Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

2087 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.60%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+314/7/202616/7/2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
AnalizadaMedia (5.5)0.45%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+314/7/202616/7/2026
Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.
AnalizadaMedia (5.5)0.60%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+314/7/202616/7/2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
AnalizadaAlta (8.7)0.95%—Microsoft Sharepoint Server14/7/202615/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaMedia (5.4)0.58%—Microsoft Sharepoint Server14/7/202616/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaMedia (5.4)0.58%—Microsoft Sharepoint Server14/7/202615/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaMedia (5.4)0.58%—Microsoft Sharepoint Server14/7/202615/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaMedia (5.4)0.52%—Microsoft Power BI Report Server14/7/202619/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network.
AnalizadaCrítica (9.8)16%⚠ Explotación activa💥 ExploitMicrosoft Sharepoint Server14/7/202617/7/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
AnalizadaCrítica (9.8)1.0%⚠ Explotación activa💥 PoCMicrosoft Sharepoint Server14/7/202614/7/2026
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
AnalizadaMedia (6.5)1.1%—Microsoft Sharepoint Server14/7/202615/7/2026
External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaCrítica (9.8)3.0%⚠ Explotación activa💥 PoCMicrosoft Sharepoint Server14/7/202623/7/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
AnalizadaMedia (4.9)0.26%—Sonatype Nexus Repository Manager14/7/202622/9/2026
Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets returned by proxy repository upstream servers. Any user with read access to a proxy repository backed by an attacker-controlled or compromised upstream server — including an anonymous user, if…
AnalizadaMedia (5.1)0.26%—Sonatype Nexus Repository Manager14/7/202622/9/2026
Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, allowing a user holding the Capability Administration permission to cause the server to send requests to internal network locations (Server-Side Request Forgery). This…
AnalizadaMedia (5.3)0.17%—Sonatype Nexus Repository Manager14/7/202622/9/2026
Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission could cause the server to initiate outbound connections to internal or otherwise restricted network hosts. This issue affects Nexus Repository 3.0.0…
AnalizadaAlta (8.2)0.22%—Sonatype Nexus Repository Manager14/7/202622/9/2026
An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository to upload arbitrary artifacts, bypassing the intended write-permission check.
AnalizadaAlta (8.7)0.32%—Sonatype Nexus Repository Manager14/7/202622/9/2026
A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targeted user. A format-specific API key realm (NuGet API Key, Docker Bearer Token, or npm Bearer Token) must be enabled and the targeted user…
Pendiente de análisisAlta (8.6)0.46%—Argo CD Helm ChartAIArgo Repo-serverAI13/7/202615/7/2026
Argo CD Helm Chart before 10.0.0 fails to install network policies by default, allowing any pod on a cluster to access repo-server and other Argo APIs. Attackers can exploit this unrestricted network access through combined attacks to achieve cluster compromise and remote code execution.
AplazadaMedia (6.4)0.35%—Block Suspend Report FOR BuddypressAI9/7/20269/7/2026
The Block, Suspend, Report for BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' parameter in versions up to and including 3.6.4. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with subscriber-level access…
AplazadaCrítica (9.2)0.44%—Yamadashy RepomixAI8/7/202610/7/2026
repomix contains a server-side request forgery vulnerability in the POST /api/pack endpoint that allows unauthenticated attackers to make arbitrary outbound requests. The endpoint fails to properly validate http://, https://, and file:// URLs before passing them to git clone, enabling attackers to access private…
AplazadaAlta (8.7)0.51%—Yamadashy RepomixAI8/7/202610/7/2026
repomix contains a local file inclusion vulnerability in the git clone endpoint that allows unauthenticated attackers to read arbitrary local git repositories. The isValidRemoteValue function in src/core/git/gitRemoteParse.ts fails to block file:// URLs, permitting attackers to supply file:// scheme URLs that bypass…
AplazadaAlta (8.5)0.39%—OwncloudAISharepoint FOR OwncloudAI6/7/20266/10/2026
SharePoint for ownCloud is an application for using SharePoint with the file storage, synchronization, and sharing application ownCloud Classic. In SharePoint for ownCloud prior to version 0.4.1, which corresponds to ownCloud 10 prior to 10.15.3, an attacker with administrative privileges can use a SSRF vulnerability…
AplazadaAlta (8.7)0.63%—Jeecg JimureportAI30/6/202614/7/2026
JimuReport through 2.5.0 exposes the POST /jmreport/auto/export endpoint without authentication: the handler is annotated @JimuNoLoginRequired, so JimuReportTokenInterceptor skips all authentication and authorization, and the export service streams the rendered report for any supplied report id without verifying the…
AplazadaAlta (8.2)0.20%—OpenprojectAIMicrosoft OnedriveAIMicrosoft SharepointAIMicrosoft Azure ADAI26/6/202629/6/2026
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, OpenProject's Storages module writes the OneDrive/SharePoint userless OAuth access_token plaintext to Rails.cache under the deterministic key storage.<id>.httpx_access_token, repopulated continuously by an hourly cron and…
AnalizadaMedia (5.9)0.27%—Sonatype Nexus Repository Manager17/6/202621/7/2026
Sonatype Nexus Repository Manager before 3.93.0 contains an authorization vulnerability in the proxy repository configuration that allows a delegated repository administrator to disclose stored upstream proxy credentials.