Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
736 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 1.7% | — | Microsoft Sharepoint Foundation | 12/5/2017 | 17/6/2026 | Microsoft SharePoint Foundation 2013 SP1 allows an elevation of privilege vulnerability when it does not properly sanitize a specially crafted web request, aka "Microsoft SharePoint XSS Vulnerability". | |
| Modificada | Alta (7.8) | 20% | — | Microsoft OfficeMicrosoft Office Compatibility PackMicrosoft Office WEB AppsMicrosoft Sharepoint Server+3 | 12/5/2017 | 17/6/2026 | Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Office for Mac 2011, Office for Mac 2016, Microsoft Office Web Apps 2010 SP2, Office Web Apps Server 2013 SP1, Word 2013 RT SP1, Word 2013 SP1, Word Automation Services on Microsoft SharePoint Server 2013 SP1, Office Word Viewer,… | |
| Modificada | Media (5.5) | 5.3% | 💥 Exploit | Broadcom Symantec Data Center Security ServerSymantec Advanced Threat ProtectionSymantec CsapiSymantec Email Security.cloud+11 | 14/4/2017 | 17/6/2026 | The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec Endpoint Protection (SEP) for Windows before 12.1.6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint… | |
| Modificada | Media (5.5) | 6.9% | 💥 Exploit | Broadcom Symantec Data Center Security ServerSymantec Advanced Threat ProtectionSymantec CsapiSymantec Email Security.cloud+11 | 14/4/2017 | 17/6/2026 | The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec Endpoint Protection (SEP) for Windows before 12.1.6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint… | |
| Modificada | Media (5.4) | 3.8% | — | Microsoft Excel WEB APPMicrosoft Office Online ServerMicrosoft Office WEB AppsMicrosoft Office WEB Apps Server+1 | 12/4/2017 | 17/6/2026 | Microsoft Excel Services on Microsoft SharePoint Server 2010 SP1 and SP2, Microsoft Excel Web Apps 2010 SP2, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps Server 2013 SP1 and Office Online Server allows remote attackers to perform cross-site scripting and run script with local user privileges via a… | |
| Modificada | Media (6.1) | 7.0% | — | Microsoft Sharepoint Foundation | 17/3/2017 | 17/6/2026 | Microsoft SharePoint Server fails to sanitize crafted web requests, allowing remote attackers to run cross-script in local security context, aka "Microsoft SharePoint XSS Vulnerability." | |
| Modificada | Media (5.5) | 30% | — | Microsoft OfficeMicrosoft Office Compatibility PackMicrosoft Office WEB AppsMicrosoft Sharepoint Server+3 | 17/3/2017 | 17/6/2026 | Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from out-of-bound memory via a crafted Office document, aka "Microsoft… | |
| Modificada | Alta (7.8) | 17% | — | Microsoft ExcelMicrosoft Excel ViewerMicrosoft Office Compatibility PackMicrosoft Sharepoint Server | 17/3/2017 | 17/6/2026 | Microsoft Office Compatibility Pack SP3, Excel 2007 SP3, Excel Viewer, and Excel Services on SharePoint Server 2007 SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." This vulnerability is… | |
| Modificada | Alta (7.8) | 26% | — | Microsoft OfficeMicrosoft Office Compatibility PackMicrosoft Office WEB AppsMicrosoft Sharepoint Server+1 | 17/3/2017 | 17/6/2026 | Microsoft Office 2010 SP2, Office Compatibility Pack SP3, Office Web Apps Server 2010 SP2, Word 2007 SP3, Word 2010 SP2, and Word Automation Services on SharePoint Server 2010 SP2 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft… | |
| Modificada | Media (4.7) | 23% | — | Microsoft ExcelMicrosoft Office Compatibility PackMicrosoft Sharepoint Server | 17/3/2017 | 17/6/2026 | Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Services on SharePoint Server 2013 SP1 allow remote attackers to obtain sensitive information from process memory via a crafted Office document, aka "Microsoft Office Information Disclosure Vulnerability." | |
| Modificada | Alta (7.8) | 17% | — | Microsoft ExcelMicrosoft Excel ViewerMicrosoft Office Compatibility PackMicrosoft Sharepoint Server | 17/3/2017 | 17/6/2026 | Microsoft Excel 2007 SP3, Office Compatibility Pack SP3, Excel Viewer, and Excel Services on SharePoint Server 2007 SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." This vulnerability is… | |
| Modificada | Alta (7.8) | 25% | — | Microsoft Sharepoint Enterprise ServerMicrosoft Word | 10/1/2017 | 17/6/2026 | Microsoft Word 2016 and SharePoint Enterprise Server 2016 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." | |
| Modificada | Alta (7.1) | 23% | — | Microsoft OfficeMicrosoft Office Compatibility PackMicrosoft Office WEB AppsMicrosoft Sharepoint Server+3 | 20/12/2016 | 17/6/2026 | Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word for Mac 2011, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read)… | |
| Modificada | Alta (7.1) | 23% | — | Microsoft OfficeMicrosoft Office Compatibility PackMicrosoft Office WEB AppsMicrosoft Sharepoint Server+3 | 20/12/2016 | 17/6/2026 | Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word for Mac 2011, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read)… | |
| Modificada | Alta (7.1) | 23% | — | Microsoft OfficeMicrosoft Office Compatibility PackMicrosoft Office WEB AppsMicrosoft Sharepoint Server+3 | 20/12/2016 | 17/6/2026 | Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word Viewer, Word for Mac 2011, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a denial of service… | |
| Modificada | Alta (7.1) | 23% | — | Microsoft ExcelMicrosoft Excel ViewerMicrosoft Office Compatibility PackMicrosoft Sharepoint Server | 20/12/2016 | 17/6/2026 | Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, Excel Viewer, Excel Services on SharePoint Server 2007 SP3, and Excel Services on SharePoint Server 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a… | |
| Modificada | Alta (7.8) | 21% | — | Microsoft ExcelMicrosoft Excel FOR MACMicrosoft Sharepoint Server | 10/11/2016 | 17/6/2026 | Microsoft Excel 2010 SP2, Excel for Mac 2011, Excel 2016 for Mac, and Excel Services on SharePoint Server 2010 SP2 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability." | |
| Modificada | Alta (7.8) | 21% | — | Microsoft Excel FOR MACMicrosoft OfficeMicrosoft Office Compatibility PackMicrosoft Office WEB Apps+3 | 10/11/2016 | 17/6/2026 | Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Excel for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, and… | |
| Modificada | Media (6.5) | 22% | — | Microsoft Excel FOR MACMicrosoft OfficeMicrosoft Office Compatibility PackMicrosoft Office WEB Apps+5 | 10/11/2016 | 17/6/2026 | Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Excel for Mac 2011, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2013 SP1, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a denial of… | |
| Modificada | Alta (7.8) | 20% | — | Microsoft ExcelMicrosoft Excel ViewerMicrosoft Office Compatibility PackMicrosoft Office Online Server+1 | 14/9/2016 | 17/6/2026 | Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, Excel Viewer, Excel Services on SharePoint Server 2007 SP3, Excel Services on SharePoint Server 2010 SP2, Excel Automation Services on SharePoint Server 2013 SP1, and Office Online Server allow… | |
| Modificada | Alta (7.8) | 17% | — | Microsoft ExcelMicrosoft Excel ViewerMicrosoft Office Compatibility PackMicrosoft Office Online Server+1 | 14/9/2016 | 17/6/2026 | Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, Excel Viewer, Excel Services on SharePoint Server 2007 SP3, Excel Services on SharePoint Server 2010 SP2, Excel Automation Services on SharePoint Server 2013 SP1, and Office Online Server allow… | |
| Modificada | Alta (7.8) | 17% | — | Microsoft Office Compatibility PackMicrosoft Office WEB AppsMicrosoft Office WEB Apps ServerMicrosoft Powerpoint+3 | 14/9/2016 | 17/6/2026 | Microsoft PowerPoint 2007 SP3, PowerPoint 2010 SP2, PowerPoint 2013 SP1, PowerPoint 2013 RT SP1, PowerPoint 2016 for Mac, Office Compatibility Pack SP3, PowerPoint Viewer, SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, and Office Web Apps Server 2013 SP1 allow remote attackers to execute arbitrary code via a… | |
| Modificada | Alta (7.8) | 18% | — | Microsoft ExcelMicrosoft Excel FOR MACMicrosoft Excel ViewerMicrosoft Office Compatibility Pack+2 | 14/9/2016 | 17/6/2026 | Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel 2016 for Mac, Office Compatibility Pack SP3, Excel Viewer, Excel Services on SharePoint Server 2007 SP3, Excel Services on SharePoint Server 2010 SP2, Excel Automation Services on SharePoint Server 2013 SP1, and Office… | |
| Modificada | Alta (7.8) | 55% | 💥 Exploit | Microsoft OfficeMicrosoft Office WEB AppsMicrosoft Office WEB Apps ServerMicrosoft Sharepoint Foundation+2 | 14/9/2016 | 17/6/2026 | Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word for Mac 2011, Word 2016 for Mac, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, SharePoint Server 2013 SP1, Excel Automation Services on SharePoint Server 2013 SP1, Word Automation Services on… | |
| Modificada | Alta (8.1) | 7.2% | — | HP Converged Infrastructure Solution Sizer SuiteHP Insight Management SizerHP Power AdvisorHP SAP Sizing Tool+11 | 22/8/2016 | 17/6/2026 | HPE Smart Update in Storage Sizing Tool before 13.0, Converged Infrastructure Solution Sizer Suite (CISSS) before 2.13.1, Power Advisor before 7.8.2, Insight Management Sizer before 16.12.1, Synergy Planning Tool before 3.3, SAP Sizing Tool before 16.12.1, Sizing Tool for SAP Business Suite powered by HANA before… |