Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
203 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.1) | 0.74% | — | Microsoft Outlook | 18/12/2024 | 17/6/2026 | A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and then make use of the vulnerable… | |
| Analizada | Media (5.3) | 0.26% | — | Hcltech Traveler FOR Microsoft Outlook | 12/11/2024 | 17/6/2026 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a control flow vulnerability. The application does not sufficiently manage its control flow during execution, creating conditions in which the control flow can be modified in unexpected ways. | |
| Analizada | Alta (8) | 1.2% | — | Microsoft Outlook | 8/10/2024 | 17/6/2026 | Outlook for Android Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.5) | 0.21% | — | Hcltech Traveler FOR Microsoft Outlook | 26/9/2024 | 17/6/2026 | The HCL Traveler for Microsoft Outlook executable (HTMO.exe) is being flagged as potentially Malicious Software or an Unrecognized Application. | |
| Analizada | Media (6.5) | 1.1% | — | Microsoft Outlook | 10/9/2024 | 10/8/2026 | Microsoft Outlook for iOS Information Disclosure Vulnerability | |
| Analizada | Media (6.7) | 0.66% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Outlook | 13/8/2024 | 17/6/2026 | Microsoft Outlook Remote Code Execution Vulnerability | |
| Modificada | Media (6.5) | 1.8% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Outlook | 9/7/2024 | 17/6/2026 | Microsoft Outlook Spoofing Vulnerability | |
| Modificada | Alta (8.8) | 3.4% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Outlook | 11/6/2024 | 20/7/2026 | Microsoft Outlook Remote Code Execution Vulnerability | |
| Aplazada | Baja (2.8) | 0.18% | — | Knowbe4 Phish Alert Button FOR OutlookAIKnowbe4 Second Chance ClientAIKnowbe4 PIQ ClientAI | 7/5/2024 | 17/6/2026 | A local privilege escalation (LPE) vulnerability has been identified in Phish Alert Button for Outlook (PAB), specifically within its configuration management functionalities. This vulnerability allows a regular user to modify the application's configuration file to redirect update checks to an arbitrary server, which… | |
| Analizada | Alta (8.1) | 2.3% | — | Microsoft Outlook | 9/4/2024 | 17/6/2026 | Outlook for Windows Spoofing Vulnerability | |
| Analizada | Alta (7.5) | 2.1% | — | Microsoft Outlook | 12/3/2024 | 17/6/2026 | Outlook for Android Information Disclosure Vulnerability | |
| Modificada | Alta (8.8) | 11% | 💥 PoC | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Outlook | 13/2/2024 | 10/8/2026 | Microsoft Outlook Remote Code Execution Vulnerability | |
| Modificada | Media (5.5) | 0.33% | — | Munsoft Easy Outlook Express Recovery | 2/2/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Munsoft Easy Outlook Express Recovery 2.0. This issue affects some unknown processing of the component Registration Key Handler. The manipulation leads to denial of service. Local access is required to approach this attack. The exploit has been… | |
| Modificada | Alta (7.5) | 2.1% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Outlook | 12/9/2023 | 17/6/2026 | Microsoft Outlook Information Disclosure Vulnerability | |
| Modificada | Media (6.1) | 0.34% | — | Wpo365 Mail Integration FOR Office 365 / Outlook | 23/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPO365 | Mail Integration for Office 365 / Outlook plugin <= 1.9.0 versions. | |
| Modificada | Media (6.5) | 2.2% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Outlook | 8/8/2023 | 10/8/2026 | Microsoft Outlook Spoofing Vulnerability | |
| Analizada | Alta (7.5) | 16% | ⚠ Explotación activa | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Outlook | 11/7/2023 | 17/6/2026 | Microsoft Outlook Security Feature Bypass Vulnerability | |
| Modificada | Alta (8.8) | 5.7% | 💥 Exploit | Microsoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft OutlookMicrosoft Outlook RT | 14/6/2023 | 17/6/2026 | Microsoft Outlook Remote Code Execution Vulnerability | |
| Modificada | Alta (7.5) | 22% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Outlook | 1/6/2023 | 17/6/2026 | Microsoft Outlook Denial of Service Vulnerability | |
| Analizada | Crítica (9.8) | 97% | ⚠ Explotación activa💥 PoC | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Outlook | 14/3/2023 | 17/6/2026 | Microsoft Outlook Elevation of Privilege Vulnerability | |
| Modificada | Media (6.3) | 0.55% | — | Microsoft Outlook | 13/12/2022 | 17/6/2026 | Outlook for Android Elevation of Privilege Vulnerability | |
| Modificada | Media (6.1) | 0.58% | — | Fortinet Fortiauthenticator Agent FOR Microsoft Outlook WEB Access | 18/7/2022 | 17/6/2026 | An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAuthenticator OWA Agent for Microsoft version 2.2 and 2.1 may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests. | |
| Modificada | Alta (7.1) | 0.38% | — | Zoom MeetingsZoom Rooms FOR Conference RoomsZoom VDI Windows Meeting ClientsZoom Plugin FOR Microsoft Outlook | 28/4/2022 | 17/6/2026 | The Zoom Client for Meetings for Windows prior to version 5.9.7, Zoom Rooms for Conference Room for Windows prior to version 5.10.0, Zoom Plugins for Microsoft Outlook for Windows prior to version 5.10.3, and Zoom VDI Windows Meeting Clients prior to version 5.9.6; was susceptible to a local privilege escalation issue… | |
| Modificada | Media (5.3) | 2.4% | — | Microsoft Outlook 2016 | 9/2/2022 | 17/6/2026 | Microsoft Outlook for Mac Security Feature Bypass Vulnerability | |
| Modificada | Alta (7.5) | 0.58% | — | Zoom Plugin FOR Microsoft Outlook | 27/9/2021 | 17/6/2026 | All versions of the Zoom Plugin for Microsoft Outlook for MacOS before 5.3.52553.0918 contain a Time-of-check Time-of-use (TOC/TOU) vulnerability during the plugin installation process. This could allow a standard user to write their own malicious application to the plugin directory, allowing the malicious application… |