Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

39 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.46%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/6/202628/7/2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
AnalizadaMedia (6.1)0.41%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/6/202628/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
AnalizadaMedia (6.1)0.52%⚠ Explotación activa💥 PoCMicrosoft Exchange ServerMicrosoft Exchange Server Subscription Edition14/5/202617/6/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
AnalizadaMedia (6.5)8.1%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition10/2/202617/6/2026
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
AnalizadaMedia (5.3)0.80%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/12/202517/6/2026
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (7.5)1.0%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/12/202517/6/2026
Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (8.8)0.83%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition14/10/202517/6/2026
Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (7.5)1.0%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition14/10/202517/6/2026
Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (7.8)0.36%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition14/10/202517/6/2026
Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally.
AnalizadaAlta (7.5)1.3%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition12/8/202517/6/2026
Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.
AnalizadaMedia (5.3)0.87%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition12/8/202517/6/2026
Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
AnalizadaMedia (5.3)0.89%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition12/8/202517/6/2026
Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
AnalizadaMedia (6.5)1.4%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition12/8/202517/6/2026
Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
AnalizadaAlta (8)7.7%💥 PoCMicrosoft Exchange ServerMicrosoft Exchange Server Subscription Edition6/8/202517/6/2026
On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following further investigation, Microsoft identified specific security…
Orbitaley — Vulnerabilidades