Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2666▼ 407 respecto a la semana anterior
Críticas / altas1266▼ 215 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)215▼ 115 respecto a la semana anterior
–

21.068 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.82%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+28/9/202617/9/2026
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.82%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+28/9/202617/9/2026
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.82%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+18/9/202617/9/2026
Use after free in Microsoft Office allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.82%—Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Office 2024+18/9/20269/9/2026
Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
AnalizadaMedia (6.5)0.92%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+28/9/202617/9/2026
Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (8.8)0.86%—Microsoft 365 AppsMicrosoft AccessMicrosoft Office 2019Microsoft Office 2021+18/9/202610/9/2026
Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.82%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+28/9/20269/9/2026
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.82%—Microsoft 365 AppsMicrosoft AccessMicrosoft Office 2016Microsoft Office 2019+28/9/202610/9/2026
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (7.3)0.43%—Microsoft 365 AppsMicrosoft AccessMicrosoft Office 2019Microsoft Office 2021+18/9/202610/9/2026
Heap-based buffer overflow in Microsoft Office Access allows an authorized attacker to execute code locally.
AnalizadaAlta (8.8)0.82%—Microsoft 365 AppsMicrosoft Office 2016Microsoft Office 2019Microsoft Office 2021+18/9/20269/9/2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.82%—Microsoft 365 AppsMicrosoft Office 2016Microsoft Office 2019Microsoft Office 2021+18/9/20269/9/2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
AnalizadaMedia (6.5)0.87%—Microsoft 365 AppsMicrosoft Office 2016Microsoft Office 2019Microsoft Office 2021+18/9/20269/9/2026
Insufficiently protected credentials in Microsoft Office allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (7.8)0.61%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+28/9/20268/9/2026
External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Pendiente de análisisAlta (7.1)0.16%—Cisco UCS ServersAICisco UCS AppliancesAI8/9/202611/9/2026
A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or admin or an unauthenticated attacker with physical access to an affected…
AnalizadaAlta (8.8)0.82%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+38/9/202624/9/2026
Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
ModificadaAlta (8.4)0.34%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+28/9/202625/9/2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
AnalizadaCrítica (9.3)0.49%—Snipeitapp Snipe-it8/9/20269/9/2026
Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Custom CSS field due to incomplete sanitization that reverses HTML encoding on greater-than and double-quote characters. Superusers can plant malicious CSS payloads using @import and url() references to exfiltrate CSRF tokens from other…
AnalizadaMedia (5.3)0.28%—Snipeitapp Snipe-it8/9/202610/9/2026
snipe-it versions before 8.7.0 fail to enforce asset view authorization in the GET /hardware/{asset}/barcode endpoint. Authenticated attackers can iterate asset IDs to retrieve barcodes and enumerate asset tags across tenants, including soft-deleted and cross-company assets.
AnalizadaMedia (5.9)0.31%—Snipeitapp Snipe-it8/9/20269/9/2026
snipe-it versions before 8.7.0 contain a server-side request forgery vulnerability in the ExternalUrl validation rule that fails to detect IPv6 transition addresses encoding private IPv4 targets. Attackers with super-admin privileges can configure webhook URLs using NAT64, 6to4, or Teredo transition addresses to…
AnalizadaAlta (7.1)0.55%—Snipeitapp Snipe-it8/9/202610/9/2026
Snipe-IT before 8.7.1 fails to validate the length of the note field in the POST /account/accept/{acceptance} endpoint, allowing authenticated users to submit unbounded input that reaches synchronous CommonMark rendering. Attackers can submit large note values to exhaust PHP worker CPU and cause denial of service…
AnalizadaAlta (8.6)0.58%—Snipeitapp Snipe-it8/9/20269/9/2026
Snipe-IT before 8.7.0 streams the SQL entry from an uploaded backup archive directly into the MySQL/MariaDB command-line client (`mysql`) without the --binary-mode flag, so the client interprets lines beginning with backslash commands such as `\!` as local shell commands. An authenticated superadministrator who…
AnalizadaAlta (7.8)0.47%—Microsoft Hevc Video ExtensionsMicrosoft Hevc Video Extensions FOR Licensed ApplicationsMicrosoft Hevc Video Extensions From Device Manufacturer8/9/20261/10/2026
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.47%—Microsoft Hevc Video ExtensionsMicrosoft Hevc Video Extensions FOR Licensed ApplicationsMicrosoft Hevc Video Extensions From Device Manufacturer8/9/20261/10/2026
Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally.
AnalizadaMedia (5.3)0.30%—Snipeitapp Snipe-it8/9/202619/9/2026
snipe-it before 8.7.0 contains an incorrect calculation vulnerability in checkout request handling that allows authenticated users to corrupt the assets.requests_counter through duplicate submissions and cancellations without active requests. Attackers can repeatedly call cancel endpoints without active requests to…
AplazadaAlta (7.1)0.25%—Easyappointments Easy AppointmentsAI8/9/20268/9/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Appointments allows DOM-Based XSS. This issue affects Easy Appointments: from n/a through 4.0.2.1.