Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
621 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7) | 0.37% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2016+3 | 8/9/2026 | 17/9/2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2016+3 | 8/9/2026 | 17/9/2026 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (5.5) | 0.55% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2016+3 | 8/9/2026 | 17/9/2026 | Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2016+3 | 8/9/2026 | 17/9/2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (8.8) | 0.86% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2016+3 | 8/9/2026 | 17/9/2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. | |
| Aplazada | Media (4.8) | 0.28% | — | WgerAIMicrosoft ExcelAILibreoffice CalcAI | 6/9/2026 | 8/9/2026 | wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas. Attackers can inject formulas like =HYPERLINK to exfiltrate admin data or execute code when admins open the exported file in Excel or LibreOffice Calc. | |
| Aplazada | Crítica (9.3) | 0.69% | — | Excel-mcp-serverAI | 4/9/2026 | 23/9/2026 | excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any file accessible to the process. | |
| Aplazada | Alta (7.5) | 0.84% | — | Maatwebsite Laravel ExcelAI | 1/9/2026 | 9/9/2026 | Laravel Excel provides supercharged Excel exports and imports in Laravel. From 3.1.8 until 3.1.70, in src/Files/Disk.php the Maatwebsite\Excel\Files\Disk::copy() method resolves the caller-controlled $destination supplied through Excel::store(), $export->store(), or storeExcel() against the process working directory… | |
| Aplazada | Alta (8.4) | 0.41% | — | ExceljsAI | 24/8/2026 | 31/8/2026 | exceljs through 4.4.0 fails to neutralize leading equals, plus, minus, or at signs in cell values written to CSV output. Attackers who can influence exported cell values can inject formulas that execute when the CSV file is opened in a spreadsheet application, potentially exfiltrating data or performing other… | |
| Aplazada | Alta (8.7) | 0.51% | — | ExceljsAI | 24/8/2026 | 31/8/2026 | exceljs through 4.4.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate file paths. Attackers can supply arbitrary file paths to read any file accessible to the Node.js process and embed it in the generated workbook. | |
| Aplazada | Crítica (9.3) | 0.60% | — | ExceljsAI | 24/8/2026 | 31/8/2026 | exceljs through 4.4.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or prototype keys when merging note objects. Attackers can assign parsed JSON with a malicious __proto__ property to cell notes, modifying Object.prototype and affecting all plain… | |
| Aplazada | Alta (8.7) | 0.63% | — | ExceljsAI | 24/8/2026 | 31/8/2026 | exceljs through 4.4.0 decompresses all entries from supplied xlsx archives into memory without limits on entry size, total size, or compression ratio. Attackers can upload highly compressed workbooks that expand to gigabytes in memory, exhausting available resources and causing denial of service. | |
| Pendiente de análisis | Media (6.1) | 0.36% | — | Microsoft ExcelAIVelociraptorAI | 12/8/2026 | 28/8/2026 | When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CSV files arbitrary execution. Velociraptor fails to sanitize such cells when exporting to CSV from various places such as the GUI, offline collector or data exports. It is not clear if the… | |
| Analizada | Media (6.5) | 0.92% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+2 | 11/8/2026 | 13/8/2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (6.5) | 0.92% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+2 | 11/8/2026 | 13/8/2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+2 | 11/8/2026 | 13/8/2026 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+2 | 11/8/2026 | 13/8/2026 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+2 | 11/8/2026 | 13/8/2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+2 | 11/8/2026 | 13/8/2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+2 | 11/8/2026 | 13/8/2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+2 | 11/8/2026 | 13/8/2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+2 | 11/8/2026 | 13/8/2026 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (5.5) | 0.54% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+2 | 11/8/2026 | 13/8/2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+2 | 11/8/2026 | 13/8/2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+2 | 11/8/2026 | 13/8/2026 | Out-of-bounds write in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |