Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

467 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.3)0.75%—Equifax Victim Information Notification Exchange23/7/202626/8/2026
The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass the login page, access other users' credentials, take over other user accounts, access sensitive PII, and dump other information from the database.
AnalizadaAlta (7.8)2.5%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition14/7/202624/7/2026
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
AnalizadaCrítica (9.6)0.86%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition14/7/202624/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (7.8)0.30%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition14/7/202624/7/2026
Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (8.8)1.0%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition14/7/202624/7/2026
Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.78%—Microsoft Exchange Online2/7/20267/7/2026
Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.6)0.69%—Microsoft Exchange Online19/6/202624/6/2026
Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
AnalizadaMedia (5.4)0.47%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/6/202628/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (8.1)0.70%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/6/202628/7/2026
Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.78%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/6/202628/7/2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
ModificadaMedia (6.5)0.86%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/6/202628/7/2026
Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
AnalizadaMedia (5)0.64%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/6/202628/7/2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
ModificadaMedia (6.1)0.46%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/6/202628/7/2026
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
AnalizadaMedia (6.1)0.41%—Microsoft Exchange ServerMicrosoft Exchange Server Subscription Edition9/6/202628/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
AnalizadaAlta (7.5)1.00%—Microsoft Exchange Online4/6/202623/7/2026
Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network.
AnalizadaMedia (6.1)0.52%⚠ Explotación activaMicrosoft Exchange ServerMicrosoft Exchange Server Subscription Edition14/5/202617/6/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
AnalizadaMedia (4.8)1.0%—Zohocorp Manageengine Exchange Reporter Plus3/4/202620/7/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions Based on Mailboxes report.
AnalizadaMedia (4.8)1.0%—Zohocorp Manageengine Exchange Reporter Plus3/4/202624/7/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Non-Owner Mailbox Permission report.
AnalizadaMedia (5.4)1.0%—Zohocorp Manageengine Exchange Reporter Plus3/4/202624/7/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count and Size report.
AnalizadaMedia (4.8)1.0%—Zohocorp Manageengine Exchange Reporter Plus3/4/202624/7/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Public Folder Client Permissions report.
AnalizadaMedia (4.8)1.0%—Zohocorp Manageengine Exchange Reporter Plus3/4/202624/7/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Equipment Mailbox Details report.
AnalizadaMedia (4.8)1.0%—Zohocorp Manageengine Exchange Reporter Plus3/4/202624/7/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Mails Exchanged Between Users report.
AnalizadaMedia (4.8)1.0%—Zohocorp Manageengine Exchange Reporter Plus3/4/202624/7/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions based on Distribution Groups report.
AnalizadaMedia (4.8)1.0%—Zohocorp Manageengine Exchange Reporter Plus3/4/202624/7/2026
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Distribution Lists report.
Pendiente de análisisAlta (7.5)0.26%—Microsoft ExchangeAIMicrosoft Exchange ActivesyncAISamsung Mobile DevicesAI2/3/202617/6/2026
In Microsoft Exchange through 2019, Exchange ActiveSync (EAS) configurations on on-premises servers may transmit sensitive data from Samsung mobile devices in cleartext, including the user's name, e-mail address, device ID, bearer token, and base64-encoded password.