Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3063▲ 563 respecto a la semana anterior
Críticas / altas1461▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.1)0.37%—Microsoft Dataverse17/9/202625/9/2026
Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.
AplazadaBaja (2.1)0.26%—Microsoft DataverseAI1/4/202617/6/2026
A vulnerability was detected in Harvard University IQSS Dataverse up to 6.8. This affects an unknown function of the file /ThemeAndWidgets.xhtml of the component Theme Customization. Performing a manipulation of the argument uploadLogo results in unrestricted upload. Remote exploitation of the attack is possible. The…
AplazadaAlta (8.8)0.60%—Dataverse IntegrationAI24/7/202517/6/2026
The Dataverse Integration plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks within its reset_password_link REST endpoint in versions 2.77 through 2.81. The endpoint’s handler accepts a client-supplied id, email, or login, looks up that user, and calls…
AnalizadaAlta (8.8)0.83%—Microsoft Dataverse13/5/202517/6/2026
Improper handling of insufficient permissions or privileges in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.
ModificadaCrítica (9.8)3.5%—Microsoft Dataverse8/5/202517/6/2026
Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.8)1.4%—Microsoft Dataverse21/3/202517/6/2026
Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.
AnalizadaAlta (7.2)0.75%—Microsoft Dataverse13/3/202517/6/2026
Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (8.8)0.75%—Microsoft Dataverse15/10/202417/6/2026
Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.