Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2666▼ 407 respecto a la semana anterior
Críticas / altas1266▼ 215 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)215▼ 115 respecto a la semana anterior
21.068 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.82% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 8/9/2026 | 17/9/2026 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 8/9/2026 | 17/9/2026 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+1 | 8/9/2026 | 17/9/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Office 2024+1 | 8/9/2026 | 9/9/2026 | Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | |
| Analizada | Media (6.5) | 0.92% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+2 | 8/9/2026 | 17/9/2026 | Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (8.8) | 0.86% | — | Microsoft 365 AppsMicrosoft AccessMicrosoft Office 2019Microsoft Office 2021+1 | 8/9/2026 | 10/9/2026 | Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 8/9/2026 | 9/9/2026 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft 365 AppsMicrosoft AccessMicrosoft Office 2016Microsoft Office 2019+2 | 8/9/2026 | 10/9/2026 | Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.3) | 0.43% | — | Microsoft 365 AppsMicrosoft AccessMicrosoft Office 2019Microsoft Office 2021+1 | 8/9/2026 | 10/9/2026 | Heap-based buffer overflow in Microsoft Office Access allows an authorized attacker to execute code locally. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft 365 AppsMicrosoft Office 2016Microsoft Office 2019Microsoft Office 2021+1 | 8/9/2026 | 9/9/2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft 365 AppsMicrosoft Office 2016Microsoft Office 2019Microsoft Office 2021+1 | 8/9/2026 | 9/9/2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network. | |
| Analizada | Media (6.5) | 0.87% | — | Microsoft 365 AppsMicrosoft Office 2016Microsoft Office 2019Microsoft Office 2021+1 | 8/9/2026 | 9/9/2026 | Insufficiently protected credentials in Microsoft Office allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.8) | 0.61% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+2 | 8/9/2026 | 8/9/2026 | External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Pendiente de análisis | Alta (7.1) | 0.16% | — | Cisco UCS ServersAICisco UCS AppliancesAI | 8/9/2026 | 11/9/2026 | A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or admin or an unauthenticated attacker with physical access to an affected… | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+3 | 8/9/2026 | 24/9/2026 | Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | |
| Modificada | Alta (8.4) | 0.34% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+2 | 8/9/2026 | 25/9/2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Crítica (9.3) | 0.49% | — | Snipeitapp Snipe-it | 8/9/2026 | 9/9/2026 | Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Custom CSS field due to incomplete sanitization that reverses HTML encoding on greater-than and double-quote characters. Superusers can plant malicious CSS payloads using @import and url() references to exfiltrate CSRF tokens from other… | |
| Analizada | Media (5.3) | 0.28% | — | Snipeitapp Snipe-it | 8/9/2026 | 10/9/2026 | snipe-it versions before 8.7.0 fail to enforce asset view authorization in the GET /hardware/{asset}/barcode endpoint. Authenticated attackers can iterate asset IDs to retrieve barcodes and enumerate asset tags across tenants, including soft-deleted and cross-company assets. | |
| Analizada | Media (5.9) | 0.31% | — | Snipeitapp Snipe-it | 8/9/2026 | 9/9/2026 | snipe-it versions before 8.7.0 contain a server-side request forgery vulnerability in the ExternalUrl validation rule that fails to detect IPv6 transition addresses encoding private IPv4 targets. Attackers with super-admin privileges can configure webhook URLs using NAT64, 6to4, or Teredo transition addresses to… | |
| Analizada | Alta (7.1) | 0.55% | — | Snipeitapp Snipe-it | 8/9/2026 | 10/9/2026 | Snipe-IT before 8.7.1 fails to validate the length of the note field in the POST /account/accept/{acceptance} endpoint, allowing authenticated users to submit unbounded input that reaches synchronous CommonMark rendering. Attackers can submit large note values to exhaust PHP worker CPU and cause denial of service… | |
| Analizada | Alta (8.6) | 0.58% | — | Snipeitapp Snipe-it | 8/9/2026 | 9/9/2026 | Snipe-IT before 8.7.0 streams the SQL entry from an uploaded backup archive directly into the MySQL/MariaDB command-line client (`mysql`) without the --binary-mode flag, so the client interprets lines beginning with backslash commands such as `\!` as local shell commands. An authenticated superadministrator who… | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft Hevc Video ExtensionsMicrosoft Hevc Video Extensions FOR Licensed ApplicationsMicrosoft Hevc Video Extensions From Device Manufacturer | 8/9/2026 | 1/10/2026 | Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft Hevc Video ExtensionsMicrosoft Hevc Video Extensions FOR Licensed ApplicationsMicrosoft Hevc Video Extensions From Device Manufacturer | 8/9/2026 | 1/10/2026 | Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (5.3) | 0.30% | — | Snipeitapp Snipe-it | 8/9/2026 | 19/9/2026 | snipe-it before 8.7.0 contains an incorrect calculation vulnerability in checkout request handling that allows authenticated users to corrupt the assets.requests_counter through duplicate submissions and cancellations without active requests. Attackers can repeatedly call cancel endpoints without active requests to… | |
| Aplazada | Alta (7.1) | 0.25% | — | Easyappointments Easy AppointmentsAI | 8/9/2026 | 8/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Appointments allows DOM-Based XSS. This issue affects Easy Appointments: from n/a through 4.0.2.1. |