Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
25 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.3) | 0.32% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network. | |
| Analizada | Media (6.1) | 0.41% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Media (6.5) | 1.1% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network. | |
| Analizada | Alta (7.5) | 1.2% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network. | |
| Analizada | Media (6.5) | 0.92% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (7.1) | 0.53% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.5) | 0.97% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (6.5) | 1.1% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network. | |
| Analizada | Crítica (9.8) | 0.97% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network. | |
| Analizada | Media (6.1) | 0.55% | — | Microsoft Skype FOR Business ServerMicrosoft Skype FOR Business Server Subscription Edition | 8/9/2026 | 16/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network. | |
| Modificada | Media (5.7) | 0.56% | — | Microsoft Skype FOR Business Server | 13/2/2024 | 10/8/2026 | Skype for Business Information Disclosure Vulnerability | |
| Analizada | Media (5.3) | 90% | ⚠ Explotación activa | Microsoft Skype FOR Business Server | 10/10/2023 | 17/6/2026 | Skype for Business Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.2) | 2.4% | — | Microsoft Skype FOR Business Server | 10/10/2023 | 17/6/2026 | Skype for Business Remote Code Execution Vulnerability | |
| Modificada | Alta (7.2) | 2.5% | — | Microsoft Skype FOR Business Server | 10/10/2023 | 17/6/2026 | Skype for Business Remote Code Execution Vulnerability | |
| Modificada | Alta (7.2) | 2.6% | — | Microsoft Skype FOR Business Server | 10/10/2023 | 17/6/2026 | Skype for Business Remote Code Execution Vulnerability | |
| Modificada | Media (6.5) | 3.6% | — | Microsoft Lync ServerMicrosoft Skype FOR Business Server | 15/4/2022 | 17/6/2026 | Skype for Business Information Disclosure Vulnerability | |
| Modificada | Media (5.3) | 2.5% | — | Microsoft Skype FOR Business Server | 15/4/2022 | 17/6/2026 | Skype for Business and Lync Spoofing Vulnerability | |
| Modificada | Alta (7.2) | 2.2% | — | Microsoft Lync ServerMicrosoft Skype FOR Business Server | 11/5/2021 | 17/6/2026 | Skype for Business and Lync Remote Code Execution Vulnerability | |
| Modificada | Alta (7.1) | 1.4% | — | Microsoft Lync ServerMicrosoft Skype FOR Business Server | 11/5/2021 | 17/6/2026 | Skype for Business and Lync Spoofing Vulnerability | |
| Modificada | Media (6.5) | 3.2% | — | Microsoft Lync ServerMicrosoft Skype FOR Business Server | 25/2/2021 | 17/6/2026 | Skype for Business and Lync Denial of Service Vulnerability | |
| Modificada | Alta (7.1) | 1.8% | — | Microsoft Lync ServerMicrosoft Skype FOR Business Server | 25/2/2021 | 17/6/2026 | Skype for Business and Lync Spoofing Vulnerability | |
| Modificada | Media (6.1) | 2.1% | — | Microsoft Lync ServerMicrosoft Skype FOR Business Server | 9/4/2019 | 17/6/2026 | A spoofing vulnerability exists when a Lync Server or Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for Business and Lync Spoofing Vulnerability'. | |
| Modificada | Alta (8.1) | 7.2% | — | HP Converged Infrastructure Solution Sizer SuiteHP Insight Management SizerHP Power AdvisorHP SAP Sizing Tool+11 | 22/8/2016 | 17/6/2026 | HPE Smart Update in Storage Sizing Tool before 13.0, Converged Infrastructure Solution Sizer Suite (CISSS) before 2.13.1, Power Advisor before 7.8.2, Insight Management Sizer before 16.12.1, Synergy Planning Tool before 3.3, SAP Sizing Tool before 16.12.1, Sizing Tool for SAP Business Suite powered by HANA before… | |
| Modificada | Media (4.3) | 8.9% | — | Microsoft Lync ServerMicrosoft Skype FOR Business Server | 9/9/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Microsoft Lync Server 2013 and Skype for Business Server 2015 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Skype for Business Server and Lync Server XSS Elevation of Privilege Vulnerability." | |
| Modificada | Media (4.3) | 11% | — | Microsoft Lync ServerMicrosoft Skype FOR Business Server | 9/9/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the jQuery engine in Microsoft Lync Server 2013 and Skype for Business Server 2015 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Skype for Business Server and Lync Server XSS Information Disclosure Vulnerability." |