Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

736 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.2)8.2%—Microsoft Sharepoint Server10/9/202417/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
AnalizadaAlta (8.8)51%—Microsoft Sharepoint Server10/9/202417/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
AnalizadaAlta (7.2)51%⚠ Explotación activaMicrosoft Sharepoint Server9/7/202417/6/2026
Microsoft SharePoint Remote Code Execution Vulnerability
ModificadaAlta (7.2)45%—Microsoft Sharepoint Server9/7/202417/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
ModificadaAlta (7.2)53%—Microsoft Sharepoint Server9/7/202417/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
ModificadaAlta (7.5)2.3%—Microsoft Sharepoint Server9/7/202417/6/2026
Microsoft SharePoint Server Information Disclosure Vulnerability
ModificadaMedia (5.3)0.47%—Virtosoftware Sharepoint Bulk File Download24/6/202417/6/2026
An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows an NTLMv2 hash leak via a UNC share pathname in the path parameter.
ModificadaMedia (5.3)0.34%—Virtosoftware Sharepoint Bulk File Download24/6/202417/6/2026
An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. It discloses full pathnames via Virto.SharePoint.FileDownloader/Api/Download.ashx?action=archive.
ModificadaCrítica (9.8)0.61%—Virtosoftware Sharepoint Bulk File Download24/6/202417/6/2026
An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows arbitrary file download and deletion via absolute path traversal in the path parameter.
ModificadaAlta (7.8)1.2%—Microsoft Sharepoint Server11/6/202417/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
AnalizadaAlta (7.2)84%—Microsoft Sharepoint Server14/5/202417/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
AnalizadaAlta (7.5)56%💥 PoCMicrosoft Sharepoint Server14/5/202417/6/2026
Microsoft SharePoint Server Information Disclosure Vulnerability
AnalizadaBaja (3.1)1.4%—Microsoft Sharepoint Server9/4/202417/6/2026
Microsoft SharePoint Server Spoofing Vulnerability
AnalizadaAlta (7.8)3.9%—Microsoft Sharepoint Server12/3/202417/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
ModificadaAlta (8.8)31%—Microsoft Sharepoint Server9/1/202417/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
ModificadaMedia (5.5)0.69%—Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+3515/11/202317/6/2026
An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the…
ModificadaMedia (6.8)3.4%—Microsoft Sharepoint Enterprise ServerMicrosoft Sharepoint Server14/11/202317/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
ModificadaMedia (6.5)0.36%—Elastic Sharepoint Online Python Connector26/10/202317/6/2026
An issue was discovered when using Document Level Security and the SPO "Limited Access" functionality in Elastic Sharepoint Online Python Connector. If a user is assigned limited access permissions to an item on a Sharepoint site then that user would have read permissions to all content on the Sharepoint site through…
ModificadaAlta (8.8)2.1%—Microsoft Sharepoint Server12/9/202317/6/2026
Microsoft SharePoint Server Elevation of Privilege Vulnerability
ModificadaAlta (7.3)0.84%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+112/9/202317/6/2026
Microsoft Word Remote Code Execution Vulnerability
ModificadaAlta (8.1)2.4%—Zohocorp Manageengine Ad360Zohocorp Manageengine Adaudit PlusZohocorp Manageengine Admanager PlusZohocorp Manageengine Assetexplorer+1328/8/202317/6/2026
Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and below and 7xxx 7002 and below, Cloud Security Plus 4161 and below, Data Security Plus 6110 and below, Eventlog Analyzer 12301 and below, Exchange Reporter Plus 5709 and…
ModificadaMedia (6.5)2.1%—Microsoft Sharepoint Server8/8/202317/6/2026
Microsoft SharePoint Server Information Disclosure Vulnerability
ModificadaAlta (8)2.0%—Microsoft Sharepoint Server8/8/202317/6/2026
Microsoft SharePoint Server Spoofing Vulnerability
ModificadaAlta (8)2.0%—Microsoft Sharepoint Server8/8/202317/6/2026
Microsoft SharePoint Server Spoofing Vulnerability
ModificadaMedia (6.5)1.9%—Microsoft Sharepoint Server8/8/202317/6/2026
Microsoft SharePoint Server Information Disclosure Vulnerability