Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

2573 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+39/6/202623/7/2026
Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (8.2)0.60%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+39/6/202623/7/2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
AnalizadaMedia (5.5)0.60%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+39/6/202623/7/2026
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
ModificadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+39/6/202623/7/2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.57%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+39/6/202623/7/2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
ModificadaAlta (7)0.28%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+39/6/202623/7/2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
ModificadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+39/6/202623/7/2026
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AplazadaMedia (5.1)0.39%—Group-officeAI29/5/202621/7/2026
Group-Office is an enterprise customer relationship management and groupware tool. Prior to 26.0.25, 25.0.100, and 6.8.165, GroupOffice allows authenticated users to persist arbitrary legacy settings for any user_id via index.php?r=core/saveSetting. A separate client-side sink in the email module injects the…
AplazadaMedia (4.3)0.27%—Onlyoffice DocspaceAI26/5/202624/7/2026
An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ONLYOFFICE DocSpace before 3.2.1. The flaw exists in multiple REST API endpoints. This allows authenticated users with low-level permissions (User or Guest) to retrieve sensitive information, such as the Owner's unique identifier (ID) and…
AplazadaMedia (5.9)0.39%—ElasticsearchAIMicrosoft Office Open XMLAI19/5/202617/6/2026
The OOXML parsing of the file indexer does not disable external entity resolution. A crafted xlsx or pptx document placed in an indexed directory can cause local files to be read or outbound HTTP requests to be performed, with the retrieved content being written to the search index.
AnalizadaAlta (7.5)0.49%—Phpoffice Phpspreadsheet12/5/202617/6/2026
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.4, 2.1.16, 2.4.5, 3.10.5, and 5.7.0, the XLSX reader's ColumnAndRowAttributes::readRowAttributes() method reads row numbers from XML attributes without validating them against the spreadsheet maximum row limit…
AnalizadaAlta (7.5)0.49%—Phpoffice Phpspreadsheet12/5/202617/6/2026
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.4, 2.1.16, 2.4.5, 3.10.5, and 5.7.0, the SpreadsheetML XML reader (Reader\Xml) does not validate the ss:Index row attribute against the maximum allowed row count (AddressRange::MAX_ROW = 1,048,576). An attacker can craft a…
AnalizadaMedia (5.5)0.31%—Microsoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Word12/5/202617/6/2026
Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel12/5/202617/6/2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
ModificadaMedia (4.3)0.70%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Word12/5/202617/6/2026
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
ModificadaAlta (8.8)0.30%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel12/5/202617/6/2026
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.33%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel12/5/202617/6/2026
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
ModificadaAlta (7.8)0.33%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel12/5/202617/6/2026
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
ModificadaAlta (8.4)0.45%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+112/5/202617/6/2026
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
ModificadaAlta (8.4)0.36%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Word12/5/202617/6/2026
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaAlta (8.4)0.36%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Word12/5/202617/6/2026
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaAlta (8.4)0.36%—Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel12/5/202617/6/2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
ModificadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+112/5/202617/6/2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
ModificadaAlta (8.4)0.36%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Word12/5/202617/6/2026
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+112/5/202617/6/2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.