Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2567▼ 300 respecto a la semana anterior
Críticas / altas1352▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
47 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.3) | 0.32% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network. | |
| Analizada | Media (6.1) | 0.41% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Media (6.5) | 1.1% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network. | |
| Analizada | Media (6.5) | 0.92% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (7.1) | 0.53% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.5) | 0.97% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (6.5) | 1.1% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network. | |
| Analizada | Crítica (9.8) | 0.97% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network. | |
| Analizada | Media (6.1) | 0.55% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Media (6.1) | 0.18% | — | SAP Business Server Pages | 10/2/2026 | 17/6/2026 | SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when clicked by a victim, redirect them to attacker?controlled sites, potentially exposing or altering sensitive information in the victim�s browser. This results in a low impact on confidentiality and… | |
| Aplazada | Media (4.3) | 0.22% | — | SAP Product Designer WEB UIAISAP Business Server PagesAI | 13/1/2026 | 17/6/2026 | SAP Product Designer Web UI of Business Server Pages allows authenticated non-administrative users to access non-sensitive information. This results in a low impact on confidentiality, with no impact on integrity or availability of the application. | |
| Modificada | Media (5.7) | 0.56% | — | Microsoft Skype FOR Business Server | 13/2/2024 | 10/8/2026 | Skype for Business Information Disclosure Vulnerability | |
| Analizada | Media (5.3) | 90% | ⚠ Explotación activa | Microsoft Skype FOR Business Server | 10/10/2023 | 17/6/2026 | Skype for Business Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.2) | 2.4% | — | Microsoft Skype FOR Business Server | 10/10/2023 | 17/6/2026 | Skype for Business Remote Code Execution Vulnerability | |
| Modificada | Alta (7.2) | 2.5% | — | Microsoft Skype FOR Business Server | 10/10/2023 | 17/6/2026 | Skype for Business Remote Code Execution Vulnerability | |
| Modificada | Alta (7.2) | 2.6% | — | Microsoft Skype FOR Business Server | 10/10/2023 | 17/6/2026 | Skype for Business Remote Code Execution Vulnerability | |
| Modificada | Media (6.5) | 0.57% | — | SAP Netweaver AS Abap Business Server Pages | 11/4/2023 | 17/6/2026 | SAP NetWeaver AS for ABAP (Business Server Pages) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an attacker authenticated as a non-administrative user to craft a request with certain parameters in certain circumstances which can consume the server's resources sufficiently to make… | |
| Modificada | Media (6.1) | 0.36% | — | SAP Netweaver AS Abap Business Server Pages | 14/2/2023 | 17/6/2026 | Due to lack of proper input validation, BSP application (CRM_BSP_FRAME) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75D, 75E, 75F, 75G, 75H, allow malicious inputs from untrusted sources, which can be leveraged by an attacker to execute a Reflected Cross-Site Scripting (XSS) attack. As a result, an… | |
| Modificada | Media (6.1) | 0.39% | — | SAP Netweaver AS Abap Business Server Pages | 14/2/2023 | 17/6/2026 | Due to insufficient input sanitization, SAP NetWeaver AS ABAP (BSP Framework) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an unauthenticated user to alter the current session of the user by injecting the malicious code over the network and gain access to the unintended data. This… | |
| Modificada | Media (6.5) | 3.6% | — | Microsoft Lync ServerMicrosoft Skype FOR Business Server | 15/4/2022 | 17/6/2026 | Skype for Business Information Disclosure Vulnerability | |
| Modificada | Media (5.3) | 2.5% | — | Microsoft Skype FOR Business Server | 15/4/2022 | 17/6/2026 | Skype for Business and Lync Spoofing Vulnerability | |
| Modificada | Alta (7.2) | 2.2% | — | Microsoft Lync ServerMicrosoft Skype FOR Business Server | 11/5/2021 | 17/6/2026 | Skype for Business and Lync Remote Code Execution Vulnerability | |
| Modificada | Alta (7.1) | 1.4% | — | Microsoft Lync ServerMicrosoft Skype FOR Business Server | 11/5/2021 | 17/6/2026 | Skype for Business and Lync Spoofing Vulnerability | |
| Modificada | Media (6.5) | 3.2% | — | Microsoft Lync ServerMicrosoft Skype FOR Business Server | 25/2/2021 | 17/6/2026 | Skype for Business and Lync Denial of Service Vulnerability |