Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
1357 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (3.3) | 0.57% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+3 | 14/7/2026 | 16/7/2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (8.7) | 0.95% | — | Microsoft Sharepoint Server | 14/7/2026 | 15/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.8) | 0.57% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+3 | 14/7/2026 | 16/7/2026 | Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.57% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+3 | 14/7/2026 | 16/7/2026 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (5.4) | 0.58% | — | Microsoft Sharepoint Server | 14/7/2026 | 15/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.5) | 0.60% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+3 | 14/7/2026 | 16/7/2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | |
| Analizada | Media (5.5) | 0.60% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+3 | 14/7/2026 | 16/7/2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | |
| Analizada | Media (5.5) | 0.45% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+3 | 14/7/2026 | 16/7/2026 | Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally. | |
| Analizada | Media (5.5) | 0.60% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+3 | 14/7/2026 | 16/7/2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (8.7) | 0.95% | — | Microsoft Sharepoint Server | 14/7/2026 | 15/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.4) | 0.58% | — | Microsoft Sharepoint Server | 14/7/2026 | 16/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.4) | 0.58% | — | Microsoft Sharepoint Server | 14/7/2026 | 15/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.4) | 0.58% | — | Microsoft Sharepoint Server | 14/7/2026 | 15/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Crítica (9.8) | 16% | ⚠ Explotación activa💥 Exploit | Microsoft Sharepoint Server | 14/7/2026 | 17/7/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | |
| Analizada | Crítica (9.8) | 1.0% | ⚠ Explotación activa💥 PoC | Microsoft Sharepoint Server | 14/7/2026 | 14/7/2026 | Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Media (6.5) | 1.1% | — | Microsoft Sharepoint Server | 14/7/2026 | 15/7/2026 | External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Crítica (9.8) | 3.0% | ⚠ Explotación activa💥 PoC | Microsoft Sharepoint Server | 14/7/2026 | 23/7/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | |
| Aplazada | Crítica (9.6) | 0.25% | — | Word Count AND Social SharesAI | 14/7/2026 | 14/7/2026 | The Word Count and Social Shares WordPress plugin through 1.0 does not validate a user-supplied file path before deletion, nor does it have proper authorization or CSRF checks, allowing any authenticated user, such as a Subscriber, to delete arbitrary files on the server, which can lead to a full site takeover (e.g.… | |
| Aplazada | Alta (8.5) | 0.39% | — | OwncloudAISharepoint FOR OwncloudAI | 6/7/2026 | 6/10/2026 | SharePoint for ownCloud is an application for using SharePoint with the file storage, synchronization, and sharing application ownCloud Classic. In SharePoint for ownCloud prior to version 0.4.1, which corresponds to ownCloud 10 prior to 10.15.3, an attacker with administrative privileges can use a SSRF vulnerability… | |
| Aplazada | Alta (8.2) | 0.20% | — | OpenprojectAIMicrosoft OnedriveAIMicrosoft SharepointAIMicrosoft Azure ADAI | 26/6/2026 | 29/6/2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, OpenProject's Storages module writes the OneDrive/SharePoint userless OAuth access_token plaintext to Rails.cache under the deterministic key storage.<id>.httpx_access_token, repopulated continuously by an hourly cron and… | |
| Aplazada | Media (5.4) | 0.23% | — | AI Share AND SummarizeAI | 24/6/2026 | 25/6/2026 | The AI Share & Summarize WordPress plugin before 2.0.4 does not sanitise and escape some of its shortcode attributes before outputting them in a page, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Pendiente de análisis | Alta (8.5) | 0.18% | — | Wondershare PdfelementAI | 19/6/2026 | 29/9/2026 | Wondershare PDFelement 5.2.9 contains a privilege escalation vulnerability due to an unquoted service path in the WsAppService Windows service. Local attackers can place a malicious executable in the service path and execute code with LocalSystem privileges upon service restart or system reboot. | |
| Aplazada | Media (4.3) | 0.19% | — | ShareaholicAI | 17/6/2026 | 17/6/2026 | Missing Authorization vulnerability in Shareaholic allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Shareaholic: from n/a through 9.7.11. | |
| Aplazada | Media (4.3) | 0.21% | — | Inisev Social Media AND Share IconsAI | 17/6/2026 | 1/10/2026 | : Missing Authorization vulnerability in Inisev Social Media & Share Icons allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Social Media & Share Icons: from n/a through 2.8.6. | |
| Aplazada | Alta (7.5) | 0.50% | — | Shared FilesAI | 15/6/2026 | 17/6/2026 | Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions. |