Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2734▼ 7 respecto a la semana anterior
Críticas / altas1273▼ 240 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
1611 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.53% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 14/10/2025 | 17/6/2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.1) | 0.48% | — | Microsoft 365 AppsMicrosoft AccessMicrosoft ExcelMicrosoft Office+3 | 14/10/2025 | 17/6/2026 | Una lectura fuera de límites en Microsoft Office Excel permite a un atacante no autorizado divulgar información localmente. | |
| Analizada | Alta (7.8) | 0.53% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 14/10/2025 | 17/6/2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (5.5) | 0.42% | — | Microsoft 365 AppsMicrosoft Office Long Term Servicing Channel | 14/10/2025 | 17/6/2026 | Uncaught exception in Microsoft Office allows an unauthorized attacker to deny service locally. | |
| Analizada | Alta (7.8) | 0.52% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 14/10/2025 | 17/6/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.38% | — | Microsoft 365 AppsMicrosoft Office Long Term Servicing Channel | 14/10/2025 | 17/6/2026 | Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.38% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 14/10/2025 | 17/6/2026 | Un uso después de liberar (use-after-free) en Microsoft Office Excel permite a un atacante no autorizado ejecutar código localmente. | |
| Analizada | Alta (7.8) | 0.38% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 14/10/2025 | 17/6/2026 | Un uso después de liberar (use-after-free) en Microsoft Office Excel permite a un atacante no autorizado ejecutar código localmente. | |
| Analizada | Alta (7.8) | 0.38% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 14/10/2025 | 17/6/2026 | Un uso después de liberar (use-after-free) en Microsoft Office Excel permite a un atacante no autorizado ejecutar código localmente. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+1 | 14/10/2025 | 17/6/2026 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7) | 0.39% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+1 | 14/10/2025 | 17/6/2026 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (6.5) | 0.30% | — | Mattermost Desktop | 13/10/2025 | 17/6/2026 | Mattermost Desktop App versions <= 5.13.0 fail to validate URLs external to the configured Mattermost servers, allowing an attacker on a server the user has configured to crash the user's application by sending the user a malformed URL. | |
| Aplazada | Media (6.6) | 0.35% | — | Minecraft Rcon TerminalAIMicrosoft Visual Studio CodeAI | 3/10/2025 | 8/10/2026 | Minecraft RCON Terminal es una extensión de VS Code que agiliza la gestión del servidor de Minecraft. Las versiones 0.1.0 a la 2.0.6 almacenan contraseñas utilizando la API de configuración de VS Code, que escribe en settings.json en texto plano. Este problema se ha corregido en la versión 2.1.0. | |
| Analizada | Crítica (9.2) | 4.3% | — | Termix | 1/10/2025 | 17/6/2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The official Docker image for Termix versions 1.5.0 and below, due to being configured with an Nginx reverse proxy, causes the backend to retrieve the proxy's IP instead of the client's IP when using the… | |
| Aplazada | Media (6.5) | 0.21% | — | TermageddonAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in termageddon Termageddon: Cookie Consent & Privacy Compliance termageddon-usercentrics allows Stored XSS.This issue affects Termageddon: Cookie Consent & Privacy Compliance: from n/a through <= 1.8.1. | |
| Aplazada | Media (4.3) | 0.25% | — | Mantrabrain Ultimate WatermarkAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in MantraBrain Ultimate Watermark ultimate-watermark allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Watermark: from n/a through <= 1.1. | |
| Analizada | Media (6.5) | 0.27% | — | Mattermost Server | 19/9/2025 | 17/6/2026 | Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate access controls which allows any authenticated user to download sensitive files via board file download endpoint using UUID enumeration | |
| Analizada | Alta (7.2) | 0.64% | — | Mattermost Server | 19/9/2025 | 17/6/2026 | Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.x <= 10.9.3 fail to validate import directory path configuration which allows admin users to execute arbitrary code via malicious plugin upload to prepackaged plugins directory | |
| Analizada | Media (6.1) | 0.17% | — | Mattermost Server | 15/9/2025 | 17/6/2026 | Mattermost versions 10.5.x <= 10.5.9 fail to properly validate redirect URLs which allows attackers to redirect users to malicious sites via crafted OAuth login URLs | |
| Analizada | Media (5.4) | 0.18% | — | Mattermost Server | 15/9/2025 | 17/6/2026 | Mattermost versions 10.10.x <= 10.10.1, 10.5.x <= 10.5.9, 10.9.x <= 10.9.4 fail to validate the redirect_to parameter, allowing an attacker to craft a malicious link that, once a user authenticates with their SAML provider, could post the user’s cookies to an attacker-controlled URL. | |
| Analizada | Media (4.3) | 0.15% | — | Mattermost Server | 15/9/2025 | 17/6/2026 | Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.x <= 10.9.3 fail to properly validate cache keys for link metadata which allows authenticated users to access unauthorized posts and poison link previews via hash collision attacks on FNV-1 hashing | |
| Analizada | Media (6.5) | 0.26% | — | Mattermost Server | 15/9/2025 | 17/6/2026 | Mattermost versions 10.10.x <= 10.10.1 fail to properly sanitize user data during shared channel membership synchronization, which allows malicious or compromised remote clusters to access sensitive user information via unsanitized user objects. This vulnerability affects Mattermost Server instances with shared… | |
| Analizada | Alta (8.4) | 0.55% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 9/9/2025 | 17/6/2026 | Un desbordamiento de búfer basado en montículo (heap) en Microsoft Office permite a un atacante no autorizado ejecutar código localmente. | |
| Analizada | Alta (7.8) | 0.60% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Powerpoint | 9/9/2025 | 17/6/2026 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.51% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 9/9/2025 | 17/6/2026 | Heap-based buffer overflow in Microsoft Office Visio allows an unauthorized attacker to execute code locally. |