Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

103 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.65%—Microsoft 365 Copilot19/3/202617/6/2026
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.
ModificadaAlta (7.1)0.54%—Microsoft 365 CopilotMicrosoft EdgeMicrosoft ExcelMicrosoft Loop+616/3/202617/6/2026
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (7.8)0.33%—Microsoft 365 Copilot10/3/202617/6/2026
Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.34%—Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel10/3/202617/6/2026
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
AnalizadaMedia (5.5)0.66%—Microsoft 365 CopilotMicrosoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+1110/3/202617/6/2026
Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally.
AnalizadaAlta (7)0.46%—Microsoft 365 CopilotMicrosoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+1010/3/202617/6/2026
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.5)0.51%—Github Copilot Command Line Interface6/3/202617/6/2026
The shell tool within GitHub Copilot CLI versions prior to and including 0.0.422 can allow arbitrary code execution through crafted bash parameter expansion patterns. An attacker who can influence the commands executed by the agent (e.g., via prompt injection through repository files, MCP server responses, or user…
AnalizadaAlta (7.8)0.84%—Microsoft Github Copilot10/2/202617/6/2026
Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (7.5)0.92%—Microsoft 365 Copilot22/1/202617/6/2026
Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (7.4)0.60%—Microsoft 365 Word Copilot22/1/202617/6/2026
Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (7.5)1.5%—Microsoft Copilot Studio22/1/202617/6/2026
Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through network attack vector
AplazadaMedia (5.3)0.21%—Quadlayers Ai-copilotAI31/12/202523/9/2026
Missing Authorization vulnerability in quadlayers AI Copilot ai-copilot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Copilot: from n/a through <= 1.5.2.
AplazadaMedia (5)0.21%—Wpmessiah WP AI CopilotAI18/12/202517/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in WP Messiah WP AI CoPilot ai-co-pilot-for-wp allows Retrieve Embedded Sensitive Data.This issue affects WP AI CoPilot: from n/a through <= 1.2.7.
AnalizadaAlta (7.8)0.36%—Microsoft Github Copilot9/12/202517/6/2026
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.43%—Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel9/12/202517/6/2026
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.43%—Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel9/12/202530/9/2026
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
AplazadaMedia (4.3)0.26%—Wpmessiah WP AI CopilotAI9/12/202517/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in WP Messiah WP AI CoPilot ai-co-pilot-for-wp allows Retrieve Embedded Sensitive Data.This issue affects WP AI CoPilot: from n/a through <= 1.2.7.
AnalizadaMedia (6.8)0.47%—Microsoft Github Copilot Chat11/11/202517/6/2026
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code CoPilot Chat Extension allows an authorized attacker to bypass a security feature locally.
AnalizadaAlta (8.8)0.75%—Microsoft Github Copilot Chat11/11/202517/6/2026
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to execute code over a network.
ModificadaAlta (7.8)0.76%—Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft ExcelMicrosoft Office Long Term Servicing Channel11/11/202517/6/2026
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
AnalizadaCrítica (9.8)5.9%—Microsoft 365 CopilotMicrosoft Office Long Term Servicing ChannelMicrosoft Windows 10 1607Microsoft Windows 10 1809+1211/11/202517/6/2026
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (7.8)0.60%—Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel14/10/202517/6/2026
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.52%—Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel14/10/202517/6/2026
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
ModificadaCrítica (9.3)0.57%—Microsoft 365 Copilot Chat9/10/202517/6/2026
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.
ModificadaCrítica (9.3)0.57%—Microsoft 365 Copilot Chat9/10/202517/6/2026
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information disclosure locally.