Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
2573 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 0.26% | — | Ntoolslab Office Reader | 4/2/2026 | 5/7/2026 | A path traversal in Moo Chan Song v4.5.7 allows attackers to cause a Denial of Service (DoS) via writing files to the internal storage. | |
| Analizada | Crítica (9.4) | 0.90% | — | Group-office Group Office | 2/2/2026 | 17/6/2026 | Group-Office is an enterprise customer relationship management and groupware tool. Prior to 6.8.150, 25.0.82, and 26.0.5, the MaintenanceController exposes an action zipLanguage which takes a lang parameter and passes it directly to a system zip command via exec(). This can be combined with uploading a crafted zip… | |
| Analizada | Alta (7.1) | 0.22% | — | Danofficeit Local Admin Service | 30/1/2026 | 17/6/2026 | Improper access control in the WCF endpoint in Edgemo (now owned by Danoffice IT) Local Admin Service 1.2.7.23180 on Windows allows a local user to escalate their privileges to local administrator via direct communication with the LocalAdminService.exe named pipe, bypassing client-side group membership restrictions. | |
| Analizada | Alta (7.8) | 71% | ⚠ Explotación activa💥 PoC | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 26/1/2026 | 25/6/2026 | Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally. | |
| Analizada | Media (5.1) | 0.28% | — | Group-office Group Office | 22/1/2026 | 17/6/2026 | Group-Office is an enterprise customer relationship management and groupware tool. In versions 6.8.148 and below, and 25.0.1 through 25.0.79, the application stores unsanitized filenames in the database, which can lead to Stored Cross-Site Scripting (XSS). Users who interact with these specially crafted file names… | |
| Analizada | Alta (7.8) | 0.50% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 13/1/2026 | 17/6/2026 | Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.44% | — | Microsoft 365 AppsMicrosoft Office Long Term Servicing Channel | 13/1/2026 | 17/6/2026 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.61% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online Server | 13/1/2026 | 17/6/2026 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (8.4) | 0.59% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 13/1/2026 | 17/6/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (8.4) | 0.53% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 13/1/2026 | 17/6/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.50% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 13/1/2026 | 17/6/2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft Office Long Term Servicing Channel | 13/1/2026 | 17/6/2026 | Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally. | |
| Analizada | Alta (7.8) | 0.61% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+1 | 13/1/2026 | 17/6/2026 | Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.67% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 13/1/2026 | 17/6/2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (8.4) | 0.52% | — | Microsoft 365 AppsMicrosoft Office Long Term Servicing Channel | 13/1/2026 | 17/6/2026 | Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7) | 0.66% | — | Microsoft OfficeMicrosoft Office Deployment ToolMicrosoft Sharepoint Server | 13/1/2026 | 17/6/2026 | Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Aplazada | Media (6.5) | 0.31% | — | Wofficeio Woffice CoreAI | 8/1/2026 | 7/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in WofficeIO Woffice Core woffice-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Woffice Core: from n/a through <= 5.4.30. | |
| Aplazada | Alta (7.1) | 0.22% | — | Xtendify WofficeAI | 8/1/2026 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WofficeIO Woffice woffice allows Reflected XSS.This issue affects Woffice: from n/a through <= 5.4.30. | |
| Analizada | Media (6.1) | 0.20% | — | Onlyoffice Document Server | 25/12/2025 | 7/10/2026 | ONLYOFFICE Docs before 9.2.1 allows XSS via the Color theme name. This is related to DocumentServer. | |
| Analizada | Media (6.1) | 0.20% | — | Onlyoffice Document Server | 25/12/2025 | 7/10/2026 | ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window. This is related to DocumentServer. | |
| Aplazada | Media (6.4) | 0.18% | — | Onlyoffice DocsAI | 24/12/2025 | 7/10/2026 | ONLYOFFICE Docs before 9.2.1 allows XSS in the textarea of the comment editing form. This is related to DocumentServer. | |
| Analizada | Alta (8.2) | 0.52% | — | Microsoft Office Out-of-box Experience | 18/12/2025 | 1/10/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Office Out-of-Box Experience allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Baja (0.9) | 0.14% | — | Libreoffice | 15/12/2025 | 7/10/2026 | An Authentication Bypass vulnerability existed where the application bundled an interpreter (Python) that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle By executing the bundled interpreter directly the attacker's scripts run with the application's… | |
| Analizada | Media (6.5) | 0.57% | — | A1apps Office App-edit Word, PDF File | 10/12/2025 | 17/6/2026 | A lack of security checks in the file import process of RHOPHI Analytics LLP Office App-Edit Word v6.4.1 allows attackers to execute a directory traversal. | |
| Analizada | Alta (7.8) | 0.52% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 9/12/2025 | 17/6/2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |