Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3302▲ 384 respecto a la semana anterior
Críticas / altas1464▲ 142 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)591▲ 117 respecto a la semana anterior
–

619 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)2.1%⚠ Explotación activaMicrosoft Sharepoint Server11/8/202626/9/2026
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaAlta (8.8)2.0%—Microsoft Sharepoint Server11/8/202613/8/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaMedia (5.4)0.58%—Microsoft Sharepoint Server11/8/202613/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (8.8)0.94%—Microsoft Sharepoint Server11/8/202613/8/2026
Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
AnalizadaMedia (5.4)0.58%—Microsoft Sharepoint Server11/8/202613/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaMedia (5.4)0.58%—Microsoft Sharepoint Server11/8/202611/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (8.8)2.0%—Microsoft Sharepoint Server11/8/202612/8/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
ModificadaMedia (5.4)0.65%—Microsoft Sharepoint Server11/8/202619/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaMedia (5.4)0.58%—Microsoft Sharepoint Server11/8/202611/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (8.1)0.96%—Microsoft Sharepoint Server11/8/202613/8/2026
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
AnalizadaMedia (6.5)1.9%—Microsoft Sharepoint Server11/8/202612/8/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (8.8)2.0%—Microsoft Sharepoint Server11/8/202612/8/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalizadaMedia (6.5)0.73%—Microsoft Sharepoint Server11/8/202612/8/2026
Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.
AnalizadaMedia (4.6)0.58%—Microsoft Sharepoint Server11/8/202613/8/2026
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaMedia (6.5)0.91%—Microsoft Sharepoint Server11/8/202613/8/2026
Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaMedia (6.5)1.2%—Microsoft Sharepoint Server11/8/202611/8/2026
Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
AnalizadaMedia (5.4)0.47%—Microsoft Sharepoint Server11/8/202611/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (8.8)0.94%—Microsoft Sharepoint Server11/8/202612/8/2026
Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
AnalizadaMedia (6.5)0.91%—Microsoft Sharepoint Server11/8/202612/8/2026
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaMedia (5.4)0.62%—Microsoft Sharepoint Server11/8/202612/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaMedia (5.4)0.58%—Microsoft Sharepoint Server16/7/202622/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaAlta (8.8)0.94%—Microsoft Sharepoint Server14/7/202615/7/2026
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
AnalizadaMedia (5.5)0.60%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+314/7/202616/7/2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
AnalizadaMedia (5.4)0.50%—Microsoft Sharepoint Server14/7/202615/7/2026
Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalizadaMedia (5.5)0.60%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+314/7/202616/7/2026
Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.