Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

3072 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (3.7)0.26%—Booking FOR Appointments AND Events CalendarAI13/8/202626/8/2026
The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authenticated employee (provider) is assigned to the appointment being accessed, allowing any employee to read any appointment by its identifier and disclose the booked customer's personal data.
AnalizadaAlta (8.7)0.78%—Microsoft Sharepoint Server11/8/202613/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (8.8)0.78%—Microsoft Sharepoint Server11/8/202613/8/2026
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (8.8)0.94%—Microsoft Sharepoint Server11/8/202613/8/2026
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (8.8)1.7%—Microsoft Sharepoint Server11/8/202613/8/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaCrítica (9.3)1.0%—Microsoft Sharepoint Server11/8/202616/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
AnalizadaMedia (5.5)0.43%—Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Office 2024+111/8/202614/8/2026
Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
AnalizadaAlta (8.8)2.0%—Microsoft Sharepoint Server11/8/202613/8/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.8)2.0%—Microsoft Sharepoint Server11/8/202613/8/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.8)1.7%—Microsoft Sharepoint Server11/8/202613/8/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.8)2.0%—Microsoft Sharepoint Server11/8/202613/8/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.8)2.0%—Microsoft Sharepoint Server11/8/202613/8/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaMedia (5.4)0.58%—Microsoft Sharepoint Server11/8/202613/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (8.8)0.94%—Microsoft Sharepoint Server11/8/202613/8/2026
Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
AnalizadaMedia (5.4)0.58%—Microsoft Sharepoint Server11/8/202613/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaMedia (5.4)0.58%—Microsoft Sharepoint Server11/8/202611/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (8.8)2.0%—Microsoft Sharepoint Server11/8/202612/8/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
ModificadaMedia (5.4)0.65%—Microsoft Sharepoint Server11/8/202619/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaMedia (5.4)0.58%—Microsoft Sharepoint Server11/8/202611/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (8.1)0.96%💥 PoCMicrosoft Sharepoint Server11/8/202613/8/2026
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
AnalizadaMedia (6.5)1.9%—Microsoft Sharepoint Server11/8/202612/8/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (8.8)2.0%—Microsoft Sharepoint Server11/8/202612/8/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaMedia (6.5)0.73%—Microsoft Sharepoint Server11/8/202612/8/2026
Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.
AnalizadaMedia (4.6)0.58%—Microsoft Sharepoint Server11/8/202613/8/2026
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaMedia (6.5)0.91%—Microsoft Sharepoint Server11/8/202613/8/2026
Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.