Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
66 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 30% | 💥 Exploit | Microsoft Live MeetingMicrosoft LyncMicrosoft Lync BasicMicrosoft Office | 15/8/2015 | 17/6/2026 | Microsoft Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, and Lync Basic 2013 SP1 allow remote attackers to execute arbitrary code via a crafted Office Graphics Library (OGL) font, aka "Microsoft Office Graphics Component Remote Code Execution Vulnerability." | |
| Analizada | Alta (7.8) | 49% | ⚠ Explotación activa | Microsoft .net FrameworkMicrosoft Live MeetingMicrosoft LyncMicrosoft Silverlight | 13/5/2015 | 17/6/2026 | The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2; Live Meeting 2007 Console; Lync 2010; Lync 2010 Attendee; Lync 2013 SP1; Lync Basic 2013 SP1; Silverlight 5 before 5.1.40416.00; and Silverlight 5 Developer Runtime before… | |
| Modificada | Media (5) | 19% | — | Microsoft Lync Server | 10/9/2014 | 17/6/2026 | The Server in Microsoft Lync Server 2013 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon hang) via a crafted request, aka "Lync Denial of Service Vulnerability." | |
| Modificada | Media (4.3) | 11% | — | Microsoft Lync Server | 10/9/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Web Components Server in Microsoft Lync Server 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Lync XSS Information Disclosure Vulnerability." | |
| Modificada | Media (5) | 20% | — | Microsoft Lync Server | 10/9/2014 | 17/6/2026 | The Response Group Service in Microsoft Lync Server 2010 and 2013 and the Core Components in Lync Server 2013 do not properly handle exceptions, which allows remote attackers to cause a denial of service (daemon hang) via a crafted call, aka "Lync Denial of Service Vulnerability." | |
| Modificada | Media (4.3) | 51% | — | Microsoft Lync Server | 11/6/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Web Components Server in Microsoft Lync Server 2010 and 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted URL containing a valid meeting ID, aka "Lync Server Content Sanitization Vulnerability." | |
| Analizada | Alta (7.8) | 85% | ⚠ Explotación activa💥 Exploit | Microsoft Excel ViewerMicrosoft LyncMicrosoft OfficeMicrosoft Office Compatibility Pack+4 | 6/11/2013 | 16/6/2026 | GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync 2010, 2010 Attendee, 2013, and Basic 2013 allows remote attackers to execute arbitrary code via a crafted TIFF image, as demonstrated by an image in a Word document, and… | |
| Modificada | Alta (7.8) | 32% | — | Microsoft .net FrameworkMicrosoft LyncMicrosoft Lync BasicMicrosoft Office+10 | 10/7/2013 | 16/6/2026 | Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.sys in the kernel-mode drivers, and GDI+, DirectWrite, and Journal, in Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server… | |
| Modificada | Alta (9.3) | 22% | — | Microsoft LyncMicrosoft Lync ServerMicrosoft Office Communicator | 15/5/2013 | 16/6/2026 | Microsoft Communicator 2007 R2, Lync 2010, Lync 2010 Attendee, and Lync Server 2013 do not properly handle objects in memory, which allows remote attackers to execute arbitrary code via an invitation that triggers access to a deleted object, aka "Lync RCE Vulnerability." | |
| Modificada | Media (4.3) | 28% | — | Microsoft Groove ServerMicrosoft InfopathMicrosoft LyncMicrosoft Office Communicator+4 | 9/10/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Microsoft InfoPath 2007 SP2 and SP3 and 2010 SP1, Communicator 2007 R2, Lync 2010 and 2010 Attendee, SharePoint Server 2007 SP2 and SP3 and 2010 SP1, Groove Server 2010 SP1, Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010 SP1, and Office Web Apps 2010 SP1… | |
| Modificada | Media (4.3) | 22% | 💥 Exploit | Microsoft LyncMicrosoft Office CommunicatorMicrosoft Internet Explorer | 12/6/2012 | 16/6/2026 | The toStaticHTML API (aka the SafeHTML component) in Microsoft Internet Explorer 8 and 9, Communicator 2007 R2, and Lync 2010 and 2010 Attendee does not properly handle event attributes and script, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted HTML document, aka… | |
| Modificada | Alta (9.3) | 18% | — | Microsoft Lync | 12/6/2012 | 16/6/2026 | Untrusted search path vulnerability in Microsoft Lync 2010, 2010 Attendee, and 2010 Attendant allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .ocsmeet file, aka "Lync Insecure Library Loading Vulnerability." | |
| Modificada | Alta (7.5) | 1.7% | 💥 Exploit | Tamlyncreative COM Bfquiztrial | 2/11/2011 | 16/6/2026 | SQL injection vulnerability in the BF Quiz (com_bfquiztrial) component before 1.3.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a bfquiztrial action to index.php. | |
| Modificada | Alta (7.5) | 18% | 💥 Exploit | Tamlyncreative COM Bfsurvey ProfreeTamlyncreative COM Bfsurvey PROTamlyncreative COM Bfsurvey Basic | 9/6/2010 | 16/6/2026 | Directory traversal vulnerability in the BF Survey (com_bfsurvey) component for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Tamlyncreative COM Bfsurvey ProfreeTamlyncreative COM Bfsurvey PROTamlyncreative COM Bfsurvey Basic | 9/6/2010 | 16/6/2026 | SQL injection vulnerability in the BF Survey Pro (com_bfsurvey_pro) component before 1.3.1, BF Survey Pro Free (com_bfsurvey_profree) component 1.2.6, and BF Survey Basic component before 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php. NOTE: some of these… | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Tamlyncreative COM Bfsurvey Profree | 18/1/2010 | 16/6/2026 | SQL injection vulnerability in the updateOnePage function in components/com_bfsurvey_pro/controller.php in BF Survey Pro Free (com_bfsurvey_profree) 1.2.4, and other versions before 1.2.6, a component for Joomla!, allows remote attackers to execute arbitrary SQL commands via the table parameter in an updateOnePage… |