Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3085▲ 506 respecto a la semana anterior
Críticas / altas1460▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
21.080 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.30% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 12/5/2026 | 17/6/2026 | Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 12/5/2026 | 17/6/2026 | Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | |
| Modificada | Alta (7.8) | 0.33% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 12/5/2026 | 17/6/2026 | Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | |
| Modificada | Alta (8.4) | 0.45% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+1 | 12/5/2026 | 17/6/2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Modificada | Alta (8.4) | 0.36% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Word | 12/5/2026 | 17/6/2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (8.4) | 0.36% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Word | 12/5/2026 | 17/6/2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (8.4) | 0.36% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 12/5/2026 | 17/6/2026 | Un desbordamiento de búfer basado en montículo (heap) en Microsoft Office permite a un atacante no autorizado ejecutar código localmente. | |
| Modificada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 12/5/2026 | 17/6/2026 | Un uso después de liberar (use-after-free) en Microsoft Office Excel permite a un atacante no autorizado ejecutar código localmente. | |
| Modificada | Alta (8.4) | 0.36% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Word | 12/5/2026 | 17/6/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 12/5/2026 | 17/6/2026 | Una lectura fuera de límites en Microsoft Office Excel permite a un atacante no autorizado divulgar información localmente. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 12/5/2026 | 17/6/2026 | Un uso después de liberar (use-after-free) en Microsoft Office Excel permite a un atacante no autorizado ejecutar código localmente. | |
| Modificada | Alta (8.4) | 0.36% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 12/5/2026 | 17/6/2026 | Un desbordamiento de búfer basado en montículo (heap) en Microsoft Office permite a un atacante no autorizado ejecutar código localmente. | |
| Analizada | Media (5.5) | 0.55% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Word | 12/5/2026 | 17/6/2026 | Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |
| Modificada | Alta (8.8) | 0.30% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 12/5/2026 | 17/6/2026 | Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (8.8) | 0.12% | — | Apple Macos | 12/5/2026 | 17/6/2026 | An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.2. An app may be able to break out of its sandbox. | |
| Analizada | Alta (7.5) | 0.23% | — | Apple IpadosApple Iphone OS | 12/5/2026 | 7/10/2026 | Se abordó un problema de inconsistencia en la interfaz de usuario con una gestión de estado mejorada. Este problema está solucionado en iOS 18.7.3 y iPadOS 18.7.3, iOS 26.2 y iPadOS 26.2. Una aplicación podría acceder a datos sensibles del usuario. | |
| Aplazada | Media (5.3) | 0.39% | — | Smart Appointment BookingAI | 12/5/2026 | 17/6/2026 | The Smart Appointment & Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and a nonce validation logic flaw in the saab_cancel_booking() function in all versions up to, and including, 1.0.8. The nonce check uses && (AND) instead of || (OR), which means… | |
| Aplazada | Crítica (9.1) | 0.27% | — | EPG INC Kura Sushi Official APPAI | 12/5/2026 | 17/6/2026 | "Kura Sushi Official App" provided by EPG, Inc. is vulnerable to improper certificate validation. A man-in-the-middle attack may allow eavesdropping on, or altering, the communication on push notifications between the affected application and the relevant server. | |
| Pendiente de análisis | Media (6.1) | 0.29% | — | SAP TAF ApplauncherAI | 12/5/2026 | 17/6/2026 | SAP TAF_APPLAUNCHER within Business Server Pages allows an unauthenticated attacker to craft malicious links that, when clicked by a victim, redirects them to attacker?controlled sites, potentially exposing or altering sensitive information in the victim�s browser. This results in a low impact on confidentiality and… | |
| Analizada | Media (6.5) | 1.9% | — | SAP Netweaver Application Server Abap | 12/5/2026 | 17/6/2026 | An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and ABAP Platform that allows an authenticated attacker with administrative access to execute specially crafted shell commands on the server, bypassing the logging mechanism. This allows the execution of unintended OS… | |
| Pendiente de análisis | Media (4.3) | 0.34% | — | SAP Application Server AbapAISAP NetweaverAISAP Abap PlatformAI | 12/5/2026 | 17/6/2026 | Due to a Code Injection vulnerability in SAP Application Server ABAP for SAP NetWeaver and ABAP Platform, an authenticated attacker could send specially crafted inputs to the application. If processed by the application, this input could be delivered to users subscribed to the channel and result in execution.… | |
| Analizada | Media (6.1) | 0.30% | — | SAP Netweaver Application Server Abap | 12/5/2026 | 17/6/2026 | Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages), an unauthenticated attacker could craft a URL that exploits an unprotected URL parameter to embed a malicious script. If a victim clicks the link, the injected input is… | |
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa💥 PoC | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Analizada | Alta (7.5) | 0.78% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/5/2026 | 17/6/2026 | A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. A remote attacker may be able to cause unexpected system termination… | |
| Analizada | Media (6.2) | 0.18% | — | Apple IpadosApple Iphone OSApple MacosApple Tvos+2 | 11/5/2026 | 17/6/2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An attacker on the local network may be able to cause a… |