Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2732▼ 9 respecto a la semana anterior
Críticas / altas1276▼ 237 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
1611 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.41% | — | Microsoft 365 AppsMicrosoft Office Long Term Servicing Channel | 11/11/2025 | 17/6/2026 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.51% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 11/11/2025 | 17/6/2026 | Un uso después de liberar (use-after-free) en Microsoft Office Excel permite a un atacante no autorizado ejecutar código localmente. | |
| Analizada | Alta (7.1) | 0.52% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 11/11/2025 | 17/6/2026 | Una lectura fuera de límites en Microsoft Office Excel permite a un atacante no autorizado divulgar información localmente. | |
| Analizada | Alta (7.8) | 0.48% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 11/11/2025 | 17/6/2026 | Un desbordamiento de búfer basado en montículo (heap) en Microsoft Office Excel permite a un atacante no autorizado ejecutar código localmente. | |
| Analizada | Alta (7.8) | 0.48% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 11/11/2025 | 17/6/2026 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Modificada | Alta (7.8) | 0.76% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft ExcelMicrosoft Office Long Term Servicing Channel | 11/11/2025 | 17/6/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (4.3) | 0.72% | — | Microsoft 365 AppsMicrosoft Office Long Term Servicing Channel | 11/11/2025 | 17/6/2026 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (7.8) | 0.64% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 11/11/2025 | 17/6/2026 | Una lectura fuera de límites en Microsoft Office Excel permite a un atacante no autorizado ejecutar código localmente. | |
| Analizada | Alta (7.1) | 0.58% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 11/11/2025 | 17/6/2026 | Una lectura fuera de límites en Microsoft Office Excel permite a un atacante no autorizado divulgar información localmente. | |
| Analizada | Crítica (9.8) | 5.9% | — | Microsoft 365 CopilotMicrosoft Office Long Term Servicing ChannelMicrosoft Windows 10 1607Microsoft Windows 10 1809+12 | 11/11/2025 | 17/6/2026 | Un desbordamiento de búfer basado en montículo (heap) en Microsoft Graphics Component permite a un atacante no autorizado ejecutar código a través de una red. | |
| Analizada | Media (5.5) | 0.59% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 11/11/2025 | 17/6/2026 | Exposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | |
| Aplazada | Alta (8.8) | 0.29% | — | NCR Atleos Terminal ManagerAI | 29/10/2025 | 17/6/2026 | An issue in NCR Atleos Terminal Manager (ConfigApp) v3.4.0 allows attackers to escalate privileges via a crafted request. | |
| Aplazada | Alta (7.1) | 0.30% | — | Somonator Terms DictionaryAI | 22/10/2025 | 8/10/2026 | Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en Somonator Terms Dictionary terms-dictionary permite XSS Reflejado. Este problema afecta a Terms Dictionary: desde n/a hasta menor o igual que 1.5.1. | |
| Analizada | Media (6.1) | 0.32% | — | Mattermost Desktop | 16/10/2025 | 17/6/2026 | Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that stops a user with a server that uses basic authentication from accessing their server which allows an attacker that provides a malicious server to the user to deny use of the Desktop App via having the user configure the… | |
| Analizada | Alta (8.1) | 0.34% | — | Mattermost Server | 16/10/2025 | 17/6/2026 | Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the original invite token which allows any attacked to join any team on a Mattermost server regardless of restrictions via manipulating the RelayState | |
| Analizada | Alta (8.1) | 0.42% | — | Mattermost Server | 16/10/2025 | 17/6/2026 | Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the original invite token which allows any attacked to join any team on a Mattermost server regardless of restrictions via manipulating the OAuth state. | |
| Analizada | Baja (3.7) | 0.27% | — | Mattermost Server | 16/10/2025 | 17/6/2026 | Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to use constant-time comparison for sensitive string comparisons which allows attackers to exploit timing oracles to perform byte-by-byte brute force attacks via response time analysis on Cloud API keys and OAuth client secrets | |
| Analizada | Media (5.4) | 0.30% | — | Mattermost Server | 16/10/2025 | 17/6/2026 | Mattermost versions 10.10.x <= 10.10.2, 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to validate email ownership during Slack import process which allows attackers to create verified user accounts with arbitrary email domains via malicious Slack import data to bypass email-based team access restrictions | |
| Analizada | Media (4.3) | 0.33% | — | Mattermost Server | 16/10/2025 | 17/6/2026 | Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when adding channel members which allows guest users to add any team members to their private channels via the `/api/v4/channels/{channel_id}/members` endpoint | |
| Modificada | Media (4.3) | 0.31% | — | Mattermost Server | 16/10/2025 | 17/6/2026 | Mattermost versions 10.5.x <= 10.5.12, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when accessing channel information which allows guest users to discover active public channels and their metadata via the `/api/v4/teams/{team_id}/channels/ids` endpoint | |
| Analizada | Alta (7.8) | 0.45% | — | Microsoft 365 AppsMicrosoft Office Long Term Servicing Channel | 14/10/2025 | 17/6/2026 | Un uso después de liberar (use-after-free) en Microsoft Office Excel permite a un atacante no autorizado ejecutar código localmente. | |
| Analizada | Alta (7.8) | 0.38% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Powerpoint | 14/10/2025 | 17/6/2026 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.42% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online Server | 14/10/2025 | 17/6/2026 | Un uso después de liberar (use-after-free) en Microsoft Office Excel permite a un atacante no autorizado ejecutar código localmente. | |
| Analizada | Alta (7.1) | 0.66% | — | Microsoft 365 AppsMicrosoft AccessMicrosoft ExcelMicrosoft Office+3 | 14/10/2025 | 17/6/2026 | Una lectura fuera de límites en Microsoft Office Excel permite a un atacante no autorizado divulgar información localmente. | |
| Analizada | Alta (7.8) | 0.60% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 14/10/2025 | 17/6/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |