Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
467 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.3) | 0.75% | — | Equifax Victim Information Notification Exchange | 23/7/2026 | 26/8/2026 | The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass the login page, access other users' credentials, take over other user accounts, access sensitive PII, and dump other information from the database. | |
| Analizada | Alta (7.8) | 2.5% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 14/7/2026 | 24/7/2026 | Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. | |
| Analizada | Crítica (9.6) | 0.86% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 14/7/2026 | 24/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.8) | 0.30% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 14/7/2026 | 24/7/2026 | Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (8.8) | 1.0% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 14/7/2026 | 24/7/2026 | Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Exchange Online | 2/7/2026 | 7/7/2026 | Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.6) | 0.69% | — | Microsoft Exchange Online | 19/6/2026 | 24/6/2026 | Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Media (5.4) | 0.47% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/6/2026 | 28/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (8.1) | 0.70% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/6/2026 | 28/7/2026 | Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.78% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/6/2026 | 28/7/2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | |
| Modificada | Media (6.5) | 0.86% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/6/2026 | 28/7/2026 | Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. | |
| Analizada | Media (5) | 0.64% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/6/2026 | 28/7/2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network. | |
| Modificada | Media (6.1) | 0.46% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/6/2026 | 28/7/2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. | |
| Analizada | Media (6.1) | 0.41% | — | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 9/6/2026 | 28/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (7.5) | 1.00% | — | Microsoft Exchange Online | 4/6/2026 | 23/7/2026 | Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (6.1) | 0.52% | ⚠ Explotación activa | Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition | 14/5/2026 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Media (4.8) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 20/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions Based on Mailboxes report. | |
| Analizada | Media (4.8) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 24/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Non-Owner Mailbox Permission report. | |
| Analizada | Media (5.4) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 24/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count and Size report. | |
| Analizada | Media (4.8) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 24/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Public Folder Client Permissions report. | |
| Analizada | Media (4.8) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 24/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Equipment Mailbox Details report. | |
| Analizada | Media (4.8) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 24/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Mails Exchanged Between Users report. | |
| Analizada | Media (4.8) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 24/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions based on Distribution Groups report. | |
| Analizada | Media (4.8) | 1.0% | — | Zohocorp Manageengine Exchange Reporter Plus | 3/4/2026 | 24/7/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Distribution Lists report. | |
| Pendiente de análisis | Alta (7.5) | 0.26% | — | Microsoft ExchangeAIMicrosoft Exchange ActivesyncAISamsung Mobile DevicesAI | 2/3/2026 | 17/6/2026 | In Microsoft Exchange through 2019, Exchange ActiveSync (EAS) configurations on on-premises servers may transmit sensitive data from Samsung mobile devices in cleartext, including the user's name, e-mail address, device ID, bearer token, and base64-encoded password. |