Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2952▲ 19 respecto a la semana anterior
Críticas / altas1451▲ 188 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

145 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.8)1.7%—Microsoft Dynamics 365AI8/9/20269/9/2026
Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.99%—Microsoft Dynamics 3658/9/202629/9/2026
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.
AnalizadaMedia (6.5)1.00%—Microsoft Dynamics 36511/8/202617/8/2026
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information over a network.
AnalizadaAlta (8.8)1.7%—Microsoft Dynamics 36511/8/202617/8/2026
Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
AnalizadaMedia (6.5)0.84%—Microsoft Dynamics 365 Business Central 2024Microsoft Dynamics 365 Business Central 2025Microsoft Dynamics 365 Business Central 202611/8/202613/8/2026
Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.
AnalizadaMedia (6.1)0.47%—Microsoft Dynamics 365 Customer Voice9/7/20269/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a network.
AnalizadaCrítica (9.9)0.78%—Microsoft Dynamics 36518/6/202625/6/2026
Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (8.8)0.78%—Microsoft Dynamics 3659/6/202623/7/2026
Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.9)0.99%—Microsoft Dynamics 36512/5/202617/6/2026
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
ModificadaCrítica (9.1)0.93%—Microsoft Dynamics 36512/5/202617/6/2026
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
AnalizadaAlta (7.8)0.30%—Microsoft Dynamics 365 Business Central12/5/202610/8/2026
Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally.
AnalizadaCrítica (9.9)0.77%—Microsoft Dynamics 365 Customer Insights12/5/202617/6/2026
Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (7.5)0.73%—Microsoft Dynamics 36523/4/202617/6/2026
Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network.
AnalizadaMedia (5.5)0.35%—Microsoft Dynamics 36514/4/202624/7/2026
Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally.
Pendiente de análisisAlta (8.8)0.46%—Microsoft Dynamics 365 Customer EngagementAIMicrosoft SQL Server Reporting ServicesAI18/3/202617/6/2026
Microsoft Dynamics 365 Customer Engagement (on-premises) 1612 (9.0.2.3034) allows the generation of customized reports via raw SQL queries in an upload of a .rdl (Report Definition Language) file; this is then processed by the SQL Server Reporting Service. An account with the privilege Add Reporting Services Reports…
AplazadaMedia (4.4)0.24%—Integrate Dynamics 365 CRMAI17/1/202617/6/2026
The Integrate Dynamics 365 CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AplazadaAlta (8.6)0.30%—Progress Datadirect Connect FOR Jdbc FOR Amazon RedshiftAIProgress Datadirect Connect FOR Jdbc FOR Apache CassandraAIProgress Datadirect Connect FOR Jdbc FOR HiveAIProgress Datadirect Connect FOR Jdbc FOR Apache ImpalaAI+2819/11/202517/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers,…
AplazadaAlta (8.6)0.30%—Progress Datadirect Connect FOR Jdbc FOR Amazon RedshiftAIProgress Datadirect Connect FOR Jdbc FOR Apache CassandraAIProgress Datadirect Connect FOR Jdbc FOR HiveAIProgress Datadirect Connect FOR Jdbc FOR Apache ImpalaAI+2819/11/202517/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers,…
AnalizadaAlta (8.7)0.60%—Microsoft Dynamics 36511/11/202517/6/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (8.7)0.60%—Microsoft Dynamics 36511/11/202517/6/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network.
AnalizadaMedia (6.5)0.92%—Microsoft Dynamics 36511/11/202517/6/2026
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network.
AplazadaMedia (6.5)0.27%—Integrate Dynamics 365 CRMAI4/10/202530/9/2026
The Integrate Dynamics 365 CRM plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.9. This is due to missing capability checks and nonce verification on functions hooked to 'init'. This makes it possible for unauthenticated attackers to deactivate the plugin, tamper with…
AnalizadaAlta (7.5)0.82%—Microsoft Dynamics 3654/9/202517/6/2026
Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability
AnalizadaAlta (7.5)0.81%—Microsoft Dynamics 365 GuidesMicrosoft Dynamics 365 Remote AssistMicrosoft TeamsMicrosoft Teams Panels+112/8/202517/6/2026
Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network.
AnalizadaMedia (6.5)1.2%—Microsoft Dynamics 36512/8/202517/6/2026
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network.