Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

636 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.80%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+110/9/202410/8/2026
Microsoft Excel Elevation of Privilege Vulnerability
AnalizadaAlta (8.7)0.48%—Techexcel Back Office Software9/9/202417/6/2026
This vulnerability exists in TechExcel Back Office Software versions prior to 1.0.0 due to improper access controls on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter through API request URL which could lead to unauthorized access to sensitive…
AnalizadaAlta (7.5)0.57%—Pxlrbt Filament Excel12/8/202417/6/2026
Filament Excel enables excel export for Filament admin resources. The export download route `/filament-excel/{path}` allowed downloading any file without login when the webserver allows `../` in the URL. Patched with Version v2.3.3.
AplazadaCrítica (9.1)0.49%—Spreadsheetconverter Import Spreadsheets From Microsoft ExcelAI12/7/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in SpreadsheetConverter Import Spreadsheets from Microsoft Excel allows Code Injection.This issue affects Import Spreadsheets from Microsoft Excel: from n/a through 10.1.4.
AplazadaMedia (6.3)0.36%—Softexpert Excellence SuiteAI26/6/202417/6/2026
File upload vulnerability found in Softexpert Excellence Suite v.2.1 allows attackers to execute arbitrary code via a .php file upload to the form/efms_exec_html/file_upload_parser.php endpoint.
ModificadaMedia (5.4)0.25%—Themefreesia Excellent21/6/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Theme Freesia Excellent allows Stored XSS.This issue affects Excellent: from n/a through 1.2.9.
AnalizadaAlta (7.8)2.1%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+114/5/202417/6/2026
Microsoft Excel Remote Code Execution Vulnerability
AplazadaMedia (5.9)0.34%—Extendwp Import Content IN Wordpress AND Woocommerce With ExcelAI18/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in extendWP Import Content in WordPress & WooCommerce with Excel allows Reflected XSS.This issue affects Import Content in WordPress & WooCommerce with Excel: from n/a through 4.2.
AplazadaMedia (4.3)0.37%—Hidekazu Ishikawa X-t9AIThemeinwp Default MAGAIOUT THE BOX NamahaAIOUT THE BOX CitylogicAI+1110/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Hidekazu Ishikawa X-T9, Hidekazu Ishikawa Lightning, themeinwp Default Mag, Out the Box Namaha, Out the Box CityLogic, Marsian i-max, Jetmonsters Emmet Lite, Macho Themes Decode, Wayneconnor Sliding Door, Out the Box Shopstar!, Modernthemesnet Gridsby, TT Themes…
AnalizadaAlta (7.5)0.83%—Myprestamodules Orders (csv, Excel) Export PRO20/3/202417/6/2026
An issue in MyPrestaModules ordersexport v.6.0.2 and before allows a remote attacker to execute arbitrary code via the download.php component.
AnalizadaCrítica (9.8)0.53%—Myprestamodules Product Catalog (csv, Excel) Import3/3/202417/6/2026
SQL Injection vulnerability in MyPrestaModules "Product Catalog (CSV, Excel) Import" (simpleimportproduct) modules for PrestaShop versions 6.5.0 and before, allows attackers to escalate privileges and obtain sensitive information via Send::__construct() and importProducts::_addDataToDb methods.
AnalizadaCrítica (9.1)0.79%—Myprestamodules Product Catalog (csv, Excel) Import27/2/202417/6/2026
In the module "Product Catalog (CSV, Excel) Import" (simpleimportproduct) <= 6.7.0 from MyPrestaModules for PrestaShop, a guest can upload files with extensions .php.
ModificadaAlta (7.8)1.2%—Microsoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Powerpoint+413/2/202410/8/2026
Microsoft Office Remote Code Execution Vulnerability
ModificadaMedia (6.1)0.66%💥 PoCRemyandrade Product Inventory With Export TO Excel29/1/202417/6/2026
Product Name and Product Code in the 'Add Product' section of Sourcecodester Product Inventory with Export to Excel 1.0 are vulnerable to XSS attacks.
ModificadaAlta (7.5)0.59%—Myprestamodules Orders (csv, Excel) Export PRO6/12/202317/6/2026
In the module "Orders (CSV, Excel) Export PRO" (ordersexport) < 5.2.0 from MyPrestaModules for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can access exports from the module which can lead to a leak of personal information from…
AnalizadaAlta (8.8)0.67%—Myprestamodules Orders (csv, Excel) Export PRO15/11/202317/6/2026
MyPrestaModules ordersexport before v5.0 was discovered to contain multiple SQL injection vulnerabilities at send.php via the key and save_setting parameters.
ModificadaAlta (7.8)57%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel14/11/202317/6/2026
Microsoft Excel Remote Code Execution Vulnerability
ModificadaAlta (7.8)1.2%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel14/11/202317/6/2026
Microsoft Excel Security Feature Bypass Vulnerability
ModificadaAlta (7.5)0.61%—Advanced Export Products Orders Cron CSV Excel Project Advanced Export Products Orders Cron CSV Excel7/11/202317/6/2026
Insecure permissions in Smart Soft advancedexport before v4.4.7 allow unauthenticated attackers to arbitrarily download user information from the ps_customer table.
ModificadaMedia (5.4)0.36%—Ipushpull Live Updates From Excel31/10/202317/6/2026
The Live updates from Excel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ipushpull_page' shortcode in versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…
ModificadaCrítica (9.8)0.98%—Myprestamodules Product Catalog (csv, Excel) Import20/9/202317/6/2026
SimpleImportProduct Prestashop Module v6.2.9 was discovered to contain a SQL injection vulnerability via the key parameter at send.php.
ModificadaAlta (7.5)32%💥 ExploitMyprestamodules Product Catalog (csv, Excel) ImportUpdateproducts Project Updateproducts20/9/202317/6/2026
MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInfo information disclosure vulnerability via send.php.
ModificadaMedia (5.5)1.2%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+112/9/202317/6/2026
Microsoft Excel Information Disclosure Vulnerability
ModificadaMedia (5.4)0.41%—Softexpert Excellence Suite14/6/202317/6/2026
SoftExpert Excellence Suite 2.1.9 is vulnerable to Cross Site Scripting (XSS) via query screens.
ModificadaAlta (7.8)44%—Microsoft 365 AppsMicrosoft ExcelMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online Server14/6/202317/6/2026
Microsoft Excel Remote Code Execution Vulnerability
Orbitaley — Vulnerabilidades