Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2758▼ 17 respecto a la semana anterior
Críticas / altas1269▼ 209 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 185 respecto a la semana anterior
2573 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.34% | — | Wpo365 Mail Integration FOR Office 365 / Outlook | 23/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPO365 | Mail Integration for Office 365 / Outlook plugin <= 1.9.0 versions. | |
| Modificada | Crítica (9.8) | 1.7% | — | Mitel Mivoice Office 400Mitel Mivoice Office 400 SMB Controller Firmware | 14/8/2023 | 17/6/2026 | A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to execute arbitrary commands within the context of the system. | |
| Modificada | Crítica (9.8) | 0.63% | — | Mitel Mivoice Office 400Mitel Mivoice Office 400 SMB Controller Firmware | 14/8/2023 | 17/6/2026 | A SQL Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to access sensitive information and execute arbitrary database and management operations. | |
| Modificada | Alta (7.5) | 2.2% | — | Onlyoffice Document Server | 14/8/2023 | 9/7/2026 | Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 through 7.3.2 allows remote attackers to cause a denial of service via crafted JavaScript file. | |
| Modificada | Crítica (9.8) | 2.4% | — | Onlyoffice Document Server | 14/8/2023 | 9/7/2026 | An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file. | |
| Modificada | Crítica (9.8) | 2.3% | — | Onlyoffice Document Server | 14/8/2023 | 9/7/2026 | A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file. | |
| Modificada | Media (6.5) | 1.7% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Visual Studio 2010 Tools FOR Office Runtime+3 | 8/8/2023 | 10/8/2026 | Visual Studio Tools for Office Runtime Spoofing Vulnerability | |
| Modificada | Alta (7.8) | 0.99% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online Server | 8/8/2023 | 10/8/2026 | Microsoft Excel Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 1.0% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 8/8/2023 | 10/8/2026 | Microsoft Outlook Remote Code Execution Vulnerability | |
| Modificada | Media (6.5) | 2.2% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Outlook | 8/8/2023 | 10/8/2026 | Microsoft Outlook Spoofing Vulnerability | |
| Modificada | Alta (7.8) | 0.77% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 8/8/2023 | 10/8/2026 | Microsoft Office Visio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 0.77% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 8/8/2023 | 10/8/2026 | Vulnerabilidad de ejecución remota de código de Microsoft Office Visio | |
| Modificada | Alta (7.8) | 0.99% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 8/8/2023 | 10/8/2026 | Microsoft Office Visio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 0.99% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online Server | 8/8/2023 | 10/8/2026 | Microsoft Office Remote Code Execution Vulnerability | |
| Modificada | Crítica (9.8) | 12% | 💥 PoC | Tongda2000 Tongda Office Anywhere | 5/8/2023 | 17/6/2026 | A vulnerability has been found in Tongda OA and classified as critical. This vulnerability affects unknown code of the file general/system/seal_manage/dianju/delete_log.php. The manipulation of the argument DELETE_STR leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to… | |
| Modificada | Crítica (9.8) | 12% | 💥 PoC | Tongda2000 Tongda Office Anywhere | 5/8/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Tongda OA. This affects an unknown part of the file general/system/seal_manage/iweboffice/delete_seal.php. The manipulation of the argument DELETE_STR leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to… | |
| Modificada | Baja (3.2) | 0.36% | — | Open-xchange Appsuite Office | 2/8/2023 | 17/6/2026 | In case Cacheservice was configured to use a sproxyd object-storage backend, it would follow HTTP redirects issued by that backend. An attacker with access to a local or restricted network with the capability to intercept and replay HTTP requests to sproxyd (or who is in control of the sproxyd service) could perform a… | |
| Modificada | Media (5.5) | 0.40% | — | Open-xchange Appsuite Office | 2/8/2023 | 17/6/2026 | Cacheservice did not correctly check if relative cache object were pointing to the defined absolute location when accessing resources. An attacker with access to the database and a local or restricted network would be able to read arbitrary local file system resources that are accessible by the services system user… | |
| Modificada | Alta (7.8) | 0.41% | — | Open-xchange Appsuite Office | 2/8/2023 | 17/6/2026 | Se podía abusar de la API de Cache Service para inyectar indirectamente parámetros con sintaxis SQL que no estaban suficientemente sanitizados y que posteriormente se ejecutaban al crear nuevos grupos de caché. Los atacantes con acceso a una red local o restringida podían realizar consultas SQL arbitrarias. Se ha… | |
| Modificada | Alta (7.8) | 0.43% | — | Open-xchange Appsuite Office | 2/8/2023 | 17/6/2026 | Se podía abusar de la API de Cache Service para inyectar parámetros con sintaxis SQL que no estaba suficientemente sanitizada antes de ejecutarse como sentencia SQL. Los atacantes con acceso a una red local o restringida podían realizar consultas SQL arbitrarias, descubriendo los datos almacenados en caché de otros… | |
| Modificada | Crítica (9.8) | 0.78% | — | Weaver E-office | 25/7/2023 | 17/6/2026 | An arbitrary file upload vulnerability in eoffice before v9.5 allows attackers to execute arbitrary code via uploading a crafted file. | |
| Modificada | Media (6.1) | 0.53% | — | Mobisystems Office Suite | 20/7/2023 | 17/6/2026 | Office Suite Premium Version v10.9.1.42602 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the filter parameter at /api?path=files. | |
| Modificada | Alta (7.5) | 1.2% | — | Mobisystems Office Suite | 20/7/2023 | 17/6/2026 | Office Suite Premium v10.9.1.42602 was discovered to contain a local file inclusion (LFI) vulnerability via the component /etc/hosts. | |
| Modificada | Media (6.1) | 0.53% | — | Mobisystems Office Suite | 20/7/2023 | 17/6/2026 | Office Suite Premium Version v10.9.1.42602 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the id parameter at /api?path=profile. | |
| Modificada | Media (5.5) | 0.76% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online Server | 11/7/2023 | 17/6/2026 | Microsoft Excel Information Disclosure Vulnerability |