Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

3072 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)1.2%—Microsoft Sharepoint Server11/8/202611/8/2026
Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
AnalizadaMedia (5.4)0.47%—Microsoft Sharepoint Server11/8/202611/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (8.8)0.94%—Microsoft Sharepoint Server11/8/202612/8/2026
Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
AnalizadaMedia (6.5)0.91%—Microsoft Sharepoint Server11/8/202612/8/2026
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaMedia (5.4)0.62%—Microsoft Sharepoint Server11/8/202612/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaMedia (5.5)0.48%—Microsoft Defender FOR Endpoint11/8/202617/8/2026
Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information locally.
AnalizadaAlta (8.8)2.1%⚠ Explotación activa💥 PoCMicrosoft Sharepoint Server11/8/202626/9/2026
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Pendiente de análisisAlta (8.1)1.5%—Ivanti Endpoint ManagerAI11/8/202631/8/2026
Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker in a MITM position to leak credentials for external SQL connections.
Pendiente de análisisAlta (7.7)0.72%—Ivanti Endpoint ManagerAI11/8/202631/8/2026
External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage.
Pendiente de análisisAlta (7.5)1.6%—Ivanti Endpoint ManagerAI11/8/202631/8/2026
An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker to crash an agent service.
AplazadaMedia (5.3)0.30%—Pinpoint Booking SystemAI10/8/202626/8/2026
The Pinpoint Booking System WordPress plugin through 2.9.9.7.1 does not validate the booking price on the server side, allowing unauthenticated users to create bookings at an arbitrary price (including zero) and, by selecting a specific payment method, obtain an instantly-approved reservation.
AplazadaBaja (3.8)0.26%—Booking FOR Appointments AND Events CalendarAI10/8/202626/8/2026
The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose record is being accessed, allowing any employee with an Employee Panel login to read and modify the stored personal data of any customer by enumerating…
AplazadaMedia (5.5)0.43%—Sourcecodester Simple Doctors Appointment SystemAI10/8/202612/8/2026
A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=set_appointment. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been made available to…
AplazadaMedia (5.3)0.30%—Dwbooster Appointment Hour BookingAI8/8/202626/8/2026
The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against the server-side configured service price, allowing unauthenticated users to submit an arbitrary final price (including zero or negative) that is stored as the authoritative booking price, corrupting…
AplazadaMedia (5.5)0.43%—Sourcecodester Simple Doctors Appointment SystemAI7/8/202612/8/2026
A security flaw has been discovered in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=delete_appointment. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to…
AnalizadaAlta (7.5)0.46%—Cisco Secure Endpoint7/8/202619/8/2026
A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in XAR files during…
AnalizadaCrítica (9.6)0.86%—Microsoft Sharepoint Online7/8/20267/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Pendiente de análisisMedia (5.3)0.36%—Langchain Langgraph Checkpoint PostgresAILangchain Langgraph Checkpoint SqliteAI6/8/202610/9/2026
LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoint saver. Prior to 3.1.1, the langgraph-checkpoint-postgres and langgraph-checkpoint-sqlite packages persisted hierarchical namespaces as a dot joined string and scoped reads by matching that string…
AplazadaCrítica (9.4)0.38%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the route `POST /api/tenants/{tenantId}/staff/{staffId}/crypto` accepts and stores attacker-controlled ML-KEM-768 public keys against any tenant on the platform without authentication.…
AplazadaCrítica (9.8)0.57%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the registration handler at `POST /api/auth/register/{userId}` validates the relationship between the WebAuthn challenge and the registration cookie's email but never validates that the…
AplazadaCrítica (9.9)0.44%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN promotes themselves to platform-wide GLOBAL_ADMIN through a single PUT request. The role-update handler accepts the `GLOBAL_ADMIN` enum value from any tenant admin updating…
AplazadaAlta (7.4)0.39%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Versions prior to 1.0.2 don't throttle failed passphrase login attempts. An attacker can submit unlimited wrong passphrase guesses against any known email address, capped only by the Argon2 verification cost…
AplazadaMedia (6.5)0.36%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the `/api/log` endpoint accepts unauthenticated POST requests, applies no schema validation to the message body, writes attacker-controlled content directly into the application's stdout…
AplazadaBaja (3.7)0.39%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.6, the bootstrap challenge endpoint at `/api/tenants/{id}/appointments/bootstrap-challenge` issues a SHA-256 proof-of-work with `difficulty=4` hex zeros, equivalent to 16 bits of work.…
AplazadaAlta (8.1)0.24%—Openreception Appointment Booking SoftwareAI6/8/20268/9/2026
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN can store `javascript:` URLs in the tenant `links` configuration (`website`, `imprint`, `privacyStatement`). These values are returned to the patient-facing landing page…