Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
636 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.80% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 10/9/2024 | 10/8/2026 | Microsoft Excel Elevation of Privilege Vulnerability | |
| Analizada | Alta (8.7) | 0.48% | — | Techexcel Back Office Software | 9/9/2024 | 17/6/2026 | This vulnerability exists in TechExcel Back Office Software versions prior to 1.0.0 due to improper access controls on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter through API request URL which could lead to unauthorized access to sensitive… | |
| Analizada | Alta (7.5) | 0.57% | — | Pxlrbt Filament Excel | 12/8/2024 | 17/6/2026 | Filament Excel enables excel export for Filament admin resources. The export download route `/filament-excel/{path}` allowed downloading any file without login when the webserver allows `../` in the URL. Patched with Version v2.3.3. | |
| Aplazada | Crítica (9.1) | 0.49% | — | Spreadsheetconverter Import Spreadsheets From Microsoft ExcelAI | 12/7/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in SpreadsheetConverter Import Spreadsheets from Microsoft Excel allows Code Injection.This issue affects Import Spreadsheets from Microsoft Excel: from n/a through 10.1.4. | |
| Aplazada | Media (6.3) | 0.36% | — | Softexpert Excellence SuiteAI | 26/6/2024 | 17/6/2026 | File upload vulnerability found in Softexpert Excellence Suite v.2.1 allows attackers to execute arbitrary code via a .php file upload to the form/efms_exec_html/file_upload_parser.php endpoint. | |
| Modificada | Media (5.4) | 0.25% | — | Themefreesia Excellent | 21/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Theme Freesia Excellent allows Stored XSS.This issue affects Excellent: from n/a through 1.2.9. | |
| Analizada | Alta (7.8) | 2.1% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 14/5/2024 | 17/6/2026 | Microsoft Excel Remote Code Execution Vulnerability | |
| Aplazada | Media (5.9) | 0.34% | — | Extendwp Import Content IN Wordpress AND Woocommerce With ExcelAI | 18/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in extendWP Import Content in WordPress & WooCommerce with Excel allows Reflected XSS.This issue affects Import Content in WordPress & WooCommerce with Excel: from n/a through 4.2. | |
| Aplazada | Media (4.3) | 0.37% | — | Hidekazu Ishikawa X-t9AIThemeinwp Default MAGAIOUT THE BOX NamahaAIOUT THE BOX CitylogicAI+11 | 10/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Hidekazu Ishikawa X-T9, Hidekazu Ishikawa Lightning, themeinwp Default Mag, Out the Box Namaha, Out the Box CityLogic, Marsian i-max, Jetmonsters Emmet Lite, Macho Themes Decode, Wayneconnor Sliding Door, Out the Box Shopstar!, Modernthemesnet Gridsby, TT Themes… | |
| Analizada | Alta (7.5) | 0.83% | — | Myprestamodules Orders (csv, Excel) Export PRO | 20/3/2024 | 17/6/2026 | An issue in MyPrestaModules ordersexport v.6.0.2 and before allows a remote attacker to execute arbitrary code via the download.php component. | |
| Analizada | Crítica (9.8) | 0.53% | — | Myprestamodules Product Catalog (csv, Excel) Import | 3/3/2024 | 17/6/2026 | SQL Injection vulnerability in MyPrestaModules "Product Catalog (CSV, Excel) Import" (simpleimportproduct) modules for PrestaShop versions 6.5.0 and before, allows attackers to escalate privileges and obtain sensitive information via Send::__construct() and importProducts::_addDataToDb methods. | |
| Analizada | Crítica (9.1) | 0.79% | — | Myprestamodules Product Catalog (csv, Excel) Import | 27/2/2024 | 17/6/2026 | In the module "Product Catalog (CSV, Excel) Import" (simpleimportproduct) <= 6.7.0 from MyPrestaModules for PrestaShop, a guest can upload files with extensions .php. | |
| Modificada | Alta (7.8) | 1.2% | — | Microsoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Powerpoint+4 | 13/2/2024 | 10/8/2026 | Microsoft Office Remote Code Execution Vulnerability | |
| Modificada | Media (6.1) | 0.66% | 💥 PoC | Remyandrade Product Inventory With Export TO Excel | 29/1/2024 | 17/6/2026 | Product Name and Product Code in the 'Add Product' section of Sourcecodester Product Inventory with Export to Excel 1.0 are vulnerable to XSS attacks. | |
| Modificada | Alta (7.5) | 0.59% | — | Myprestamodules Orders (csv, Excel) Export PRO | 6/12/2023 | 17/6/2026 | In the module "Orders (CSV, Excel) Export PRO" (ordersexport) < 5.2.0 from MyPrestaModules for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can access exports from the module which can lead to a leak of personal information from… | |
| Analizada | Alta (8.8) | 0.67% | — | Myprestamodules Orders (csv, Excel) Export PRO | 15/11/2023 | 17/6/2026 | MyPrestaModules ordersexport before v5.0 was discovered to contain multiple SQL injection vulnerabilities at send.php via the key and save_setting parameters. | |
| Modificada | Alta (7.8) | 57% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 14/11/2023 | 17/6/2026 | Microsoft Excel Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 1.2% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 14/11/2023 | 17/6/2026 | Microsoft Excel Security Feature Bypass Vulnerability | |
| Modificada | Alta (7.5) | 0.61% | — | Advanced Export Products Orders Cron CSV Excel Project Advanced Export Products Orders Cron CSV Excel | 7/11/2023 | 17/6/2026 | Insecure permissions in Smart Soft advancedexport before v4.4.7 allow unauthenticated attackers to arbitrarily download user information from the ps_customer table. | |
| Modificada | Media (5.4) | 0.36% | — | Ipushpull Live Updates From Excel | 31/10/2023 | 17/6/2026 | The Live updates from Excel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ipushpull_page' shortcode in versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Modificada | Crítica (9.8) | 0.98% | — | Myprestamodules Product Catalog (csv, Excel) Import | 20/9/2023 | 17/6/2026 | SimpleImportProduct Prestashop Module v6.2.9 was discovered to contain a SQL injection vulnerability via the key parameter at send.php. | |
| Modificada | Alta (7.5) | 32% | 💥 Exploit | Myprestamodules Product Catalog (csv, Excel) ImportUpdateproducts Project Updateproducts | 20/9/2023 | 17/6/2026 | MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInfo information disclosure vulnerability via send.php. | |
| Modificada | Media (5.5) | 1.2% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 12/9/2023 | 17/6/2026 | Microsoft Excel Information Disclosure Vulnerability | |
| Modificada | Media (5.4) | 0.41% | — | Softexpert Excellence Suite | 14/6/2023 | 17/6/2026 | SoftExpert Excellence Suite 2.1.9 is vulnerable to Cross Site Scripting (XSS) via query screens. | |
| Modificada | Alta (7.8) | 44% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online Server | 14/6/2023 | 17/6/2026 | Microsoft Excel Remote Code Execution Vulnerability |