Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

1611 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.60%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+113/1/202617/6/2026
Desreferencia de puntero no confiable en Microsoft Office Word permite a un atacante no autorizado ejecutar código localmente.
AnalizadaAlta (7.8)0.66%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel13/1/202617/6/2026
Lectura fuera de límites en Microsoft Office Excel permite a un atacante no autorizado ejecutar código localmente.
AnalizadaAlta (8.4)0.52%—Microsoft 365 AppsMicrosoft Office Long Term Servicing Channel13/1/202617/6/2026
Lectura fuera de límites en Microsoft Office Word permite a un atacante no autorizado ejecutar código localmente.
AnalizadaMedia (4.7)0.21%💥 PoCTermix12/1/202617/6/2026
Termix es una plataforma de gestión de servidores basada en web con capacidades de terminal SSH, tunelización y edición de archivos. Desde la versión 1.7.0 hasta la 1.9.0, existe una vulnerabilidad de cross-site scripting (XSS) almacenado en el componente Termix File Manager. La aplicación no logra sanear el contenido…
AnalizadaCrítica (10)2.1%—Gongrzhe Terminal-controller-mcp7/1/202617/6/2026
A command injection vulnerability in the execute_command function of terminal-controller-mcp 0.1.7 allows attackers to execute arbitrary commands via a crafted input.
AplazadaMedia (6.5)0.35%—Aa-team PRO Bulk WatermarkAI31/12/202523/9/2026
Salto de ruta: '... / ...//' vulnerabilidad en el plugin AA-Team Pro Bulk Watermark para WordPress permite el salto de ruta. Este problema afecta a Pro Bulk Watermark Plugin para WordPress: desde n/a hasta 2.0.
AplazadaMedia (5.3)0.23%—Simplecoding Terms DescriptionsAI31/12/202517/6/2026
Vulnerabilidad de inserción de información sensible en datos enviados en descripciones de términos de Vladimir Statsenko permite recuperar datos sensibles incrustados. Este problema afecta a las descripciones de términos: desde n/d hasta 3.4.9.
AnalizadaCrítica (10)86%⚠ Explotación activa💥 ExploitSmartertools Smartermail29/12/20257/10/2026
La explotación exitosa de la vulnerabilidad podría permitir a un atacante no autenticado subir archivos arbitrarios a cualquier ubicación en el servidor de correo, potencialmente habilitando la ejecución remota de código.
AnalizadaMedia (4.1)0.18%—Mattermost Server24/12/202517/6/2026
Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fail to verify that post actions invoking /share-issue-publicly were created by the Jira plugin which allowed a malicious Mattermost user to exfiltrate Jira tickets when victim users interacted with affected posts
AnalizadaMedia (4.3)0.19%—Mattermost Server24/12/202517/6/2026
Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fails to validate user channel membership when attaching Mattermost posts as comments to Jira issues, which allows an authenticated attacker with access to the Jira plugin to read post content and attachments from channels…
AnalizadaAlta (8.3)0.26%—Mattermost Server22/12/202517/6/2026
Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 with the Jira plugin enabled and Mattermost Jira plugin versions <=4.4.0 fail to enforce authentication and issue-key path restrictions in the Jira plugin, which allows an unauthenticated attacker who knows a valid user ID…
AplazadaMedia (6.5)0.12%—Identity Agent FOR Terminal ServicesAI22/12/202517/6/2026
An authenticated local user can obtain information that allows claiming security policy rules of another user due to sensitive information being printed in plaintext in Identity Agent for Terminal Services debug files.
AnalizadaBaja (3.9)0.11%—Mattermost Desktop17/12/202517/6/2026
Mattermost Desktop App versions <6.0.0 fail to enable the Hardened Runtime on the Mattermost Desktop App when packaged for Mac App Store which allows an attacker to inherit TCC permissions via copying the binary to a tmp folder.
AnalizadaBaja (3.7)0.20%—Mattermost Server17/12/202517/6/2026
Mattermost versions 10.11.x <= 10.11.5, 11.0.x <= 11.0.4, 10.12.x <= 10.12.2 fail to invalidate remote cluster invite tokens when using the legacy (version 1) protocol or when the confirming party does not provide a refreshed token, which allows an attacker who has obtained an invite token to authenticate as the…
AnalizadaBaja (3.3)0.12%—Mattermost Desktop17/12/202517/6/2026
Mattermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on server deletion which allows an attacker with access to the users system to gain access to potentially sensitive information via reading the application logs.
AnalizadaMedia (6.5)0.29%—Mattermost Server17/12/202517/6/2026
Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 fail to check WebSocket request field for proper UTF-8 format, which allows attacker to crash Calls plug-in via sending malformed request.
AnalizadaMedia (6.1)0.15%—Mattermost Server17/12/202517/6/2026
Mattermost versions 10.11.x <= 10.11.4 fail to validate redirect URLs on the /error page, which allows an attacker to redirect a victim to a malicious site via a crafted link opened in a new tab.
AnalizadaMedia (4.3)0.12%—Mattermost Server17/12/202517/6/2026
Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 and Mattermost Calls versions <=1.10.0 fail to implement CSRF protection on the Calls widget page which allows an authenticated attacker to initiate calls and inject messages into channels or direct messages via a malicious webpage or crafted…
AnalizadaBaja (3)0.18%—Mattermost Server17/12/202517/6/2026
Mattermost versions 10.11.x <= 10.11.6 and Mattermost GitHub plugin versions <=2.4.0 fail to validate plugin bot identity in reaction forwarding which allows attackers to hijack the GitHub reaction feature to make users add reactions to arbitrary GitHub objects via crafted notification posts.
AnalizadaMedia (6.9)0.21%—Waveterm Wave Terminal12/12/202517/6/2026
Code Injection using Electron Fuses in waveterm on MacOS allows TCC Bypass. This issue affects waveterm: 0.12.2.
AnalizadaAlta (7.8)0.52%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+19/12/202517/6/2026
Una lectura fuera de límites en Microsoft Office Excel permite a un atacante no autorizado ejecutar código localmente.
AnalizadaAlta (7.8)0.61%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+19/12/202517/6/2026
Un uso después de liberar (use-after-free) en Microsoft Office Excel permite a un atacante no autorizado ejecutar código localmente.
AnalizadaAlta (7.8)0.81%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+19/12/202517/6/2026
Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.52%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+19/12/202517/6/2026
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.52%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+19/12/202517/6/2026
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.