Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

619 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (9.3)23%—Microsoft ExcelMicrosoft OfficeMicrosoft Office Compatibility PackMicrosoft Office Excel Viewer+210/3/201016/6/2026
Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2 and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted spreadsheet in which "a MDXSET record is broken up into several records," aka "Microsoft…
ModificadaAlta (9.3)23%—Microsoft ExcelMicrosoft OfficeMicrosoft Office Compatibility PackMicrosoft Office Excel Viewer+210/3/201016/6/2026
Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted spreadsheet in which "a MDXTUPLE record is broken up into…
ModificadaAlta (7.8)61%—Microsoft ExcelMicrosoft OfficeMicrosoft Office Compatibility PackMicrosoft Office Excel Viewer+210/3/201016/6/2026
Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 do not properly parse the Excel file format, which allows…
ModificadaAlta (9.3)19%—Microsoft ExcelMicrosoft OfficeMicrosoft Office Compatibility PackMicrosoft Office Excel Viewer+210/3/201016/6/2026
Microsoft Office Excel 2002 SP3 does not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Microsoft Office Excel Record Memory Corruption Vulnerability."
ModificadaBaja (3.5)8.5%—Microsoft Sharepoint Server26/2/201016/6/2026
_layouts/Upload.aspx in the Documents module in Microsoft SharePoint before 2010 uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (aka attachments), which allows remote authenticated users to leverage same-origin relationships and conduct cross-site…
ModificadaMedia (5)33%💥 ExploitMicrosoft Sharepoint Server30/10/200916/6/2026
The download functionality in Team Services in Microsoft Office SharePoint Server 2007 12.0.0.4518 and 12.0.0.6219 allows remote attackers to read ASP.NET source code via pathnames in the SourceUrl and Source parameters to _layouts/download.aspx.
ModificadaAlta (9.3)36%—Microsoft OfficeMicrosoft Office Compatibility Pack FOR Word Excel PPT 2007Microsoft Office ExcelMicrosoft Office Excel Viewer+210/6/200916/6/2026
Excel in 2007 Microsoft Office System SP1 and SP2; Microsoft Office Excel Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a BIFF file with a malformed Qsir (0x806) record object, aka "Record Pointer…
ModificadaAlta (9.3)37%—Microsoft OfficeMicrosoft Office Compatibility Pack FOR Word Excel PPT 2007Microsoft Office ExcelMicrosoft Office Excel Viewer+210/6/200916/6/2026
Integer overflow in Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel Viewer; Microsoft Office Compatibility Pack…
ModificadaAlta (9.3)28%—Microsoft OfficeMicrosoft Office Compatibility Pack FOR Word Excel PPT 2007Microsoft Office ExcelMicrosoft Office Excel Viewer+210/6/200916/6/2026
Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel Viewer; and Microsoft Office Compatibility Pack for Word,…
ModificadaAlta (9.3)29%—Microsoft OfficeMicrosoft Office Compatibility Pack FOR Word Excel PPT 2007Microsoft Office ExcelMicrosoft Office Excel Viewer+210/6/200916/6/2026
Stack-based buffer overflow in Excel in Microsoft Office 2000 SP3 and Office XP SP3 allows remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "String Copy Stack-Based Overrun Vulnerability."
ModificadaAlta (9.3)31%—Microsoft OfficeMicrosoft Office Compatibility Pack FOR Word Excel PPT 2007Microsoft Office ExcelMicrosoft Office Excel Viewer+210/6/200916/6/2026
Array index error in Excel in Microsoft Office 2000 SP3 and Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac, allows remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Array Indexing Memory Corruption Vulnerability."
AnalizadaAlta (7.8)53%⚠ Explotación activaMicrosoft OfficeMicrosoft Office Compatibility PackMicrosoft Office Excel ViewerMicrosoft Office Sharepoint Server+110/6/200916/6/2026
Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel Viewer; and Microsoft Office Compatibility Pack for Word,…
ModificadaAlta (9.3)28%—Microsoft OfficeMicrosoft Office Compatibility Pack FOR Word Excel PPT 2007Microsoft Office ExcelMicrosoft Office Excel Viewer+210/6/200916/6/2026
Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; and Microsoft Office Excel Viewer 2003 SP3 allow remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Record Pointer…
ModificadaAlta (7.5)48%—Microsoft Office Sharepoint ServerMicrosoft Search Server10/12/200816/6/2026
Microsoft Office SharePoint Server 2007 Gold and SP1 and Microsoft Search Server 2008 do not properly perform authentication and authorization for administrative functions, which allows remote attackers to cause a denial of service (server load), obtain sensitive information, and "create scripts that would run in the…
ModificadaBaja (3.5)9.4%—Microsoft Sharepoint Server10/11/200816/6/2026
Microsoft SharePoint uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (aka attachments), which allows remote authenticated users to leverage same-origin relationships and conduct cross-site scripting (XSS) attacks by uploading HTML documents.
ModificadaAlta (9.3)34%—Microsoft ExcelMicrosoft Excel ViewerMicrosoft OfficeMicrosoft Office Compatibility Pack+215/10/200816/6/2026
Integer overflow in the REPT function in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1; Office Excel Viewer 2003 SP3; Office Excel Viewer; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; Office SharePoint Server 2007 Gold and SP1; Office 2004 and…
ModificadaAlta (9.3)36%—Microsoft OfficeMicrosoft Office Compatibility PackMicrosoft Office Excel ViewerMicrosoft Sharepoint Server12/8/200816/6/2026
Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1; Office Excel Viewer 2003 Gold and SP3; Office Excel Viewer; Office Compatibility Pack 2007 Gold and SP1; Office SharePoint Server 2007 Gold and SP1; and Office 2004 and 2008 for Mac do not properly parse Country record values when…
ModificadaMedia (4.3)8.0%💥 ExploitMicrosoft Sharepoint Server18/4/200816/6/2026
Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 2.0 allows remote attackers to inject arbitrary web script or HTML via the Picture Source (aka picture object source) field in the Rich Text Editor.
ModificadaMedia (4.3)36%💥 ExploitMicrosoft Sharepoint ServerMicrosoft Sharepoint ServicesMicrosoft Windows 20039/5/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Microsoft Windows SharePoint Services 3.0 for Windows Server 2003 and Office SharePoint Server 2007 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (query string) in "every main page," as demonstrated by default.aspx.