Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
3072 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (3.7) | 0.26% | — | Booking FOR Appointments AND Events CalendarAI | 13/8/2026 | 26/8/2026 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authenticated employee (provider) is assigned to the appointment being accessed, allowing any employee to read any appointment by its identifier and disclose the booked customer's personal data. | |
| Analizada | Alta (8.7) | 0.78% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 0.94% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 1.7% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Crítica (9.3) | 1.0% | — | Microsoft Sharepoint Server | 11/8/2026 | 16/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.5) | 0.43% | — | Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Office 2024+1 | 11/8/2026 | 14/8/2026 | Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (8.8) | 2.0% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 2.0% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 1.7% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 2.0% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 2.0% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Media (5.4) | 0.58% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Alta (8.8) | 0.94% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Media (5.4) | 0.58% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.4) | 0.58% | — | Microsoft Sharepoint Server | 11/8/2026 | 11/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Alta (8.8) | 2.0% | — | Microsoft Sharepoint Server | 11/8/2026 | 12/8/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Modificada | Media (5.4) | 0.65% | — | Microsoft Sharepoint Server | 11/8/2026 | 19/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.4) | 0.58% | — | Microsoft Sharepoint Server | 11/8/2026 | 11/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Alta (8.1) | 0.96% | 💥 PoC | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | |
| Analizada | Media (6.5) | 1.9% | — | Microsoft Sharepoint Server | 11/8/2026 | 12/8/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Alta (8.8) | 2.0% | — | Microsoft Sharepoint Server | 11/8/2026 | 12/8/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Media (6.5) | 0.73% | — | Microsoft Sharepoint Server | 11/8/2026 | 12/8/2026 | Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network. | |
| Analizada | Media (4.6) | 0.58% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Media (6.5) | 0.91% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. |