Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
145 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.53% | — | Microsoft Dynamics 365 | 12/8/2025 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.5) | 0.83% | — | Microsoft Dynamics 365 | 20/6/2025 | 17/6/2026 | Exposure of private personal information to an unauthorized actor in Dynamics 365 FastTrack Implementation Assets allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (7.5) | 1.4% | — | Microsoft Dynamics 365 Customer Service | 30/4/2025 | 17/6/2026 | Improper input validation in Microsoft Dynamics allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (5.5) | 0.69% | — | Microsoft Dynamics 365 Business Central 2023Microsoft Dynamics 365 Business Central 2024Microsoft Dynamics 365 Business Central 2025 | 8/4/2025 | 10/8/2026 | Improper input validation in Dynamics Business Central allows an authorized attacker to disclose information locally. | |
| Analizada | Alta (8.8) | 1.1% | — | Microsoft Dynamics 365 Sales | 6/2/2025 | 17/6/2026 | Server-side request forgery (ssrf) in Microsoft Dynamics 365 Sales allows an authorized attacker to elevate privileges over a network. | |
| Aplazada | Crítica (9.9) | 1.4% | 💥 PoC | Dynamics 365 IntegrationAI | 4/1/2025 | 17/6/2026 | The Dynamics 365 Integration plugin for WordPress is vulnerable to Remote Code Execution and Arbitrary File Read in all versions up to, and including, 1.3.23 via Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.38% | — | Alexacrm Dynamics 365 IntegrationAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in AlexaCRM Dynamics 365 Integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dynamics 365 Integration: from n/a through 1.3.13. | |
| Aplazada | Media (5.4) | 0.36% | — | Alexacrm Dynamics 365 IntegrationAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in AlexaCRM Dynamics 365 Integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dynamics 365 Integration: from n/a through 1.3.12. | |
| Analizada | Alta (7.6) | 0.64% | — | Microsoft Dynamics 365 Sales | 26/11/2024 | 17/6/2026 | Microsoft Dynamics 365 Sales Spoofing Vulnerability | |
| Analizada | Alta (8.8) | 0.71% | — | Microsoft Dynamics 365 Business Central | 17/9/2024 | 10/8/2026 | Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacker to elevate privileges over a network. | |
| Analizada | Media (5.4) | 0.89% | — | Microsoft Dynamics 365 | 10/9/2024 | 10/8/2026 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | |
| Analizada | Crítica (9.8) | 1.4% | — | Microsoft Dynamics 365 Business Central | 10/9/2024 | 10/8/2026 | Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability | |
| Analizada | Alta (8.2) | 1.00% | — | Microsoft Dynamics 365 | 13/8/2024 | 17/6/2026 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | |
| Analizada | Crítica (9.8) | 0.88% | — | Microsoft Dynamics 365 | 31/7/2024 | 17/6/2026 | Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate privileges over a network. | |
| Modificada | Alta (7.3) | 1.4% | — | Microsoft Dynamics 365 | 9/7/2024 | 17/6/2026 | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability | |
| Modificada | Media (5.7) | 1.7% | — | Microsoft Dynamics 365 | 11/6/2024 | 20/7/2026 | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability | |
| Modificada | Alta (8.8) | 3.4% | — | Microsoft Dynamics 365 Business Central | 11/6/2024 | 10/8/2026 | Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability | |
| Modificada | Alta (7.3) | 0.95% | — | Microsoft Dynamics 365 Business Central | 11/6/2024 | 21/7/2026 | Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability | |
| Analizada | Media (4.1) | 0.99% | — | Microsoft Dynamics 365 Customer Insights | 14/5/2024 | 17/6/2026 | Dynamics 365 Customer Insights Spoofing Vulnerability | |
| Analizada | Media (4.1) | 0.99% | — | Microsoft Dynamics 365 Customer Insights | 14/5/2024 | 17/6/2026 | Dynamics 365 Customer Insights Spoofing Vulnerability | |
| Aplazada | Media (5.3) | 0.58% | — | Alexacrm Dynamics 365 IntegrationAI | 14/5/2024 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in AlexaCRM Dynamics 365 Integration.This issue affects Dynamics 365 Integration: from n/a through 1.3.17. | |
| Analizada | Media (5.4) | 1.1% | — | Microsoft Dynamics 365 | 12/3/2024 | 17/6/2026 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | |
| Modificada | Alta (7.6) | 1.2% | — | Microsoft Dynamics 365 | 13/2/2024 | 10/8/2026 | Dynamics 365 Sales Spoofing Vulnerability | |
| Modificada | Alta (8.2) | 1.1% | — | Microsoft Dynamics 365 | 13/2/2024 | 10/8/2026 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | |
| Modificada | Alta (7.6) | 1.1% | — | Microsoft Dynamics 365 | 13/2/2024 | 10/8/2026 | Dynamics 365 Field Service Spoofing Vulnerability |