Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

103 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.4)0.36%—Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft 365Microsoft Office 2016+39/6/202623/7/2026
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
ModificadaAlta (8.4)0.36%—Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft 365Microsoft Office 2016+39/6/202623/7/2026
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
ModificadaAlta (8.4)0.36%—Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft 365Microsoft Office 2016+39/6/202623/7/2026
Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.
ModificadaAlta (8.4)0.36%—Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft 365Microsoft Office 2016+39/6/202623/7/2026
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
ModificadaMedia (4.7)0.42%—Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft 365Microsoft Office 2019+29/6/202623/7/2026
Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information locally.
AnalizadaAlta (7.5)0.92%—Microsoft Copilot Chat4/6/202623/7/2026
Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (8.8)0.61%—Microsoft Copilot4/6/202623/7/2026
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute code over a network.
ModificadaAlta (7.5)0.92%—Microsoft Copilot4/6/202623/7/2026
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (7.5)0.92%—Microsoft 365 Copilot22/5/202623/7/2026
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.
AnalizadaCrítica (9.3)0.76%—Microsoft 365 Copilot22/5/202623/7/2026
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.
AnalizadaAlta (8.5)0.38%—Github Copilot-cli13/5/202617/6/2026
GitHub Copilot CLI brings AI-powered coding assistance directly to your command line. Prior to 1.0.43, a security vulnerability has been identified in GitHub Copilot CLI where a malicious bare git repository nested inside a project directory can achieve arbitrary code execution when the agent performs git operations.…
AnalizadaAlta (7.8)0.47%—Microsoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel12/5/202617/6/2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
AnalizadaMedia (6.2)0.40%—Microsoft 365 Copilot12/5/202617/6/2026
Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally.
AnalizadaMedia (4.4)0.26%—Microsoft 365 Copilot12/5/202617/6/2026
Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally.
AnalizadaAlta (8.4)0.36%—Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel12/5/202617/6/2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
AplazadaCrítica (10)0.78%—Microsoft CopilotAI11/5/202617/6/2026
SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57, SOCFortress CoPilot ships a hardcoded JWT signing secret as a fallback value in backend/app/auth/utils.py:28 and ships it verbatim in .env.example. Any deployment where JWT_SECRET is not explicitly…
AnalizadaAlta (7.5)1.0%—Microsoft Copilot Chat7/5/202617/6/2026
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network.
ModificadaAlta (7.5)1.0%—Microsoft 365 Copilot Chat7/5/202617/6/2026
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.
ModificadaAlta (7.5)1.0%—Microsoft 365 Copilot Chat7/5/202617/6/2026
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.
AnalizadaCrítica (9.3)0.72%—Microsoft 365 Copilot23/4/202617/6/2026
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
AplazadaBaja (2.1)0.34%—Ericc-ch Copilot-apiAI23/4/202617/6/2026
A vulnerability was determined in ericc-ch copilot-api up to 0.7.0. This impacts an unknown function of the file /token of the component Header Handler. Executing a manipulation of the argument Host can lead to reliance on reverse dns resolution. The attack may be performed from remote. The exploit has been publicly…
AplazadaMedia (5.5)0.25%—Ericc-ch Copilot-apiAI20/4/202617/6/2026
A vulnerability was found in ericc-ch copilot-api up to 0.7.0. The impacted element is the function cors of the file src/server.ts of the component Token Endpoint. Performing a manipulation results in permissive cross-domain policy with untrusted domains. It is possible to initiate the attack remotely. The exploit has…
AnalizadaMedia (6.5)0.74%—Microsoft Github Copilot Chat14/4/202617/6/2026
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an authorized attacker to disclose information over a network.
ModificadaCrítica (9.9)0.72%—Microsoft 365 Copilot Chat19/3/202617/6/2026
Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (7.5)0.92%—Microsoft Copilot19/3/202617/6/2026
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.