Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
84 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 14% | — | Microsoft ExcelMicrosoft Office 365 Proplus | 10/10/2019 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1331. | |
| Analizada | Alta (8.8) | 22% | ⚠ Explotación activa | Microsoft ExcelMicrosoft OfficeMicrosoft Office 365 Proplus | 11/9/2019 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. | |
| Modificada | Alta (7.8) | 3.8% | — | Microsoft OfficeMicrosoft Office 365 ProplusMicrosoft Project | 11/9/2019 | 17/6/2026 | A security feature bypass vulnerability exists when Microsoft Office improperly handles input, aka 'Microsoft Office Security Feature Bypass Vulnerability'. | |
| Modificada | Media (5.5) | 7.8% | — | Microsoft ExcelMicrosoft OfficeMicrosoft Office 365 Proplus | 11/9/2019 | 17/6/2026 | An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information Disclosure Vulnerability'. | |
| Modificada | Alta (7.8) | 13% | — | Microsoft OfficeMicrosoft Office 365 ProplusMicrosoft Windows 10Microsoft Windows 7+6 | 11/9/2019 | 17/6/2026 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1240, CVE-2019-1241, CVE-2019-1242, CVE-2019-1243, CVE-2019-1247, CVE-2019-1248, CVE-2019-1249,… | |
| Modificada | Crítica (9.8) | 4.0% | — | Microsoft OfficeMicrosoft Office 365 ProplusMicrosoft Office Online ServerMicrosoft Sharepoint Server | 14/8/2019 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. The file could then take actions on… | |
| Modificada | Media (4.3) | 4.4% | — | Microsoft OfficeMicrosoft Office 365 ProplusMicrosoft Outlook | 14/8/2019 | 17/6/2026 | An elevation of privilege vulnerability exists when Microsoft Outlook initiates processing of incoming messages without sufficient validation of the formatting of the messages. An attacker who successfully exploited the vulnerability could attempt to force Outlook to load a local or remote message store (over SMB). To… | |
| Modificada | Alta (7.8) | 4.9% | — | Microsoft OfficeMicrosoft Office 365 ProplusMicrosoft Office Online ServerMicrosoft Office WEB Apps+4 | 14/8/2019 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. The file could then take actions on… | |
| Modificada | Alta (7.8) | 4.6% | — | Microsoft OfficeMicrosoft Office 365 ProplusMicrosoft Outlook | 14/8/2019 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then… | |
| Modificada | Alta (7.8) | 4.6% | — | Microsoft OfficeMicrosoft Office 365 Proplus | 14/8/2019 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Outlook when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an… | |
| Modificada | Alta (7.8) | 4.3% | — | Microsoft OfficeMicrosoft Office 365 ProplusMicrosoft Windows 10Microsoft Windows 7+6 | 14/8/2019 | 17/6/2026 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially… | |
| Modificada | Media (5.5) | 8.7% | — | Microsoft OfficeMicrosoft Office 365 Proplus | 15/7/2019 | 17/6/2026 | An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information Disclosure Vulnerability'. | |
| Modificada | Alta (8.8) | 13% | — | Microsoft ExcelMicrosoft OfficeMicrosoft Office 365 Proplus | 15/7/2019 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1110. | |
| Modificada | Alta (8.8) | 13% | — | Microsoft ExcelMicrosoft OfficeMicrosoft Office 365 Proplus | 15/7/2019 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1111. | |
| Modificada | Media (6.5) | 5.3% | — | Microsoft Exchange ServerMicrosoft LyncMicrosoft Lync BasicMicrosoft Mail AND Calendar+5 | 15/7/2019 | 17/6/2026 | An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security… | |
| Modificada | Alta (7.8) | 6.6% | — | Microsoft OfficeMicrosoft Office 365 ProplusMicrosoft Office Online ServerMicrosoft Sharepoint Server | 12/6/2019 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take… | |
| Modificada | Alta (7.8) | 4.9% | — | Microsoft OfficeMicrosoft Office 365 ProplusMicrosoft Office Online ServerMicrosoft Office WEB Apps+3 | 12/6/2019 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take… | |
| Modificada | Alta (7.8) | 13% | — | Microsoft OfficeMicrosoft Office 365 ProplusMicrosoft Office Online ServerMicrosoft Word | 16/5/2019 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. | |
| Modificada | Alta (7.8) | 14% | — | Microsoft OfficeMicrosoft Office 365 Proplus | 16/5/2019 | 17/6/2026 | A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0945, CVE-2019-0947. | |
| Modificada | Alta (7.8) | 14% | — | Microsoft ExcelMicrosoft Office 365 Proplus | 9/4/2019 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. | |
| Modificada | Alta (7.8) | 11% | — | Microsoft OfficeMicrosoft Office 365 Proplus | 9/4/2019 | 17/6/2026 | A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0823, CVE-2019-0824, CVE-2019-0825, CVE-2019-0826. | |
| Modificada | Alta (7.8) | 11% | — | Microsoft OfficeMicrosoft Office 365 Proplus | 9/4/2019 | 17/6/2026 | A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0823, CVE-2019-0824, CVE-2019-0825, CVE-2019-0827. | |
| Modificada | Alta (7.8) | 11% | — | Microsoft OfficeMicrosoft Office 365 Proplus | 9/4/2019 | 17/6/2026 | A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0823, CVE-2019-0824, CVE-2019-0826, CVE-2019-0827. | |
| Modificada | Alta (7.8) | 11% | — | Microsoft OfficeMicrosoft Office 365 Proplus | 9/4/2019 | 17/6/2026 | A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0823, CVE-2019-0825, CVE-2019-0826, CVE-2019-0827. | |
| Modificada | Alta (7.8) | 14% | — | Microsoft OfficeMicrosoft Office 365 Proplus | 9/4/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'. |