Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2814▼ 267 respecto a la semana anterior
Críticas / altas1316▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

21.069 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+211/8/202613/8/2026
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+211/8/202614/8/2026
Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Office 2024+111/8/202613/8/2026
Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaMedia (5.5)0.54%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+211/8/202614/8/2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
AnalizadaMedia (5.5)0.43%—Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Office 2024+111/8/202614/8/2026
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+111/8/202613/8/2026
Un desbordamiento de búfer basado en montículo (heap) en Microsoft Office permite a un atacante no autorizado ejecutar código localmente.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+211/8/202614/8/2026
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaMedia (5.5)0.54%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+211/8/202613/8/2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+211/8/202614/8/2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+211/8/202614/8/2026
Un desbordamiento de búfer basado en montículo (heap) en Microsoft Office permite a un atacante no autorizado ejecutar código localmente.
AnalizadaMedia (4.3)0.67%—Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Office 2024+111/8/202614/8/2026
Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
AnalizadaMedia (5.5)0.54%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+111/8/202613/8/2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
AnalizadaAlta (8.8)0.91%—Microsoft Windows APP11/8/202628/8/2026
Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.8)1.5%—Microsoft Windows APP11/8/202616/8/2026
Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2021Microsoft Office 202411/8/202614/8/2026
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaAlta (8.6)1.0%⚠ Explotación activaCisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense11/8/202616/9/2026
This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload,…
AnalizadaMedia (5.4)0.16%—Intel Approximate Bayesian Inference Framework11/8/20262/10/2026
Uncontrolled search path for some Approximate Bayesian Inference Framework before version on commit #484c949 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This…
AplazadaAlta (8.7)0.51%—Inventec Appliances Chiline CloudAI11/8/202626/8/2026
Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated remote attackers can modify a specific parameter to read other users' sensitive data.
Pendiente de análisisMedia (6.3)0.35%—SAP Netweaver Application Server AbapAI11/8/202626/8/2026
Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP, an authenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated victim accesses this link, the injected input is processed and reflected within the DOM on the client side during…
AnalizadaMedia (5.3)0.36%—SAP Approuter11/8/20268/9/2026
SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated attacker could send a specially crafted request to obtain limited unauthorized access to information. This results in a low impact on confidentiality. There is no impact on…
AnalizadaMedia (5.9)0.44%—SAP Approuter11/8/20268/9/2026
SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. Due to the complexity of the required conditions, an attacker with low privileges could send specially crafted requests to bypass authorization checks and reach protected resources beyond their…
AnalizadaMedia (5.9)0.20%—SAP Approuter11/8/20268/9/2026
SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker with low privileges could send a specially crafted request that bypasses the integrity check and loads another user's session context. Successful exploitation requires…
AnalizadaMedia (4.3)0.17%—SAP Approuter11/8/20268/9/2026
SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An unauthenticated attacker could craft a malicious link and trick a victim into following it. Successful exploitation could allow the attacker to bind the victim's session to an attacker-controlled identity,…
AnalizadaBaja (3.7)0.35%—SAP Approuter11/8/20268/9/2026
SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this under a non-default configuration. Successful exploitation is highly complex, as it depends on conditions outside the attacker's control. This could result in a low impact on availability. There is…
AnalizadaMedia (4.3)0.38%—SAP Approuter11/8/20268/9/2026
SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could send high volumes of data without consuming responses, causing unbounded memory growth. This results in a low impact on availability. There is no impact on confidentiality and integrity.