Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

736 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8)2.1%—Microsoft Sharepoint Server11/11/202517/6/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.8)2.5%—Microsoft Sharepoint Server14/10/202517/6/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (7.1)0.66%—Microsoft 365 AppsMicrosoft AccessMicrosoft ExcelMicrosoft Office+314/10/202517/6/2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
AnalizadaAlta (7.1)0.48%—Microsoft 365 AppsMicrosoft AccessMicrosoft ExcelMicrosoft Office+314/10/202517/6/2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
AnalizadaAlta (8.8)1.4%—Microsoft Sharepoint Server14/10/202517/6/2026
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+114/10/202517/6/2026
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7)0.39%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+114/10/202517/6/2026
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.71%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server9/9/202517/6/2026
Free of memory not on the heap in Microsoft Office allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.1)0.63%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Enterprise Server+29/9/202517/6/2026
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
AnalizadaAlta (8.8)20%💥 PoCMicrosoft Sharepoint Server9/9/202517/6/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (7.1)16%—Microsoft Sharepoint Server12/8/202517/6/2026
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
AnalizadaMedia (6.2)0.50%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Enterprise Server+212/8/202517/6/2026
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
AnalizadaAlta (8.4)0.55%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Enterprise Server+212/8/202517/6/2026
Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaAlta (8.8)19%—Microsoft Sharepoint Server12/8/202517/6/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaMedia (6.5)100%💥 ExploitMicrosoft Sharepoint Server20/7/202517/6/2026
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitMicrosoft Sharepoint Server20/7/20254/8/2026
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the…
AnalizadaMedia (6.5)99%⚠ Explotación activa💥 ExploitMicrosoft Sharepoint Enterprise ServerMicrosoft Sharepoint Server8/7/20254/8/2026
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (8.8)100%⚠ Explotación activa💥 ExploitMicrosoft Sharepoint Server8/7/202517/6/2026
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (7.8)0.67%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+18/7/202517/6/2026
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaAlta (8.8)1.2%—Microsoft Sharepoint Server8/7/202517/6/2026
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.6)3.0%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Enterprise Server8/7/202517/6/2026
Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally.
AnalizadaAlta (8.8)1.7%—Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint Server10/6/202517/6/2026
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (7.8)0.65%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Enterprise Server+210/6/202517/6/2026
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.64%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Enterprise Server+210/6/202517/6/2026
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaAlta (8.8)21%💥 ExploitMicrosoft Sharepoint Enterprise ServerMicrosoft Sharepoint Server10/6/202517/6/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.