Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1226 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.79%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online Server+49/11/202210/8/2026
Microsoft Word Information Disclosure Vulnerability
ModificadaMedia (5.7)0.70%—Github Enterprise Server1/11/202217/6/2026
An improper cache key vulnerability was identified in GitHub Enterprise Server that allowed an unauthorized actor to access private repository files through a public repository. To exploit this, an actor would need to already be authorized on the GitHub Enterprise Server instance, be able to create a public…
ModificadaMedia (6.5)0.50%—Nextcloud Enterprise ServerNextcloud Server27/10/202217/6/2026
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. In Nextcloud Server prior to versions 23.0.9 and 24.0.5 and Nextcloud Enterprise Server prior to versions 22.2.10.5, 23.0.9, and 24.0.5 an attacker reading `nextcloud.log` may gain knowledge of credentials to connect to a…
ModificadaMedia (4.3)0.91%—Nextcloud Enterprise ServerNextcloud Server27/10/202217/6/2026
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server prior to versions 23.0.10 and 24.0.6 and Nextcloud Enterprise Server prior to versions 22.2.10, 23.0.10, and 24.0.6 are vulnerable to a logged-in attacker slowing down the system by generating a lot of…
ModificadaMedia (5.3)0.67%—Nextcloud Enterprise ServerNextcloud Server27/10/202217/6/2026
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Nextcloud Server and Nextcloud Enterprise Server prior to versions 23.0.9 and 24.0.5 are vulnerable to exposure of information that cannot be controlled by administrators without direct database access. Versions 23.0.9 and…
ModificadaAlta (8.8)2.1%—Github Enterprise Server19/10/202217/6/2026
A deserialization of untrusted data vulnerability was identified in GitHub Enterprise Server that could potentially lead to remote code execution on the SVNBridge. To exploit this vulnerability, an attacker would need to gain access via a server-side request forgery (SSRF) that would let an attacker control the data…
ModificadaAlta (8.8)76%—Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server11/10/202217/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
ModificadaMedia (4.4)0.15%—Opensuse LeapOpensuse Leap MicroSuse Linux Enterprise Server6/10/202217/6/2026
A Incorrect Authorization vulnerability in chkstat of SUSE Linux Enterprise Server 12-SP5; openSUSE Leap 15.3, openSUSE Leap 15.4, openSUSE Leap Micro 5.2 did not consider group writable path components, allowing local attackers with access to a group what can write to a location included in the path to a privileged…
ModificadaMedia (5.5)0.22%—IBM Java SDKSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KITRedhat Satellite+429/9/202217/6/2026
IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 before SR16 FP7, and 5.0 before SR16 FP13 stores plaintext information in memory dumps, which allows local users to obtain sensitive information by reading a file.
ModificadaMedia (5.3)0.96%—Nextcloud Enterprise ServerNextcloud Server16/9/202217/6/2026
Nextcloud server is an open source personal cloud platform. In affected versions it was found that locally running webservices can be found and requested erroneously. It is recommended that the Nextcloud Server is upgraded to 23.0.8 or 24.0.4. It is recommended that the Nextcloud Enterprise Server is upgraded to…
ModificadaAlta (7.5)0.76%—Nextcloud Enterprise ServerNextcloud Server15/9/202217/6/2026
Nextcloud server is an open source personal cloud product. Affected versions of this package are vulnerable to Information Exposure which fails to strip the Authorization header on HTTP downgrade. This can lead to account access exposure and compromise. It is recommended that the Nextcloud Server is upgraded to 23.0.7…
ModificadaAlta (8.8)2.1%—Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server13/9/202217/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
ModificadaAlta (8.8)2.0%—Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server13/9/202217/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
ModificadaAlta (8.8)51%—Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server13/9/202217/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
ModificadaAlta (8.8)54%—Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server13/9/202217/6/2026
Microsoft SharePoint Remote Code Execution Vulnerability
ModificadaMedia (5.4)0.60%—Github Enterprise Server2/8/202217/6/2026
A stored XSS vulnerability was identified in GitHub Enterprise Server that allowed the injection of arbitrary attributes. This injection was blocked by Github's Content Security Policy (CSP). This vulnerability affected all versions of GitHub Enterprise Server prior to 3.6 and was fixed in versions 3.3.11, 3.4.6 and…
ModificadaAlta (8.8)11%—Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server10/5/202217/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
ModificadaAlta (7.8)0.58%—Samba Cifs-utilsDebian LinuxSuse Caas PlatformSuse Enterprise Storage+1527/4/202217/6/2026
In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.
ModificadaAlta (8.8)1.7%—Github Enterprise Server5/4/202217/6/2026
A path traversal vulnerability was identified in GitHub Enterprise Server management console that allowed the bypass of CSRF protections. This could potentially lead to privilege escalation. To exploit this vulnerability, an attacker would need to target a user that was actively logged into the management console.…
ModificadaAlta (7.8)0.50%—Cobbler Project CobblerOpensuse FactoryOpensuse BackportsSuse Linux Enterprise Server+119/2/202217/6/2026
An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring. (Only lines beginning with #import are blocked.)
ModificadaAlta (8.8)2.2%—Github Enterprise Server18/2/202217/6/2026
A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance. This vulnerability affected all…
ModificadaAlta (8.8)17%—Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server9/2/202217/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
ModificadaAlta (8)2.0%—Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server9/2/202217/6/2026
Microsoft SharePoint Server Spoofing Vulnerability
ModificadaMedia (4.3)2.1%—Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server9/2/202217/6/2026
Microsoft SharePoint Server Security Feature Bypass Vulnerability
AnalizadaAlta (7.8)94%⚠ Explotación activa💥 ExploitPolkit Project PolkitRedhat Enterprise Linux Server Update Services FOR SAP SolutionsRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+2628/1/202215/8/2026
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends…