Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

2573 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)0.26%—Ntoolslab Office Reader4/2/20265/7/2026
A path traversal in Moo Chan Song v4.5.7 allows attackers to cause a Denial of Service (DoS) via writing files to the internal storage.
AnalizadaCrítica (9.4)0.90%—Group-office Group Office2/2/202617/6/2026
Group-Office is an enterprise customer relationship management and groupware tool. Prior to 6.8.150, 25.0.82, and 26.0.5, the MaintenanceController exposes an action zipLanguage which takes a lang parameter and passes it directly to a system zip command via exec(). This can be combined with uploading a crafted zip…
AnalizadaAlta (7.1)0.22%—Danofficeit Local Admin Service30/1/202617/6/2026
Improper access control in the WCF endpoint in Edgemo (now owned by Danoffice IT) Local Admin Service 1.2.7.23180 on Windows allows a local user to escalate their privileges to local administrator via direct communication with the LocalAdminService.exe named pipe, bypassing client-side group membership restrictions.
AnalizadaAlta (7.8)71%⚠ Explotación activa💥 PoCMicrosoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel26/1/202625/6/2026
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
AnalizadaMedia (5.1)0.28%—Group-office Group Office22/1/202617/6/2026
Group-Office is an enterprise customer relationship management and groupware tool. In versions 6.8.148 and below, and 25.0.1 through 25.0.79, the application stores unsanitized filenames in the database, which can lead to Stored Cross-Site Scripting (XSS). Users who interact with these specially crafted file names…
AnalizadaAlta (7.8)0.50%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+113/1/202617/6/2026
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.44%—Microsoft 365 AppsMicrosoft Office Long Term Servicing Channel13/1/202617/6/2026
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.61%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online Server13/1/202617/6/2026
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (8.4)0.59%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel13/1/202617/6/2026
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
AnalizadaAlta (8.4)0.53%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel13/1/202617/6/2026
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.50%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+113/1/202617/6/2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft Office Long Term Servicing Channel13/1/202617/6/2026
Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally.
AnalizadaAlta (7.8)0.61%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+113/1/202617/6/2026
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.67%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel13/1/202617/6/2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (8.4)0.52%—Microsoft 365 AppsMicrosoft Office Long Term Servicing Channel13/1/202617/6/2026
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7)0.66%—Microsoft OfficeMicrosoft Office Deployment ToolMicrosoft Sharepoint Server13/1/202617/6/2026
Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally.
AplazadaMedia (6.5)0.31%—Wofficeio Woffice CoreAI8/1/20267/10/2026
Authorization Bypass Through User-Controlled Key vulnerability in WofficeIO Woffice Core woffice-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Woffice Core: from n/a through <= 5.4.30.
AplazadaAlta (7.1)0.22%—Xtendify WofficeAI8/1/20267/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WofficeIO Woffice woffice allows Reflected XSS.This issue affects Woffice: from n/a through <= 5.4.30.
AnalizadaMedia (6.1)0.20%—Onlyoffice Document Server25/12/20257/10/2026
ONLYOFFICE Docs before 9.2.1 allows XSS via the Color theme name. This is related to DocumentServer.
AnalizadaMedia (6.1)0.20%—Onlyoffice Document Server25/12/20257/10/2026
ONLYOFFICE Docs before 9.2.1 allows XSS via the Font field for the Multilevel list settings window. This is related to DocumentServer.
AplazadaMedia (6.4)0.18%—Onlyoffice DocsAI24/12/20257/10/2026
ONLYOFFICE Docs before 9.2.1 allows XSS in the textarea of the comment editing form. This is related to DocumentServer.
AnalizadaAlta (8.2)0.52%—Microsoft Office Out-of-box Experience18/12/20251/10/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Office Out-of-Box Experience allows an unauthorized attacker to perform spoofing over a network.
AnalizadaBaja (0.9)0.14%—Libreoffice15/12/20257/10/2026
An Authentication Bypass vulnerability existed where the application bundled an interpreter (Python) that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle By executing the bundled interpreter directly the attacker's scripts run with the application's…
AnalizadaMedia (6.5)0.57%—A1apps Office App-edit Word, PDF File10/12/202517/6/2026
A lack of security checks in the file import process of RHOPHI Analytics LLP Office App-Edit Word v6.4.1 allows attackers to execute a directory traversal.
AnalizadaAlta (7.8)0.52%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+19/12/202517/6/2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.