Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1226 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 67% | — | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint Server | 9/5/2023 | 17/6/2026 | Microsoft SharePoint Server Spoofing Vulnerability | |
| Analizada | Alta (7.5) | 64% | ⚠ Explotación activa | Netapp Smi-s ProviderSuse Manager ServerSuse Linux Enterprise ServerVmware Esxi+1 | 25/4/2023 | 17/6/2026 | The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack with a significant amplification factor. | |
| Modificada | Media (5.3) | 0.64% | — | Github Enterprise Server | 7/4/2023 | 17/6/2026 | An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff. To do so, an attacker would need write access to the repository and be able to correctly guess the target branch before it’s created by the code maintainer. This vulnerability… | |
| Modificada | Media (5.3) | 0.46% | — | Github Enterprise Server | 7/4/2023 | 17/6/2026 | An improper authentication vulnerability was identified in GitHub Enterprise Server that allowed an unauthorized actor to modify other users' secret gists by authenticating through an SSH certificate authority. To do so, a user had to know the secret gist's URL. This vulnerability affected all versions of GitHub… | |
| Modificada | Alta (8.8) | 1.0% | — | Github Enterprise Server | 8/3/2023 | 17/6/2026 | A path traversal vulnerability was identified in GitHub Enterprise Server that allowed remote code execution when building a GitHub Pages site. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance. This vulnerability affected… | |
| Modificada | Media (4.3) | 0.57% | — | Github Enterprise Server | 7/3/2023 | 17/6/2026 | An information disclosure vulnerability was identified in GitHub Enterprise Server that allowed private repositories to be added to a GitHub Actions runner group via the API by a user who did not have access to those repositories, resulting in the repository names being shown in the UI. To exploit this vulnerability,… | |
| Modificada | Alta (8.8) | 0.84% | — | Github Enterprise Server | 2/3/2023 | 17/6/2026 | A code injection vulnerability was identified in GitHub Enterprise Server that allowed setting arbitrary environment variables from a single environment variable value in GitHub Actions when using a Windows based runner. To exploit this vulnerability, an attacker would need existing permission to control the value of… | |
| Modificada | Media (5.5) | 0.27% | — | Linux KernelSuse Linux Enterprise Server | 1/3/2023 | 17/6/2026 | In the Linux kernel before 6.2, mm/memory-tiers.c misinterprets the alloc_memory_type return value (expects it to be NULL in the error case, whereas it is actually an error pointer). NOTE: this is disputed by third parties because there are no realistic cases in which a user can cause the alloc_memory_type error case… | |
| Modificada | Media (6.5) | 0.68% | — | Github Enterprise Server | 16/2/2023 | 17/6/2026 | A path traversal vulnerability was identified in GitHub Enterprise Server that allowed arbitrary file reading when building a GitHub Pages site. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance. This vulnerability affected… | |
| Modificada | Alta (7.8) | 0.22% | — | Suse Linux Enterprise Module FOR SAP ApplicationsOpensuse LeapSuse Linux Enterprise Server | 15/2/2023 | 17/6/2026 | An Incorrect Default Permissions vulnerability in saphanabootstrap-formula of SUSE Linux Enterprise Module for SAP Applications 15-SP1, SUSE Linux Enterprise Server for SAP 12-SP5; openSUSE Leap 15.4 allows local attackers to escalate to root by manipulating the sudo configuration that is created. This issue affects:… | |
| Modificada | Alta (8.8) | 1.1% | — | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server | 14/2/2023 | 19/8/2026 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | |
| Modificada | Crítica (9.8) | 85% | 💥 PoC | Microsoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online ServerMicrosoft Office WEB Apps+4 | 14/2/2023 | 19/8/2026 | Microsoft Word Remote Code Execution Vulnerability | |
| Modificada | Crítica (9.8) | 1.2% | — | Github Enterprise Server | 17/1/2023 | 17/6/2026 | An incorrect authorization vulnerability was identified in GitHub Enterprise Server, allowing for escalation of privileges in GraphQL API requests from GitHub Apps. This vulnerability allowed an app installed on an organization to gain access to and modify most organization-level resources that are not tied to a… | |
| Modificada | Media (6.5) | 0.56% | — | Github Enterprise Server | 9/1/2023 | 17/6/2026 | An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a repository-scoped token with read/write access to modify Action Workflow files without a Workflow scope. The Create or Update file contents API should enforce workflow scope. This vulnerability affected all versions of… | |
| Modificada | Alta (7.2) | 1.1% | — | Github Enterprise Server | 14/12/2022 | 17/6/2026 | An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a scoped user-to-server token to escalate to full admin/owner privileges. An attacker would require an account with admin access to install a malicious GitHub App. This vulnerability was fixed in versions 3.3.17, 3.4.12,… | |
| Modificada | Alta (8.8) | 2.0% | — | Github Enterprise Server | 14/12/2022 | 17/6/2026 | A path traversal vulnerability was identified in GitHub Enterprise Server that allowed remote code execution when building a GitHub Pages site. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the instance. This vulnerability was fixed in versions 3.3.17,… | |
| Modificada | Crítica (9.8) | 1.5% | — | Github Enterprise Server | 14/12/2022 | 17/6/2026 | An improper limitation of a pathname to a restricted directory vulnerability was identified in GitHub Enterprise Server that enabled remote code execution. A check was added within Pages to ensure the working directory is clean before unpacking new content to prevent an arbitrary file overwrite bug. This vulnerability… | |
| Modificada | Alta (8.8) | 2.0% | — | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server | 13/12/2022 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Modificada | Media (6.5) | 0.74% | — | Github Enterprise Server | 1/12/2022 | 17/6/2026 | An improper privilege management vulnerability was identified in GitHub Enterprise Server that allowed users with improper privileges to create or delete pages via the API. To exploit this vulnerability, an attacker would need to be added to an organization's repo with write permissions. This vulnerability affected… | |
| Modificada | Media (6.5) | 1.1% | — | Nextcloud Enterprise ServerNextcloud ServerFedoraproject Fedora | 25/11/2022 | 17/6/2026 | Nextcloud server is an open source personal cloud server. Affected versions of nextcloud server did not properly limit user display names which could allow a malicious users to overload the backing database and cause a denial of service. It is recommended that the Nextcloud Server is upgraded to 22.2.10, 23.0.7 or… | |
| Modificada | Alta (8.8) | 1.2% | — | Github Enterprise Server | 23/11/2022 | 17/6/2026 | CRITICAL: An improper neutralization of argument delimiters in a command vulnerability was identified in GitHub Enterprise Server that enabled remote code execution. To exploit this vulnerability, an attacker would need permission to create and build GitHub Pages using GitHub Actions. This vulnerability affected only… | |
| Modificada | Media (6.5) | 1.6% | — | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server | 9/11/2022 | 10/8/2026 | Microsoft SharePoint Server Spoofing Vulnerability | |
| Modificada | Media (5.5) | 0.92% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online Server+4 | 9/11/2022 | 10/8/2026 | Microsoft Word Information Disclosure Vulnerability | |
| Modificada | Alta (8.8) | 1.6% | — | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server | 9/11/2022 | 10/8/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 1.2% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online Server+4 | 9/11/2022 | 10/8/2026 | Microsoft Word Remote Code Execution Vulnerability |