Vulnerabilities

Summary — last 7 days

New vulnerabilities3,333▲ 343 vs. last week
Critical / high1,493▲ 121 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)592▲ 117 vs. last week
–

619 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
AnalyzedLow (3.5)0.58%—Microsoft Sharepoint Server9/8/20269/9/2026
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
AnalyzedHigh (7.5)0.51%—Microsoft Sharepoint Server9/8/20269/9/2026
Time-of-check time-of-use (toctou) race condition in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalyzedHigh (8.8)0.78%—Microsoft Sharepoint Server9/8/20269/9/2026
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalyzedHigh (8.8)0.99%—Microsoft Sharepoint Server9/8/20269/9/2026
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
AnalyzedMedium (5.4)0.40%—Microsoft Sharepoint Server9/8/20269/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalyzedHigh (7.7)0.84%—Microsoft Sharepoint Server9/8/20269/9/2026
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
AnalyzedMedium (6.5)1.00%—Microsoft Sharepoint Server9/8/20269/9/2026
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
AnalyzedMedium (4.8)0.40%—Microsoft Sharepoint Server9/8/20269/10/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalyzedHigh (8.8)0.78%—Microsoft Sharepoint Server9/8/20269/9/2026
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalyzedHigh (8.8)0.91%—Microsoft Sharepoint Server9/8/20269/9/2026
Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
AnalyzedMedium (5.4)0.45%—Microsoft Sharepoint Server9/8/20269/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalyzedMedium (6.5)1.00%—Microsoft Sharepoint Server9/8/20269/9/2026
Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
AnalyzedMedium (5.4)0.45%—Microsoft Sharepoint Server9/8/20269/10/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
AnalyzedHigh (8.8)0.78%—Microsoft Sharepoint Server9/8/20269/9/2026
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalyzedHigh (8.8)0.78%—Microsoft Sharepoint Server9/8/20269/9/2026
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalyzedHigh (8.8)0.78%—Microsoft Sharepoint Server9/8/20269/9/2026
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalyzedHigh (8.7)0.78%—Microsoft Sharepoint Server8/11/20268/13/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
AnalyzedHigh (8.8)0.78%—Microsoft Sharepoint Server8/11/20268/13/2026
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
AnalyzedHigh (8.8)0.94%—Microsoft Sharepoint Server8/11/20268/13/2026
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
AnalyzedHigh (8.8)1.7%—Microsoft Sharepoint Server8/11/20268/13/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalyzedCritical (9.3)1.0%—Microsoft Sharepoint Server8/11/20268/16/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
AnalyzedHigh (8.8)2.0%—Microsoft Sharepoint Server8/11/20268/13/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalyzedHigh (8.8)2.0%—Microsoft Sharepoint Server8/11/20268/13/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalyzedHigh (8.8)1.7%—Microsoft Sharepoint Server8/11/20268/13/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
AnalyzedHigh (8.8)2.0%—Microsoft Sharepoint Server8/11/20268/13/2026
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.