Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2732▼ 9 respecto a la semana anterior
Críticas / altas1276▼ 237 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
–

1611 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.41%—Microsoft 365 AppsMicrosoft Office Long Term Servicing Channel11/11/202517/6/2026
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.51%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+111/11/202517/6/2026
Un uso después de liberar (use-after-free) en Microsoft Office Excel permite a un atacante no autorizado ejecutar código localmente.
AnalizadaAlta (7.1)0.52%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+111/11/202517/6/2026
Una lectura fuera de límites en Microsoft Office Excel permite a un atacante no autorizado divulgar información localmente.
AnalizadaAlta (7.8)0.48%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+111/11/202517/6/2026
Un desbordamiento de búfer basado en montículo (heap) en Microsoft Office Excel permite a un atacante no autorizado ejecutar código localmente.
AnalizadaAlta (7.8)0.48%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+111/11/202517/6/2026
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
ModificadaAlta (7.8)0.76%—Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft ExcelMicrosoft Office Long Term Servicing Channel11/11/202517/6/2026
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
AnalizadaMedia (4.3)0.72%—Microsoft 365 AppsMicrosoft Office Long Term Servicing Channel11/11/202517/6/2026
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (7.8)0.64%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+111/11/202517/6/2026
Una lectura fuera de límites en Microsoft Office Excel permite a un atacante no autorizado ejecutar código localmente.
AnalizadaAlta (7.1)0.58%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+111/11/202517/6/2026
Una lectura fuera de límites en Microsoft Office Excel permite a un atacante no autorizado divulgar información localmente.
AnalizadaCrítica (9.8)5.9%—Microsoft 365 CopilotMicrosoft Office Long Term Servicing ChannelMicrosoft Windows 10 1607Microsoft Windows 10 1809+1211/11/202517/6/2026
Un desbordamiento de búfer basado en montículo (heap) en Microsoft Graphics Component permite a un atacante no autorizado ejecutar código a través de una red.
AnalizadaMedia (5.5)0.59%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel11/11/202517/6/2026
Exposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
AplazadaAlta (8.8)0.29%—NCR Atleos Terminal ManagerAI29/10/202517/6/2026
An issue in NCR Atleos Terminal Manager (ConfigApp) v3.4.0 allows attackers to escalate privileges via a crafted request.
AplazadaAlta (7.1)0.30%—Somonator Terms DictionaryAI22/10/20258/10/2026
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en Somonator Terms Dictionary terms-dictionary permite XSS Reflejado. Este problema afecta a Terms Dictionary: desde n/a hasta menor o igual que 1.5.1.
AnalizadaMedia (6.1)0.32%—Mattermost Desktop16/10/202517/6/2026
Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that stops a user with a server that uses basic authentication from accessing their server which allows an attacker that provides a malicious server to the user to deny use of the Desktop App via having the user configure the…
AnalizadaAlta (8.1)0.34%—Mattermost Server16/10/202517/6/2026
Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the original invite token which allows any attacked to join any team on a Mattermost server regardless of restrictions via manipulating the RelayState
AnalizadaAlta (8.1)0.42%—Mattermost Server16/10/202517/6/2026
Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the original invite token which allows any attacked to join any team on a Mattermost server regardless of restrictions via manipulating the OAuth state.
AnalizadaBaja (3.7)0.27%—Mattermost Server16/10/202517/6/2026
Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to use constant-time comparison for sensitive string comparisons which allows attackers to exploit timing oracles to perform byte-by-byte brute force attacks via response time analysis on Cloud API keys and OAuth client secrets
AnalizadaMedia (5.4)0.30%—Mattermost Server16/10/202517/6/2026
Mattermost versions 10.10.x <= 10.10.2, 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to validate email ownership during Slack import process which allows attackers to create verified user accounts with arbitrary email domains via malicious Slack import data to bypass email-based team access restrictions
AnalizadaMedia (4.3)0.33%—Mattermost Server16/10/202517/6/2026
Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when adding channel members which allows guest users to add any team members to their private channels via the `/api/v4/channels/{channel_id}/members` endpoint
ModificadaMedia (4.3)0.31%—Mattermost Server16/10/202517/6/2026
Mattermost versions 10.5.x <= 10.5.12, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when accessing channel information which allows guest users to discover active public channels and their metadata via the `/api/v4/teams/{team_id}/channels/ids` endpoint
AnalizadaAlta (7.8)0.45%—Microsoft 365 AppsMicrosoft Office Long Term Servicing Channel14/10/202517/6/2026
Un uso después de liberar (use-after-free) en Microsoft Office Excel permite a un atacante no autorizado ejecutar código localmente.
AnalizadaAlta (7.8)0.38%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Powerpoint14/10/202517/6/2026
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.42%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online Server14/10/202517/6/2026
Un uso después de liberar (use-after-free) en Microsoft Office Excel permite a un atacante no autorizado ejecutar código localmente.
AnalizadaAlta (7.1)0.66%—Microsoft 365 AppsMicrosoft AccessMicrosoft ExcelMicrosoft Office+314/10/202517/6/2026
Una lectura fuera de límites en Microsoft Office Excel permite a un atacante no autorizado divulgar información localmente.
AnalizadaAlta (7.8)0.60%—Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel14/10/202517/6/2026
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
Orbitaley — Vulnerabilidades