Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

3072 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.78%—Microsoft Sharepoint Server8/9/20269/9/2026
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.99%—Microsoft Sharepoint Server8/9/20269/9/2026
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
AnalizadaMedia (5.4)0.40%—Microsoft Sharepoint Server8/9/20269/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (7.7)0.84%—Microsoft Sharepoint Server8/9/20269/9/2026
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
AnalizadaAlta (8.8)0.82%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+28/9/202617/9/2026
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.
AnalizadaMedia (6.5)1.00%—Microsoft Sharepoint Server8/9/20269/9/2026
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
AnalizadaMedia (4.8)0.40%—Microsoft Sharepoint Server8/9/202610/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (8.8)0.78%—Microsoft Sharepoint Server8/9/20269/9/2026
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.91%—Microsoft Sharepoint Server8/9/20269/9/2026
Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
AnalizadaMedia (5.4)0.45%—Microsoft Sharepoint Server8/9/20269/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaMedia (6.5)1.00%—Microsoft Sharepoint Server8/9/20269/9/2026
Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
AnalizadaMedia (5.4)0.45%—Microsoft Sharepoint Server8/9/202610/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (8.8)0.78%—Microsoft Sharepoint Server8/9/20269/9/2026
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.78%—Microsoft Sharepoint Server8/9/20269/9/2026
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.78%—Microsoft Sharepoint Server8/9/20269/9/2026
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.8)1.0%—Ivanti Endpoint Manager Mobile8/9/20269/9/2026
Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin.
AplazadaAlta (7.1)0.25%—Easyappointments Easy AppointmentsAI8/9/20268/9/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Appointments allows DOM-Based XSS. This issue affects Easy Appointments: from n/a through 4.0.2.1.
Pendiente de análisisMedia (6.3)0.38%—Zoho Manageengine Endpoint CentralAI7/9/20268/9/2026
Zohocorp ManageEngine Endpoint Central versions below 11.5.2600.15 are vulnerable to Privilege Escalation Due to Outdated Component
Pendiente de análisisMedia (5)0.29%—Zoho Manageengine Endpoint CentralAI7/9/20268/9/2026
Zohocorp ManageEngine Endpoint Central versions below 11.5.2605.01 are vulnerable to Local privilege escalation due to loading a dll from an untrusted path.
Pendiente de análisisMedia (6.3)0.38%—Zohocorp Manageengine Endpoint CentralAI7/9/20268/9/2026
Zohocorp ManageEngine Endpoint Central versions below 11.4.2540.23 are vulnerable to Privilege Escalation During JAR Extraction
Pendiente de análisisMedia (5.7)0.35%—Zohocorp Manageengine Endpoint CentralAI7/9/20268/9/2026
Zohocorp ManageEngine Endpoint Central versions before 11.5.2605.01 are vulnerable to local privilege escalation due to Agent upgrade.
AplazadaMedia (5.5)0.43%—Code-projects Doctor Appointment SystemAI4/9/20264/9/2026
A flaw has been found in code-projects Doctor Appointment System 1.0. This issue affects some unknown processing of the file /contactus.php. This manipulation of the argument firstname causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.
AplazadaMedia (5.5)0.43%—Code-projects Doctor Appointment SystemAI4/9/202611/9/2026
A vulnerability was detected in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient/booking.php. The manipulation of the argument doc_id results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.
AplazadaMedia (5.5)0.43%—Code-projects Doctor Appointment SystemAI3/9/20265/9/2026
A vulnerability was identified in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient_login.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.
AplazadaCrítica (9.3)0.40%—VikappointmentsAI3/9/20263/9/2026
Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions.