Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
736 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.60% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+3 | 14/7/2026 | 16/7/2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | |
| Analizada | Media (5.5) | 0.45% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+3 | 14/7/2026 | 16/7/2026 | Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally. | |
| Analizada | Media (5.5) | 0.60% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+3 | 14/7/2026 | 16/7/2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (8.7) | 0.95% | — | Microsoft Sharepoint Server | 14/7/2026 | 15/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.4) | 0.58% | — | Microsoft Sharepoint Server | 14/7/2026 | 16/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.4) | 0.58% | — | Microsoft Sharepoint Server | 14/7/2026 | 15/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.4) | 0.58% | — | Microsoft Sharepoint Server | 14/7/2026 | 15/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Crítica (9.8) | 16% | ⚠ Explotación activa💥 Exploit | Microsoft Sharepoint Server | 14/7/2026 | 17/7/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | |
| Analizada | Crítica (9.8) | 1.0% | ⚠ Explotación activa💥 PoC | Microsoft Sharepoint Server | 14/7/2026 | 14/7/2026 | Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Media (6.5) | 1.1% | — | Microsoft Sharepoint Server | 14/7/2026 | 15/7/2026 | External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Crítica (9.8) | 3.0% | ⚠ Explotación activa💥 PoC | Microsoft Sharepoint Server | 14/7/2026 | 23/7/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | |
| Aplazada | Alta (8.5) | 0.39% | — | OwncloudAISharepoint FOR OwncloudAI | 6/7/2026 | 6/10/2026 | SharePoint for ownCloud is an application for using SharePoint with the file storage, synchronization, and sharing application ownCloud Classic. In SharePoint for ownCloud prior to version 0.4.1, which corresponds to ownCloud 10 prior to 10.15.3, an attacker with administrative privileges can use a SSRF vulnerability… | |
| Aplazada | Alta (8.2) | 0.20% | — | OpenprojectAIMicrosoft OnedriveAIMicrosoft SharepointAIMicrosoft Azure ADAI | 26/6/2026 | 29/6/2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, OpenProject's Storages module writes the OneDrive/SharePoint userless OAuth access_token plaintext to Rails.cache under the deterministic key storage.<id>.httpx_access_token, repopulated continuously by an hourly cron and… | |
| Analizada | Media (4.6) | 0.58% | — | Microsoft Sharepoint Server | 9/6/2026 | 23/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Modificada | Media (5.4) | 1.1% | — | Microsoft Sharepoint Server | 9/6/2026 | 23/7/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Modificada | Media (5.4) | 0.58% | — | Microsoft Sharepoint Server | 9/6/2026 | 23/7/2026 | Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.4) | 0.58% | — | Microsoft Sharepoint Server | 9/6/2026 | 23/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Modificada | Media (5.4) | 0.59% | — | Microsoft Sharepoint Server | 9/6/2026 | 23/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.4) | 0.58% | — | Microsoft Sharepoint Server | 9/6/2026 | 23/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.4) | 0.58% | — | Microsoft Sharepoint Server | 9/6/2026 | 23/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Modificada | Media (5.4) | 0.59% | — | Microsoft Sharepoint Server | 9/6/2026 | 23/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | |
| Modificada | Media (5.4) | 0.53% | — | Microsoft Sharepoint Server | 9/6/2026 | 23/7/2026 | Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Alta (8) | 0.98% | — | Microsoft Sharepoint Server | 9/6/2026 | 23/7/2026 | Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Baja (3.3) | 0.56% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+3 | 9/6/2026 | 23/7/2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (8.8) | 2.3% | — | Microsoft Sharepoint Server | 9/6/2026 | 23/7/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. |