Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
736 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 8.2% | — | Microsoft Sharepoint Server | 10/9/2024 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Analizada | Alta (8.8) | 51% | — | Microsoft Sharepoint Server | 10/9/2024 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Analizada | Alta (7.2) | 51% | ⚠ Explotación activa | Microsoft Sharepoint Server | 9/7/2024 | 17/6/2026 | Microsoft SharePoint Remote Code Execution Vulnerability | |
| Modificada | Alta (7.2) | 45% | — | Microsoft Sharepoint Server | 9/7/2024 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Modificada | Alta (7.2) | 53% | — | Microsoft Sharepoint Server | 9/7/2024 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Modificada | Alta (7.5) | 2.3% | — | Microsoft Sharepoint Server | 9/7/2024 | 17/6/2026 | Microsoft SharePoint Server Information Disclosure Vulnerability | |
| Modificada | Media (5.3) | 0.47% | — | Virtosoftware Sharepoint Bulk File Download | 24/6/2024 | 17/6/2026 | An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows an NTLMv2 hash leak via a UNC share pathname in the path parameter. | |
| Modificada | Media (5.3) | 0.34% | — | Virtosoftware Sharepoint Bulk File Download | 24/6/2024 | 17/6/2026 | An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. It discloses full pathnames via Virto.SharePoint.FileDownloader/Api/Download.ashx?action=archive. | |
| Modificada | Crítica (9.8) | 0.61% | — | Virtosoftware Sharepoint Bulk File Download | 24/6/2024 | 17/6/2026 | An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows arbitrary file download and deletion via absolute path traversal in the path parameter. | |
| Modificada | Alta (7.8) | 1.2% | — | Microsoft Sharepoint Server | 11/6/2024 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Analizada | Alta (7.2) | 84% | — | Microsoft Sharepoint Server | 14/5/2024 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Analizada | Alta (7.5) | 56% | 💥 PoC | Microsoft Sharepoint Server | 14/5/2024 | 17/6/2026 | Microsoft SharePoint Server Information Disclosure Vulnerability | |
| Analizada | Baja (3.1) | 1.4% | — | Microsoft Sharepoint Server | 9/4/2024 | 17/6/2026 | Microsoft SharePoint Server Spoofing Vulnerability | |
| Analizada | Alta (7.8) | 3.9% | — | Microsoft Sharepoint Server | 12/3/2024 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Modificada | Alta (8.8) | 31% | — | Microsoft Sharepoint Server | 9/1/2024 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Modificada | Media (5.5) | 0.69% | — | Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+35 | 15/11/2023 | 17/6/2026 | An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the… | |
| Modificada | Media (6.8) | 3.4% | — | Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint Server | 14/11/2023 | 17/6/2026 | Microsoft SharePoint Server Remote Code Execution Vulnerability | |
| Modificada | Media (6.5) | 0.36% | — | Elastic Sharepoint Online Python Connector | 26/10/2023 | 17/6/2026 | An issue was discovered when using Document Level Security and the SPO "Limited Access" functionality in Elastic Sharepoint Online Python Connector. If a user is assigned limited access permissions to an item on a Sharepoint site then that user would have read permissions to all content on the Sharepoint site through… | |
| Modificada | Alta (8.8) | 2.1% | — | Microsoft Sharepoint Server | 12/9/2023 | 17/6/2026 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.3) | 0.84% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+1 | 12/9/2023 | 17/6/2026 | Microsoft Word Remote Code Execution Vulnerability | |
| Modificada | Alta (8.1) | 2.4% | — | Zohocorp Manageengine Ad360Zohocorp Manageengine Adaudit PlusZohocorp Manageengine Admanager PlusZohocorp Manageengine Assetexplorer+13 | 28/8/2023 | 17/6/2026 | Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and below and 7xxx 7002 and below, Cloud Security Plus 4161 and below, Data Security Plus 6110 and below, Eventlog Analyzer 12301 and below, Exchange Reporter Plus 5709 and… | |
| Modificada | Media (6.5) | 2.1% | — | Microsoft Sharepoint Server | 8/8/2023 | 17/6/2026 | Microsoft SharePoint Server Information Disclosure Vulnerability | |
| Modificada | Alta (8) | 2.0% | — | Microsoft Sharepoint Server | 8/8/2023 | 17/6/2026 | Microsoft SharePoint Server Spoofing Vulnerability | |
| Modificada | Alta (8) | 2.0% | — | Microsoft Sharepoint Server | 8/8/2023 | 17/6/2026 | Microsoft SharePoint Server Spoofing Vulnerability | |
| Modificada | Media (6.5) | 1.9% | — | Microsoft Sharepoint Server | 8/8/2023 | 17/6/2026 | Microsoft SharePoint Server Information Disclosure Vulnerability |