Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

1357 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)1.5%—Microsoft Sharepoint Server9/6/202623/7/2026
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
ModificadaMedia (5.4)0.59%—Microsoft Sharepoint Server9/6/202623/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (7.8)0.57%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+39/6/202623/7/2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
AnalizadaMedia (5.5)0.60%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+39/6/202623/7/2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
AnalizadaAlta (7.8)0.57%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+39/6/202623/7/2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
ModificadaMedia (6.1)0.60%—Microsoft Sharepoint Server9/6/202623/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
AplazadaAlta (8.6)0.15%—Nsasoft NetsharewatcherAI4/6/202622/7/2026
NetShareWatcher 1.5.8.0 contains a structured exception handler buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input. Attackers can craft a payload with overwritten SEH and NSEH pointers through the Restrictions custom filter field to trigger code execution…
ModificadaAlta (8)1.2%—Microsoft Sharepoint Server1/6/202622/7/2026
Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Pendiente de análisisAlta (8.2)0.32%—Espressif Shared Github DangerjsAI28/5/202617/6/2026
Espressif Shared GitHub DangerJS is a reusable GitHub Action CI DangerJS workflow for Espressif GitHub projects. Prior to 1.0.1, the action's entrypoint.sh invoked DangerJS from the caller's workspace after copying the fork's checkout into it, creating an untrusted search path for both binary resolution and Node.js…
AplazadaBaja (2.1)0.45%—Pingvin Share Pingvin-shareAI26/5/202623/7/2026
A security flaw has been discovered in stonith404 pingvin-share up to 1.13.0. This affects the function getServerSideProps of the file frontend/src/pages/auth/signIn.tsx of the component Sign-in Auto-Redirect. The manipulation of the argument redirect results in cross site scripting. The attack may be performed from…
AnalizadaAlta (8.8)2.7%⚠ Explotación activa💥 PoCMicrosoft Sharepoint Server22/5/202623/7/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AplazadaAlta (8.4)0.18%—Bytello Share Windows EditionAI13/5/202617/6/2026
Bytello Share (Windows Edition) installer executable provided by Bytello insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privilege of the user invoking the installer.
AnalizadaAlta (8.4)0.17%—Ashlar ArgonAshlar CobaltAshlar Cobalt ShareAshlar Lithium+112/5/202617/6/2026
An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose information or execute arbitrary code when a specially crafted VC6 file is being parsed.
AnalizadaAlta (8.4)0.17%—Ashlar ArgonAshlar CobaltAshlar Cobalt ShareAshlar Lithium+112/5/202617/6/2026
An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose information or execute arbitrary code when a specially crafted VC6 file is being parsed.
AnalizadaAlta (8.4)0.17%—Ashlar ArgonAshlar CobaltAshlar Cobalt ShareAshlar Lithium+112/5/202617/6/2026
An Out-of-Bounds Write vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to execute arbitrary code when a specially crafted VC6 file is being parsed.
AplazadaCrítica (9.1)0.53%—Pingvin Share XAI12/5/202617/6/2026
Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows an attacker who has obtained a valid username and password to skip the second-factor authentication (TOTP) requirement entirely. Although, an attacker still needs the…
AnalizadaAlta (8)2.1%—Microsoft Sharepoint Server12/5/202617/6/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
ModificadaAlta (8.4)0.45%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+112/5/202617/6/2026
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
ModificadaAlta (8.8)1.1%—Microsoft Sharepoint Server12/5/202617/6/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.8)2.3%—Microsoft Sharepoint Server12/5/202617/6/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.8)2.3%—Microsoft Sharepoint Server12/5/202617/6/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.8)2.3%—Microsoft Sharepoint Server12/5/202617/6/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.8)2.3%—Microsoft Sharepoint Server12/5/202617/6/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (7.6)0.43%—Clerk/astroClerk/backendClerk/chrome-extensionClerk/clerk-expo+1311/5/202617/6/2026
Clerk JavaScript is the official JavaScript repository for Clerk authentication. has(), auth.protect(), and related authorization predicates in @clerk/shared, @clerk/nextjs, @clerk/backend, and other framework SDKs can return true for certain combined authorization checks when the result should be false, allowing a…
AplazadaMedia (5.4)0.22%—Share-this-image Share This ImageAI29/4/202617/6/2026
Server-Side Request Forgery (SSRF) vulnerability in ILLID Share This Image share-this-image allows Server Side Request Forgery.This issue affects Share This Image: from n/a through <= 2.14.