Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

84 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)14%—Microsoft ExcelMicrosoft Office 365 Proplus10/10/201917/6/2026
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1331.
AnalizadaAlta (8.8)22%⚠ Explotación activaMicrosoft ExcelMicrosoft OfficeMicrosoft Office 365 Proplus11/9/201917/6/2026
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.
ModificadaAlta (7.8)3.8%—Microsoft OfficeMicrosoft Office 365 ProplusMicrosoft Project11/9/201917/6/2026
A security feature bypass vulnerability exists when Microsoft Office improperly handles input, aka 'Microsoft Office Security Feature Bypass Vulnerability'.
ModificadaMedia (5.5)7.8%—Microsoft ExcelMicrosoft OfficeMicrosoft Office 365 Proplus11/9/201917/6/2026
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information Disclosure Vulnerability'.
ModificadaAlta (7.8)13%—Microsoft OfficeMicrosoft Office 365 ProplusMicrosoft Windows 10Microsoft Windows 7+611/9/201917/6/2026
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1240, CVE-2019-1241, CVE-2019-1242, CVE-2019-1243, CVE-2019-1247, CVE-2019-1248, CVE-2019-1249,…
ModificadaCrítica (9.8)4.0%—Microsoft OfficeMicrosoft Office 365 ProplusMicrosoft Office Online ServerMicrosoft Sharepoint Server14/8/201917/6/2026
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. The file could then take actions on…
ModificadaMedia (4.3)4.4%—Microsoft OfficeMicrosoft Office 365 ProplusMicrosoft Outlook14/8/201917/6/2026
An elevation of privilege vulnerability exists when Microsoft Outlook initiates processing of incoming messages without sufficient validation of the formatting of the messages. An attacker who successfully exploited the vulnerability could attempt to force Outlook to load a local or remote message store (over SMB). To…
ModificadaAlta (7.8)4.9%—Microsoft OfficeMicrosoft Office 365 ProplusMicrosoft Office Online ServerMicrosoft Office WEB Apps+414/8/201917/6/2026
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. The file could then take actions on…
ModificadaAlta (7.8)4.6%—Microsoft OfficeMicrosoft Office 365 ProplusMicrosoft Outlook14/8/201917/6/2026
A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then…
ModificadaAlta (7.8)4.6%—Microsoft OfficeMicrosoft Office 365 Proplus14/8/201917/6/2026
A remote code execution vulnerability exists in Microsoft Outlook when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an…
ModificadaAlta (7.8)4.3%—Microsoft OfficeMicrosoft Office 365 ProplusMicrosoft Windows 10Microsoft Windows 7+614/8/201917/6/2026
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially…
ModificadaMedia (5.5)8.7%—Microsoft OfficeMicrosoft Office 365 Proplus15/7/201917/6/2026
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information Disclosure Vulnerability'.
ModificadaAlta (8.8)13%—Microsoft ExcelMicrosoft OfficeMicrosoft Office 365 Proplus15/7/201917/6/2026
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1110.
ModificadaAlta (8.8)13%—Microsoft ExcelMicrosoft OfficeMicrosoft Office 365 Proplus15/7/201917/6/2026
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1111.
ModificadaMedia (6.5)5.3%—Microsoft Exchange ServerMicrosoft LyncMicrosoft Lync BasicMicrosoft Mail AND Calendar+515/7/201917/6/2026
An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security…
ModificadaAlta (7.8)6.6%—Microsoft OfficeMicrosoft Office 365 ProplusMicrosoft Office Online ServerMicrosoft Sharepoint Server12/6/201917/6/2026
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take…
ModificadaAlta (7.8)4.9%—Microsoft OfficeMicrosoft Office 365 ProplusMicrosoft Office Online ServerMicrosoft Office WEB Apps+312/6/201917/6/2026
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take…
ModificadaAlta (7.8)13%—Microsoft OfficeMicrosoft Office 365 ProplusMicrosoft Office Online ServerMicrosoft Word16/5/201917/6/2026
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'.
ModificadaAlta (7.8)14%—Microsoft OfficeMicrosoft Office 365 Proplus16/5/201917/6/2026
A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0945, CVE-2019-0947.
ModificadaAlta (7.8)14%—Microsoft ExcelMicrosoft Office 365 Proplus9/4/201917/6/2026
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.
ModificadaAlta (7.8)11%—Microsoft OfficeMicrosoft Office 365 Proplus9/4/201917/6/2026
A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0823, CVE-2019-0824, CVE-2019-0825, CVE-2019-0826.
ModificadaAlta (7.8)11%—Microsoft OfficeMicrosoft Office 365 Proplus9/4/201917/6/2026
A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0823, CVE-2019-0824, CVE-2019-0825, CVE-2019-0827.
ModificadaAlta (7.8)11%—Microsoft OfficeMicrosoft Office 365 Proplus9/4/201917/6/2026
A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0823, CVE-2019-0824, CVE-2019-0826, CVE-2019-0827.
ModificadaAlta (7.8)11%—Microsoft OfficeMicrosoft Office 365 Proplus9/4/201917/6/2026
A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0823, CVE-2019-0825, CVE-2019-0826, CVE-2019-0827.
ModificadaAlta (7.8)14%—Microsoft OfficeMicrosoft Office 365 Proplus9/4/201917/6/2026
A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'.
Orbitaley — Vulnerabilidades