Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
2573 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.17% | — | LibreofficeAI | 15/6/2026 | 17/6/2026 | LibreOffice can import documents in the OOXML format (DOCX). A heap buffer overflow existed when replaying deferred parser events for a text box element. A handler object was assumed to be of one type and written to at that type's field layout, but it could be a smaller object, so the write landed past the end of the… | |
| Aplazada | Media (5.4) | 0.17% | — | LibreofficeAI | 15/6/2026 | 17/6/2026 | LibreOffice can import EMF+ graphics, which may be embedded in documents. A heap buffer overflow existed when importing an EMF+ gradient brush. The number of gradient blend points was read from the file and used to compute an allocation size, but that multiplication could overflow, so a small buffer was allocated and… | |
| Aplazada | Media (5.4) | 0.17% | — | LibreofficeAI | 15/6/2026 | 23/7/2026 | A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the document was not checked against the length of the format-code string, so a malformed number format could be processed against memory outside that string. In fixed versions the position is… | |
| Aplazada | Media (5.4) | 0.17% | — | LibreofficeAI | 15/6/2026 | 17/6/2026 | LibreOffice can import drawings in the DXF format used by CAD software. A heap buffer overflow existed when importing a DXF polyline. The point count taken from the file was truncated to a 16-bit value when the point buffer was sized, while the full count was used to fill it, so a polyline whose point count exceeded… | |
| Modificada | Alta (8.4) | 0.36% | — | Microsoft Office 2024 | 9/6/2026 | 23/7/2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7) | 0.26% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office 2021Microsoft Office 2024 | 9/6/2026 | 23/7/2026 | Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally. | |
| Modificada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+2 | 9/6/2026 | 23/7/2026 | Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2021Microsoft Office 2024 | 9/6/2026 | 23/7/2026 | Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Modificada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2021Microsoft Office 2024 | 9/6/2026 | 23/7/2026 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Baja (3.3) | 0.56% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+3 | 9/6/2026 | 23/7/2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (7.8) | 0.57% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+3 | 9/6/2026 | 23/7/2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Modificada | Alta (8.4) | 0.36% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft 365Microsoft Office 2016+3 | 9/6/2026 | 23/7/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Modificada | Alta (8.4) | 0.36% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft 365Microsoft Office 2016+3 | 9/6/2026 | 23/7/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.57% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+3 | 9/6/2026 | 23/7/2026 | Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+3 | 9/6/2026 | 23/7/2026 | Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Baja (3.3) | 0.47% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2021Microsoft Office 2024 | 9/6/2026 | 23/7/2026 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |
| Modificada | Alta (8.4) | 0.36% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft 365Microsoft Office 2016+3 | 9/6/2026 | 23/7/2026 | Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Modificada | Alta (8.4) | 0.36% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft 365Microsoft Office 2016+3 | 9/6/2026 | 23/7/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Modificada | Media (4.7) | 0.42% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft 365Microsoft Office 2019+2 | 9/6/2026 | 23/7/2026 | Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information locally. | |
| Analizada | Baja (3.3) | 0.47% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2021Microsoft Office 2024 | 9/6/2026 | 23/7/2026 | Protection mechanism failure in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally. | |
| Modificada | Alta (8.4) | 0.45% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+3 | 9/6/2026 | 23/7/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Modificada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2021Microsoft Office 2024 | 9/6/2026 | 23/7/2026 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (8.4) | 0.45% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+3 | 9/6/2026 | 23/7/2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Modificada | Media (4.3) | 0.76% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+3 | 9/6/2026 | 23/7/2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (7.8) | 0.57% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+3 | 9/6/2026 | 23/7/2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. |