Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2674▼ 561 respecto a la semana anterior
Críticas / altas1270▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)217▼ 222 respecto a la semana anterior
2573 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.52% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 14/10/2025 | 17/6/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.38% | — | Microsoft 365 AppsMicrosoft Office Long Term Servicing Channel | 14/10/2025 | 17/6/2026 | Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.38% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 14/10/2025 | 17/6/2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.38% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 14/10/2025 | 17/6/2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.38% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 14/10/2025 | 17/6/2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+1 | 14/10/2025 | 17/6/2026 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7) | 0.39% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+1 | 14/10/2025 | 17/6/2026 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | |
| Aplazada | Baja (2.1) | 0.42% | — | JSC R7 Office Document ServerAI | 22/9/2025 | 17/6/2026 | A flaw has been found in JSC R7 R7-Office Document Server up to 20250820. Impacted is an unknown function of the file /downloadas/. Executing manipulation of the argument cmd can lead to path traversal. The attack can be launched remotely. Upgrading to version 2025.3.1.923 is recommended to address this issue. The… | |
| Aplazada | Baja (1.9) | 0.14% | — | Ooma Office Business Phone APPAI | 19/9/2025 | 30/9/2026 | Una vulnerabilidad fue encontrada en la aplicación Ooma Office Business Phone hasta la versión 7.2.2 en Android. Esto afecta una parte desconocida del componente com.ooma.office2. La manipulación resulta en una exportación indebida de componentes de aplicaciones de Android. El ataque necesita ser abordado localmente.… | |
| Aplazada | Baja (2) | 0.33% | — | OnlyofficeAI | 11/9/2025 | 17/6/2026 | A vulnerability was determined in Ascensio System SIA OnlyOffice up to 12.7.0. Impacted is an unknown function of the file /Products/Projects/Messages.aspx of the component Comment Handler. Executing manipulation can lead to cross site scripting. The attack may be launched remotely. The exploit has been publicly… | |
| Aplazada | Baja (2) | 0.27% | — | OnlyofficeAI | 11/9/2025 | 17/6/2026 | A vulnerability was found in Ascensio System SIA OnlyOffice up to 12.7.0. This issue affects some unknown processing of the file /Products/Projects/Messages.aspx of the component SVG Image Handler. Performing manipulation results in cross site scripting. The attack may be initiated remotely. The exploit has been made… | |
| Analizada | Alta (7.5) | 1.1% | — | Microsoft Officeplus | 9/9/2025 | 17/6/2026 | Exposure of sensitive information to an unauthorized actor in Microsoft Office Plus allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Alta (8.4) | 0.55% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 9/9/2025 | 17/6/2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.60% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Powerpoint | 9/9/2025 | 17/6/2026 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.51% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 9/9/2025 | 17/6/2026 | Heap-based buffer overflow in Microsoft Office Visio allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.71% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server | 9/9/2025 | 17/6/2026 | Free of memory not on the heap in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.1) | 0.63% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Enterprise Server+2 | 9/9/2025 | 17/6/2026 | Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (7.8) | 0.58% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 9/9/2025 | 17/6/2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.58% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 9/9/2025 | 17/6/2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.58% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 9/9/2025 | 17/6/2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (5.5) | 0.65% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 9/9/2025 | 17/6/2026 | Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (7.8) | 0.58% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 9/9/2025 | 17/6/2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.58% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 9/9/2025 | 17/6/2026 | Free of memory not on the heap in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.58% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 9/9/2025 | 17/6/2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.58% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 9/9/2025 | 17/6/2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |