Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

2087 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.2)0.50%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Enterprise Server+212/8/202517/6/2026
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
AnalizadaAlta (8.4)0.55%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Enterprise Server+212/8/202517/6/2026
Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaAlta (8.8)19%—Microsoft Sharepoint Server12/8/202517/6/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaMedia (6.5)100%💥 ExploitMicrosoft Sharepoint Server20/7/202517/6/2026
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitMicrosoft Sharepoint Server20/7/20254/8/2026
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the…
AnalizadaMedia (5.4)0.18%—Oracle Hyperion Financial Reporting15/7/202517/6/2026
Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Workspace). The supported version that is affected is 11.2.20.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting. Successful…
AnalizadaBaja (2.1)0.36%—Phpgurukul Online Fire Reporting System14/7/202517/6/2026
A vulnerability was found in PHPGurukul Online Fire Reporting System 1.2. It has been classified as critical. Affected is an unknown function of the file /admin/manage-site.php. The manipulation of the argument webtitle leads to sql injection. It is possible to launch the attack remotely. The exploit has been…
AnalizadaBaja (2.1)0.37%—Phpgurukul Online Fire Reporting System14/7/202517/6/2026
A vulnerability was found in PHPGurukul Online Fire Reporting System 1.2 and classified as critical. This issue affects some unknown processing of the file /admin/add-team.php. The manipulation of the argument teammember leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to…
AnalizadaBaja (2.1)0.37%—Phpgurukul Online Fire Reporting System14/7/202517/6/2026
A vulnerability has been found in PHPGurukul Online Fire Reporting System 1.2 and classified as critical. This vulnerability affects unknown code of the file /admin/all-requests.php. The manipulation of the argument teamid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to…
AnalizadaBaja (2.1)0.37%—Phpgurukul Online Fire Reporting System14/7/202517/6/2026
A vulnerability, which was classified as critical, was found in PHPGurukul Online Fire Reporting System 1.2. This affects an unknown part of the file /admin/assigned-requests.php. The manipulation of the argument teamid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…
AnalizadaBaja (2.1)0.37%—Phpgurukul Online Fire Reporting System14/7/202517/6/2026
A vulnerability classified as critical was found in PHPGurukul Online Fire Reporting System 1.2. Affected by this vulnerability is an unknown functionality of the file /admin/completed-requests.php. The manipulation of the argument teamid leads to sql injection. The attack can be launched remotely. The exploit has…
AnalizadaBaja (2.1)0.37%—Phpgurukul Online Fire Reporting System14/7/202517/6/2026
A vulnerability classified as critical has been found in PHPGurukul Online Fire Reporting System 1.2. Affected is an unknown function of the file /admin/new-requests.php. The manipulation of the argument teamid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the…
AnalizadaBaja (2.1)0.37%—Phpgurukul Online Fire Reporting System14/7/202517/6/2026
A vulnerability was found in PHPGurukul Online Fire Reporting System 1.2. It has been rated as critical. This issue affects some unknown processing of the file /admin/team-ontheway-requests.php. The manipulation of the argument teamid leads to sql injection. The attack may be initiated remotely. The exploit has been…
AnalizadaBaja (2.1)0.37%—Phpgurukul Online Fire Reporting System14/7/202517/6/2026
A vulnerability was found in PHPGurukul Online Fire Reporting System 1.2. It has been declared as critical. This vulnerability affects unknown code of the file /admin/workin-progress-requests.php. The manipulation of the argument teamid leads to sql injection. The attack can be initiated remotely. The exploit has been…
AnalizadaBaja (2.1)0.37%—Phpgurukul Online Fire Reporting System14/7/202517/6/2026
A vulnerability was found in PHPGurukul Online Fire Reporting System 1.2. It has been classified as critical. This affects an unknown part of the file /admin/bwdates-report-result.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to initiate the attack remotely. The exploit…
AnalizadaMedia (6.5)99%⚠ Explotación activa💥 ExploitMicrosoft Sharepoint Enterprise ServerMicrosoft Sharepoint Server8/7/20254/8/2026
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (8.8)100%⚠ Explotación activa💥 ExploitMicrosoft Sharepoint Server8/7/202517/6/2026
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (7.8)0.67%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+18/7/202517/6/2026
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaAlta (8.8)1.2%—Microsoft Sharepoint Server8/7/202517/6/2026
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.6)3.0%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Enterprise Server8/7/202517/6/2026
Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally.
AnalizadaMedia (5.5)0.60%—Code-projects Crime Reporting System8/7/202517/6/2026
A vulnerability, which was classified as critical, was found in code-projects Crime Reporting System 1.0. This affects an unknown part of the file /headlogin.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public…
AnalizadaMedia (5.5)0.45%—Code-projects Crime Reporting System8/7/202517/6/2026
A vulnerability, which was classified as critical, has been found in code-projects Crime Reporting System 1.0. Affected by this issue is some unknown functionality of the file /policelogin.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been…
AnalizadaMedia (5.5)0.45%—Code-projects Crime Reporting System8/7/202517/6/2026
A vulnerability classified as critical was found in code-projects Crime Reporting System 1.0. Affected by this vulnerability is an unknown functionality of the file /registration.php. The manipulation of the argument Name leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to…
AnalizadaMedia (5.5)0.45%—Code-projects Crime Reporting System8/7/202517/6/2026
A vulnerability classified as critical has been found in code-projects Crime Reporting System 1.0. Affected is an unknown function of the file /complainer_page.php. The manipulation of the argument location leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the…
AnalizadaMedia (5.5)0.45%—Code-projects Crime Reporting System8/7/202517/6/2026
A vulnerability was found in code-projects Crime Reporting System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /userlogin.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public…
Orbitaley — Vulnerabilidades