Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
445 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 2.4% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 9/2/2022 | 17/6/2026 | Microsoft Office Graphics Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 2.9% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 9/2/2022 | 17/6/2026 | Microsoft Office Visio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 2.6% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 11/1/2022 | 17/6/2026 | Microsoft Excel Remote Code Execution Vulnerability | |
| Modificada | Alta (8.8) | 3.1% | — | Microsoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online Server+3 | 11/1/2022 | 17/6/2026 | Microsoft Office Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 5.1% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 15/12/2021 | 17/6/2026 | Microsoft Office Graphics Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 2.1% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft Excel RTMicrosoft Office+3 | 15/12/2021 | 17/6/2026 | Microsoft Excel Remote Code Execution Vulnerability | |
| Modificada | Media (5.5) | 2.0% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 15/12/2021 | 17/6/2026 | Microsoft Office Trust Center Spoofing Vulnerability | |
| Modificada | Media (5.5) | 2.9% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 15/12/2021 | 17/6/2026 | Visual Basic for Applications Information Disclosure Vulnerability | |
| Modificada | Media (6.5) | 2.8% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 15/12/2021 | 17/6/2026 | Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.8) | 1.1% | — | Microsoft 365 AppsMicrosoft Office Long Term Servicing Channel | 10/11/2021 | 19/8/2026 | Microsoft Word Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 4.9% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 10/11/2021 | 19/8/2026 | Microsoft Access Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 2.3% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+3 | 10/11/2021 | 19/8/2026 | Microsoft Excel Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 2.7% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+2 | 13/10/2021 | 17/6/2026 | Microsoft Excel Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 5.9% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 13/10/2021 | 17/6/2026 | Microsoft Office Visio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 5.7% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 13/10/2021 | 17/6/2026 | Microsoft Office Visio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 2.3% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 13/10/2021 | 17/6/2026 | Microsoft Excel Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 2.3% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+2 | 13/10/2021 | 17/6/2026 | Microsoft Excel Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 2.3% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 13/10/2021 | 17/6/2026 | Microsoft Excel Remote Code Execution Vulnerability | |
| Modificada | Media (5.5) | 0.73% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+2 | 13/10/2021 | 17/6/2026 | Microsoft Excel Information Disclosure Vulnerability | |
| Modificada | Alta (7.8) | 2.3% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 13/10/2021 | 17/6/2026 | Microsoft Excel Remote Code Execution Vulnerability | |
| Modificada | Alta (8.1) | 1.1% | — | Mirahezebots Channelmgnt | 9/4/2021 | 17/6/2026 | sopel-channelmgnt is a channelmgnt plugin for sopel. In versions prior to 2.0.1, on some IRC servers, restrictions around the removal of the bot using the kick/kickban command could be bypassed when kicking multiple users at once. We also believe it may have been possible to remove users from other channels but due to… | |
| Modificada | Alta (7.4) | 2.7% | — | Djangoproject Channels | 22/2/2021 | 17/6/2026 | Django Channels 3.x before 3.0.3 allows remote attackers to obtain sensitive information from a different request scope. The legacy channels.http.AsgiHandler class, used for handling HTTP type requests in an ASGI environment prior to Django 3.0, did not correctly separate request scopes in Channels 3.0. In many cases… | |
| Modificada | Media (5.5) | 0.39% | — | Crossbeam-channel Project Crossbeam-channel | 31/12/2020 | 17/6/2026 | An issue was discovered in the crossbeam-channel crate before 0.4.4 for Rust. It has incorrect expectations about the relationship between the memory allocation and how many iterator elements there are. | |
| Modificada | Media (6.5) | 1.5% | — | Mirahezebots Channelmgnt | 13/10/2020 | 17/6/2026 | In the Channelmgnt plug-in for Sopel (a Python IRC bot) before version 1.0.3, malicious users are able to op/voice and take over a channel. This is an ACL bypass vulnerability. This plugin is bundled with MirahezeBot-Plugins with versions from 9.0.0 and less than 9.0.2 affected. Version 9.0.2 includes 1.0.3 of… | |
| Modificada | Media (6.1) | 3.8% | 💥 Exploit | Podcast Channels Project Podcast Channels | 27/12/2019 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Podcast Channels plugin 0.20 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the Filename parameter to getid3/demos/demo.write.php. |