Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3222▲ 222 respecto a la semana anterior
Críticas / altas1465▲ 132 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)511▼ 31 respecto a la semana anterior
619 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (3.5) | 0.58% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | |
| Analizada | Alta (7.5) | 0.51% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Time-of-check time-of-use (toctou) race condition in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.99% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Media (5.4) | 0.40% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.7) | 0.84% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | |
| Analizada | Media (6.5) | 1.00% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | |
| Analizada | Media (4.8) | 0.40% | — | Microsoft Sharepoint Server | 8/9/2026 | 10/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.91% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Media (5.4) | 0.45% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Media (6.5) | 1.00% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | |
| Analizada | Media (5.4) | 0.45% | — | Microsoft Sharepoint Server | 8/9/2026 | 10/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Sharepoint Server | 8/9/2026 | 9/9/2026 | Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.7) | 0.78% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 0.94% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 1.7% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Crítica (9.3) | 1.0% | — | Microsoft Sharepoint Server | 11/8/2026 | 16/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (8.8) | 2.0% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 2.0% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 1.7% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 2.0% | — | Microsoft Sharepoint Server | 11/8/2026 | 13/8/2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |