Media (5.1) | 0.16% | — | Phppointofsale PHP Point OF Sale | 21/4/2026 | 17/6/2026 | HTML injection vulnerability in PHP Point of Sale v19.4. This vulnerability allows an attacker to render HTML in the victim's browser due to a lack of proper validation of user input by sending a request to '/reports/generate/specific_customer', ussing 'start_date_formatted' y 'end_date_formatted' parameters. | |
| Aplazada | Alta (7.5) | 2.4% | 💥 Exploit | Easyappointments Easy AppointmentsAI | 18/4/2026 | 17/6/2026 | The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.21 via the `/wp-json/wp/v2/eablocks/ea_appointments/` REST API endpoint. This is due to the endpoint being registered with `'permission_callback' => '__return_true'`, which allows… |