Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

621 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7)0.37%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2016+38/9/202617/9/2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2016+38/9/202617/9/2026
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaMedia (5.5)0.55%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2016+38/9/202617/9/2026
Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2016+38/9/202617/9/2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (8.8)0.86%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2016+38/9/202617/9/2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.
AplazadaMedia (4.8)0.28%—WgerAIMicrosoft ExcelAILibreoffice CalcAI6/9/20268/9/2026
wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas. Attackers can inject formulas like =HYPERLINK to exfiltrate admin data or execute code when admins open the exported file in Excel or LibreOffice Calc.
AplazadaCrítica (9.3)0.69%—Excel-mcp-serverAI4/9/202623/9/2026
excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any file accessible to the process.
AplazadaAlta (7.5)0.84%—Maatwebsite Laravel ExcelAI1/9/20269/9/2026
Laravel Excel provides supercharged Excel exports and imports in Laravel. From 3.1.8 until 3.1.70, in src/Files/Disk.php the Maatwebsite\Excel\Files\Disk::copy() method resolves the caller-controlled $destination supplied through Excel::store(), $export->store(), or storeExcel() against the process working directory…
AplazadaAlta (8.4)0.41%—ExceljsAI24/8/202631/8/2026
exceljs through 4.4.0 fails to neutralize leading equals, plus, minus, or at signs in cell values written to CSV output. Attackers who can influence exported cell values can inject formulas that execute when the CSV file is opened in a spreadsheet application, potentially exfiltrating data or performing other…
AplazadaAlta (8.7)0.51%—ExceljsAI24/8/202631/8/2026
exceljs through 4.4.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate file paths. Attackers can supply arbitrary file paths to read any file accessible to the Node.js process and embed it in the generated workbook.
AplazadaCrítica (9.3)0.60%—ExceljsAI24/8/202631/8/2026
exceljs through 4.4.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or prototype keys when merging note objects. Attackers can assign parsed JSON with a malicious __proto__ property to cell notes, modifying Object.prototype and affecting all plain…
AplazadaAlta (8.7)0.63%—ExceljsAI24/8/202631/8/2026
exceljs through 4.4.0 decompresses all entries from supplied xlsx archives into memory without limits on entry size, total size, or compression ratio. Attackers can upload highly compressed workbooks that expand to gigabytes in memory, exhausting available resources and causing denial of service.
Pendiente de análisisMedia (6.1)0.36%—Microsoft ExcelAIVelociraptorAI12/8/202628/8/2026
When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CSV files arbitrary execution. Velociraptor fails to sanitize such cells when exporting to CSV from various places such as the GUI, offline collector or data exports. It is not clear if the…
AnalizadaMedia (6.5)0.92%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+211/8/202613/8/2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
AnalizadaMedia (6.5)0.92%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+211/8/202613/8/2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+211/8/202613/8/2026
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+211/8/202613/8/2026
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+211/8/202613/8/2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+211/8/202613/8/2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+211/8/202613/8/2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+211/8/202613/8/2026
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+211/8/202613/8/2026
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaMedia (5.5)0.54%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+211/8/202613/8/2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+211/8/202613/8/2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+211/8/202613/8/2026
Out-of-bounds write in Microsoft Office Excel allows an unauthorized attacker to execute code locally.