Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1226 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.2% | — | Github Enterprise Server | 25/1/2022 | 17/6/2026 | A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed more permissions to be granted during a GitHub App's user-authorization web flow than was displayed to the user during approval. To exploit this vulnerability, an attacker would need to create a GitHub App on the instance and… | |
| Modificada | Alta (7.8) | 2.3% | — | Microsoft Sharepoint Enterprise ServerMicrosoft Word | 11/1/2022 | 17/6/2026 | Microsoft Word Remote Code Execution Vulnerability | |
| Modificada | Alta (8.8) | 3.1% | — | Microsoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online Server+3 | 11/1/2022 | 17/6/2026 | Microsoft Office Remote Code Execution Vulnerability | |
| Modificada | Alta (8.8) | 1.9% | — | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint Server | 29/12/2021 | 17/6/2026 | Microsoft SharePoint Elevation of Privilege Vulnerability | |
| Modificada | Media (5.7) | 1.2% | — | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server | 15/12/2021 | 17/6/2026 | Microsoft SharePoint Server Spoofing Vulnerability | |
| Modificada | Media (5.7) | 1.5% | — | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint Server | 15/12/2021 | 17/6/2026 | Microsoft SharePoint Server Spoofing Vulnerability | |
| Modificada | Alta (8.8) | 2.7% | — | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server | 15/12/2021 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Modificada | Alta (7.2) | 2.2% | — | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server | 15/12/2021 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Analizada | Alta (7.5) | 25% | 💥 PoC | Balasys DheaterSiemens Scalance W1750d FirmwareSuse Linux Enterprise ServerF5 Big-ip Access Policy Manager+26 | 11/11/2021 | 23/9/2026 | The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network… | |
| Modificada | Media (6.5) | 1.1% | — | Github Enterprise Server | 10/11/2021 | 17/6/2026 | A path traversal vulnerability was identified in GitHub Pages builds on GitHub Enterprise Server that could allow an attacker to read system files. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance. This vulnerability… | |
| Modificada | Alta (7.8) | 2.3% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+3 | 10/11/2021 | 19/8/2026 | Microsoft Excel Remote Code Execution Vulnerability | |
| Modificada | Alta (8.8) | 6.5% | — | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server | 13/10/2021 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Modificada | Alta (8.8) | 48% | — | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server | 13/10/2021 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 6.0% | — | Microsoft OfficeMicrosoft Office Online ServerMicrosoft Office WEB Apps ServerMicrosoft Sharepoint Enterprise Server+2 | 13/10/2021 | 17/6/2026 | Microsoft Word Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 2.7% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+2 | 13/10/2021 | 17/6/2026 | Microsoft Excel Remote Code Execution Vulnerability | |
| Modificada | Baja (3.5) | 1.4% | — | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server | 13/10/2021 | 17/6/2026 | Microsoft SharePoint Server Spoofing Vulnerability | |
| Modificada | Crítica (9.8) | 1.2% | — | Github Enterprise Server | 24/9/2021 | 17/6/2026 | An improper access control vulnerability in GitHub Enterprise Server allowed a workflow job to execute in a self-hosted runner group it should not have had access to. This affects customers using self-hosted runner groups for access control. A repository with access to one enterprise runner group could access all of… | |
| Modificada | Media (4.3) | 0.93% | — | Github Enterprise Server | 24/9/2021 | 17/6/2026 | A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently restricted and made it possible to read files on the GitHub Enterprise Server instance. To exploit this… | |
| Modificada | Baja (3.5) | 1.3% | — | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint Foundation | 15/9/2021 | 10/8/2026 | Microsoft SharePoint Server Spoofing Vulnerability | |
| Modificada | Baja (3.5) | 1.3% | — | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server | 15/9/2021 | 10/8/2026 | Microsoft SharePoint Server Spoofing Vulnerability | |
| Modificada | Media (4.3) | 4.0% | — | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint Server | 12/8/2021 | 10/8/2026 | Microsoft SharePoint Server Spoofing Vulnerability | |
| Modificada | Alta (7.1) | 0.30% | — | Suse Linux Enterprise ServerOpensuse Factory | 28/7/2021 | 17/6/2026 | A UNIX Symbolic Link (Symlink) Following vulnerability in the clone-master-clean-up.sh script of clone-master-clean-up in SUSE Linux Enterprise Server 12 SP3, SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allows local attackers to delete arbitrary files. This issue affects: SUSE Linux Enterprise Server 12 SP3… | |
| Modificada | Media (6.5) | 1.2% | — | Github Enterprise Server | 14/7/2021 | 17/6/2026 | A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently restricted and made it possible to read files on the GitHub Enterprise Server instance. To exploit this… | |
| Modificada | Alta (8.1) | 1.3% | — | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server | 8/6/2021 | 17/6/2026 | Microsoft SharePoint Server Spoofing Vulnerability | |
| Modificada | Alta (8.8) | 3.0% | — | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server | 8/6/2021 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability |