Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2544▼ 345 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
276 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (8.8) | 0.50% | — | Microsoft Exchange ServerAI | 2/10/2026 | 3/10/2026 | Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network. | |
| Pendiente de análisis | Alta (8.1) | 0.72% | — | Microsoft Exchange ServerAI | 8/9/2026 | 9/9/2026 | Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. | |
| Analizada | Crítica (9.1) | 0.86% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 8/9/2026 | 22/9/2026 | Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Media (5.9) | 0.47% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 8/9/2026 | 29/9/2026 | Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (8.1) | 0.69% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 8/9/2026 | 29/9/2026 | Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 8/9/2026 | 29/9/2026 | Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network. | |
| Analizada | Media (6.5) | 0.64% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 8/9/2026 | 29/9/2026 | Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network. | |
| Analizada | Media (6.5) | 0.84% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 8/9/2026 | 29/9/2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Crítica (9.3) | 0.76% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 8/9/2026 | 30/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (8.8) | 0.91% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 8/9/2026 | 30/9/2026 | External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.94% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 11/8/2026 | 17/8/2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Media (6.5) | 0.64% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 11/8/2026 | 14/8/2026 | Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network. | |
| Analizada | Media (5.4) | 0.45% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 11/8/2026 | 13/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Alta (8.8) | 0.91% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 11/8/2026 | 14/8/2026 | Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. | |
| Analizada | Media (6.5) | 2.0% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 11/8/2026 | 13/8/2026 | Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network. | |
| Modificada | Alta (8) | 0.69% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 11/8/2026 | 2/9/2026 | Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 1.0% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 11/8/2026 | 14/8/2026 | Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.8) | 2.5% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 14/7/2026 | 24/7/2026 | Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. | |
| Analizada | Crítica (9.6) | 0.86% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 14/7/2026 | 24/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.8) | 0.30% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 14/7/2026 | 24/7/2026 | Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (8.8) | 1.0% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 14/7/2026 | 24/7/2026 | Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. | |
| Analizada | Media (5.4) | 0.47% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/6/2026 | 28/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (8.1) | 0.70% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/6/2026 | 28/7/2026 | Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/6/2026 | 28/7/2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | |
| Modificada | Media (6.5) | 0.86% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/6/2026 | 28/7/2026 | Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. |