Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

160 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4)38%💥 ExploitMicrosoft Forms ServerMicrosoft GrooveMicrosoft Groove Data Bridge ServerMicrosoft Groove Management Server+615/9/201116/6/2026
Microsoft Office Groove 2007 SP2, SharePoint Workspace 2010 Gold and SP1, Office Forms Server 2007 SP2, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Office Groove Data Bridge Server 2007 SP2, Office Groove Management Server 2007 SP2, Groove Server 2010 Gold and SP1, Windows SharePoint…
ModificadaMedia (4.3)2.0%—Tibco Iprocess EngineTibco Iprocess Workspace20/5/201116/6/2026
Session fixation vulnerability in TIBCO iProcess Engine before 11.1.3 and iProcess Workspace before 11.3.1 allows remote attackers to hijack web sessions via unspecified vectors.
ModificadaMedia (4.3)1.3%—Tibco Iprocess EngineTibco Iprocess Workspace20/5/201116/6/2026
Cross-site scripting (XSS) vulnerability in TIBCO iProcess Engine before 11.1.3 and iProcess Workspace before 11.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.8)2.2%—Sybase Appeon FOR PowerbuilderSybase EaserverSybase Replication ServerSybase Workspace20/1/201116/6/2026
Directory traversal vulnerability in Sybase EAServer 6.x before 6.3 ESD#2, as used in Appeon, Replication Server Messaging Edition (RSME), and WorkSpace, allows remote attackers to read arbitrary files via "../\" (dot dot forward-slash backslash) sequences in a crafted request.
ModificadaAlta (10)4.5%—Sybase Appeon FOR PowerbuilderSybase EaserverSybase Replication ServerSybase Workspace20/1/201116/6/2026
Unspecified vulnerability in Sybase EAServer 5.x and 6.x before 6.3 ESD#2, as used in Appeon, Replication Server Messaging Edition (RSME), and WorkSpace, allows remote attackers to install arbitrary web services and execute arbitrary code, related to a "design vulnerability."
ModificadaAlta (9.3)2.5%—Symantec Workspace StreamingSymantec Appstream17/6/201016/6/2026
Symantec AppStream 5.2.x and Symantec Workspace Streaming (SWS) 6.1.x before 6.1 SP4 do not properly perform authentication, which allows remote Workspace Streaming servers and man-in-the-middle attackers to download arbitrary executable files onto a client system, and execute these files, via unspecified vectors.
ModificadaAlta (7.5)3.6%—Groove WorkspaceGroove Virtual Office20/5/200516/6/2026
Unknown vulnerability in Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 allows remote attackers to bypass restrictions on COM objects.
ModificadaMedia (6.8)3.0%—Groove WorkspaceGroove Virtual Office20/5/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Groove Mobile Workspace in Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 allow remote attackers to inject arbitrary web script or HTML via the (1) picture columns embedded within SharePoint lists…
ModificadaMedia (4.6)0.97%—Groove WorkspaceGroove Virtual Office20/5/200516/6/2026
Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 installs the client installation directories with insecure EVERYBODY permissions, which allows local users to gain sensitive information.
ModificadaBaja (2.6)1.6%—Groove WorkspaceGroove Virtual Office20/5/200516/6/2026
Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 does not properly display file extensions on attached or embedded files in a compound document, which may allow remote attackers to trick users into executing malicious code.
Orbitaley — Vulnerabilidades