Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

1226 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.2%—Github Enterprise Server25/1/202217/6/2026
A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed more permissions to be granted during a GitHub App's user-authorization web flow than was displayed to the user during approval. To exploit this vulnerability, an attacker would need to create a GitHub App on the instance and…
ModificadaAlta (7.8)2.3%—Microsoft Sharepoint Enterprise ServerMicrosoft Word11/1/202217/6/2026
Microsoft Word Remote Code Execution Vulnerability
ModificadaAlta (8.8)3.1%—Microsoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online Server+311/1/202217/6/2026
Microsoft Office Remote Code Execution Vulnerability
ModificadaAlta (8.8)1.9%—Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint Server29/12/202117/6/2026
Microsoft SharePoint Elevation of Privilege Vulnerability
ModificadaMedia (5.7)1.2%—Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server15/12/202117/6/2026
Microsoft SharePoint Server Spoofing Vulnerability
ModificadaMedia (5.7)1.5%—Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint Server15/12/202117/6/2026
Microsoft SharePoint Server Spoofing Vulnerability
ModificadaAlta (8.8)2.7%—Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server15/12/202117/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
ModificadaAlta (7.2)2.2%—Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server15/12/202117/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
AnalizadaAlta (7.5)25%💥 PoCBalasys DheaterSiemens Scalance W1750d FirmwareSuse Linux Enterprise ServerF5 Big-ip Access Policy Manager+2611/11/202123/9/2026
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network…
ModificadaMedia (6.5)1.1%—Github Enterprise Server10/11/202117/6/2026
A path traversal vulnerability was identified in GitHub Pages builds on GitHub Enterprise Server that could allow an attacker to read system files. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance. This vulnerability…
ModificadaAlta (7.8)2.3%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+310/11/202119/8/2026
Microsoft Excel Remote Code Execution Vulnerability
ModificadaAlta (8.8)6.5%—Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server13/10/202117/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
ModificadaAlta (8.8)48%—Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server13/10/202117/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
ModificadaAlta (7.8)6.0%—Microsoft OfficeMicrosoft Office Online ServerMicrosoft Office WEB Apps ServerMicrosoft Sharepoint Enterprise Server+213/10/202117/6/2026
Microsoft Word Remote Code Execution Vulnerability
ModificadaAlta (7.8)2.7%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+213/10/202117/6/2026
Microsoft Excel Remote Code Execution Vulnerability
ModificadaBaja (3.5)1.4%—Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server13/10/202117/6/2026
Microsoft SharePoint Server Spoofing Vulnerability
ModificadaCrítica (9.8)1.2%—Github Enterprise Server24/9/202117/6/2026
An improper access control vulnerability in GitHub Enterprise Server allowed a workflow job to execute in a self-hosted runner group it should not have had access to. This affects customers using self-hosted runner groups for access control. A repository with access to one enterprise runner group could access all of…
ModificadaMedia (4.3)0.93%—Github Enterprise Server24/9/202117/6/2026
A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently restricted and made it possible to read files on the GitHub Enterprise Server instance. To exploit this…
ModificadaBaja (3.5)1.3%—Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint Foundation15/9/202110/8/2026
Microsoft SharePoint Server Spoofing Vulnerability
ModificadaBaja (3.5)1.3%—Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server15/9/202110/8/2026
Microsoft SharePoint Server Spoofing Vulnerability
ModificadaMedia (4.3)4.0%—Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint Server12/8/202110/8/2026
Microsoft SharePoint Server Spoofing Vulnerability
ModificadaAlta (7.1)0.30%—Suse Linux Enterprise ServerOpensuse Factory28/7/202117/6/2026
A UNIX Symbolic Link (Symlink) Following vulnerability in the clone-master-clean-up.sh script of clone-master-clean-up in SUSE Linux Enterprise Server 12 SP3, SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allows local attackers to delete arbitrary files. This issue affects: SUSE Linux Enterprise Server 12 SP3…
ModificadaMedia (6.5)1.2%—Github Enterprise Server14/7/202117/6/2026
A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently restricted and made it possible to read files on the GitHub Enterprise Server instance. To exploit this…
ModificadaAlta (8.1)1.3%—Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server8/6/202117/6/2026
Microsoft SharePoint Server Spoofing Vulnerability
ModificadaAlta (8.8)3.0%—Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint FoundationMicrosoft Sharepoint Server8/6/202117/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability