Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
103 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.65% | — | Microsoft 365 Copilot | 19/3/2026 | 17/6/2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. | |
| Modificada | Alta (7.1) | 0.54% | — | Microsoft 365 CopilotMicrosoft EdgeMicrosoft ExcelMicrosoft Loop+6 | 16/3/2026 | 17/6/2026 | AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (7.8) | 0.33% | — | Microsoft 365 Copilot | 10/3/2026 | 17/6/2026 | Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.34% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 10/3/2026 | 17/6/2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (5.5) | 0.66% | — | Microsoft 365 CopilotMicrosoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+11 | 10/3/2026 | 17/6/2026 | Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (7) | 0.46% | — | Microsoft 365 CopilotMicrosoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+10 | 10/3/2026 | 17/6/2026 | Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.5) | 0.51% | — | Github Copilot Command Line Interface | 6/3/2026 | 17/6/2026 | The shell tool within GitHub Copilot CLI versions prior to and including 0.0.422 can allow arbitrary code execution through crafted bash parameter expansion patterns. An attacker who can influence the commands executed by the agent (e.g., via prompt injection through repository files, MCP server responses, or user… | |
| Analizada | Alta (7.8) | 0.84% | — | Microsoft Github Copilot | 10/2/2026 | 17/6/2026 | Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.5) | 0.92% | — | Microsoft 365 Copilot | 22/1/2026 | 17/6/2026 | Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (7.4) | 0.60% | — | Microsoft 365 Word Copilot | 22/1/2026 | 17/6/2026 | Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (7.5) | 1.5% | — | Microsoft Copilot Studio | 22/1/2026 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through network attack vector | |
| Aplazada | Media (5.3) | 0.21% | — | Quadlayers Ai-copilotAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in quadlayers AI Copilot ai-copilot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Copilot: from n/a through <= 1.5.2. | |
| Aplazada | Media (5) | 0.21% | — | Wpmessiah WP AI CopilotAI | 18/12/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in WP Messiah WP AI CoPilot ai-co-pilot-for-wp allows Retrieve Embedded Sensitive Data.This issue affects WP AI CoPilot: from n/a through <= 1.2.7. | |
| Analizada | Alta (7.8) | 0.36% | — | Microsoft Github Copilot | 9/12/2025 | 17/6/2026 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.43% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 9/12/2025 | 17/6/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.43% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 9/12/2025 | 30/9/2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Aplazada | Media (4.3) | 0.26% | — | Wpmessiah WP AI CopilotAI | 9/12/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in WP Messiah WP AI CoPilot ai-co-pilot-for-wp allows Retrieve Embedded Sensitive Data.This issue affects WP AI CoPilot: from n/a through <= 1.2.7. | |
| Analizada | Media (6.8) | 0.47% | — | Microsoft Github Copilot Chat | 11/11/2025 | 17/6/2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code CoPilot Chat Extension allows an authorized attacker to bypass a security feature locally. | |
| Analizada | Alta (8.8) | 0.75% | — | Microsoft Github Copilot Chat | 11/11/2025 | 17/6/2026 | Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to execute code over a network. | |
| Modificada | Alta (7.8) | 0.76% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft ExcelMicrosoft Office Long Term Servicing Channel | 11/11/2025 | 17/6/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Crítica (9.8) | 5.9% | — | Microsoft 365 CopilotMicrosoft Office Long Term Servicing ChannelMicrosoft Windows 10 1607Microsoft Windows 10 1809+12 | 11/11/2025 | 17/6/2026 | Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.8) | 0.60% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 14/10/2025 | 17/6/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.52% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 14/10/2025 | 17/6/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Modificada | Crítica (9.3) | 0.57% | — | Microsoft 365 Copilot Chat | 9/10/2025 | 17/6/2026 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network. | |
| Modificada | Crítica (9.3) | 0.57% | — | Microsoft 365 Copilot Chat | 9/10/2025 | 17/6/2026 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information disclosure locally. |