Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
103 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.4) | 0.36% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft 365Microsoft Office 2016+3 | 9/6/2026 | 23/7/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Modificada | Alta (8.4) | 0.36% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft 365Microsoft Office 2016+3 | 9/6/2026 | 23/7/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Modificada | Alta (8.4) | 0.36% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft 365Microsoft Office 2016+3 | 9/6/2026 | 23/7/2026 | Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Modificada | Alta (8.4) | 0.36% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft 365Microsoft Office 2016+3 | 9/6/2026 | 23/7/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Modificada | Media (4.7) | 0.42% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft 365Microsoft Office 2019+2 | 9/6/2026 | 23/7/2026 | Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (7.5) | 0.92% | — | Microsoft Copilot Chat | 4/6/2026 | 23/7/2026 | Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (8.8) | 0.61% | — | Microsoft Copilot | 4/6/2026 | 23/7/2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute code over a network. | |
| Modificada | Alta (7.5) | 0.92% | — | Microsoft Copilot | 4/6/2026 | 23/7/2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (7.5) | 0.92% | — | Microsoft 365 Copilot | 22/5/2026 | 23/7/2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Crítica (9.3) | 0.76% | — | Microsoft 365 Copilot | 22/5/2026 | 23/7/2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network. | |
| Analizada | Alta (8.5) | 0.38% | — | Github Copilot-cli | 13/5/2026 | 17/6/2026 | GitHub Copilot CLI brings AI-powered coding assistance directly to your command line. Prior to 1.0.43, a security vulnerability has been identified in GitHub Copilot CLI where a malicious bare git repository nested inside a project directory can achieve arbitrary code execution when the agent performs git operations.… | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 12/5/2026 | 17/6/2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (6.2) | 0.40% | — | Microsoft 365 Copilot | 12/5/2026 | 17/6/2026 | Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally. | |
| Analizada | Media (4.4) | 0.26% | — | Microsoft 365 Copilot | 12/5/2026 | 17/6/2026 | Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally. | |
| Analizada | Alta (8.4) | 0.36% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 12/5/2026 | 17/6/2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Aplazada | Crítica (10) | 0.78% | — | Microsoft CopilotAI | 11/5/2026 | 17/6/2026 | SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57, SOCFortress CoPilot ships a hardcoded JWT signing secret as a fallback value in backend/app/auth/utils.py:28 and ships it verbatim in .env.example. Any deployment where JWT_SECRET is not explicitly… | |
| Analizada | Alta (7.5) | 1.0% | — | Microsoft Copilot Chat | 7/5/2026 | 17/6/2026 | Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network. | |
| Modificada | Alta (7.5) | 1.0% | — | Microsoft 365 Copilot Chat | 7/5/2026 | 17/6/2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. | |
| Modificada | Alta (7.5) | 1.0% | — | Microsoft 365 Copilot Chat | 7/5/2026 | 17/6/2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Crítica (9.3) | 0.72% | — | Microsoft 365 Copilot | 23/4/2026 | 17/6/2026 | Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Baja (2.1) | 0.34% | — | Ericc-ch Copilot-apiAI | 23/4/2026 | 17/6/2026 | A vulnerability was determined in ericc-ch copilot-api up to 0.7.0. This impacts an unknown function of the file /token of the component Header Handler. Executing a manipulation of the argument Host can lead to reliance on reverse dns resolution. The attack may be performed from remote. The exploit has been publicly… | |
| Aplazada | Media (5.5) | 0.25% | — | Ericc-ch Copilot-apiAI | 20/4/2026 | 17/6/2026 | A vulnerability was found in ericc-ch copilot-api up to 0.7.0. The impacted element is the function cors of the file src/server.ts of the component Token Endpoint. Performing a manipulation results in permissive cross-domain policy with untrusted domains. It is possible to initiate the attack remotely. The exploit has… | |
| Analizada | Media (6.5) | 0.74% | — | Microsoft Github Copilot Chat | 14/4/2026 | 17/6/2026 | Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an authorized attacker to disclose information over a network. | |
| Modificada | Crítica (9.9) | 0.72% | — | Microsoft 365 Copilot Chat | 19/3/2026 | 17/6/2026 | Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.5) | 0.92% | — | Microsoft Copilot | 19/3/2026 | 17/6/2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network. |