Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2758▼ 17 respecto a la semana anterior
Críticas / altas1269▼ 209 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 185 respecto a la semana anterior
–

2573 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.34%—Wpo365 Mail Integration FOR Office 365 / Outlook23/8/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPO365 | Mail Integration for Office 365 / Outlook plugin <= 1.9.0 versions.
ModificadaCrítica (9.8)1.7%—Mitel Mivoice Office 400Mitel Mivoice Office 400 SMB Controller Firmware14/8/202317/6/2026
A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to execute arbitrary commands within the context of the system.
ModificadaCrítica (9.8)0.63%—Mitel Mivoice Office 400Mitel Mivoice Office 400 SMB Controller Firmware14/8/202317/6/2026
A SQL Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to access sensitive information and execute arbitrary database and management operations.
ModificadaAlta (7.5)2.2%—Onlyoffice Document Server14/8/20239/7/2026
Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 through 7.3.2 allows remote attackers to cause a denial of service via crafted JavaScript file.
ModificadaCrítica (9.8)2.4%—Onlyoffice Document Server14/8/20239/7/2026
An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.
ModificadaCrítica (9.8)2.3%—Onlyoffice Document Server14/8/20239/7/2026
A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.
ModificadaMedia (6.5)1.7%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Visual Studio 2010 Tools FOR Office Runtime+38/8/202310/8/2026
Visual Studio Tools for Office Runtime Spoofing Vulnerability
ModificadaAlta (7.8)0.99%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online Server8/8/202310/8/2026
Microsoft Excel Remote Code Execution Vulnerability
ModificadaAlta (7.8)1.0%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel8/8/202310/8/2026
Microsoft Outlook Remote Code Execution Vulnerability
ModificadaMedia (6.5)2.2%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Outlook8/8/202310/8/2026
Microsoft Outlook Spoofing Vulnerability
ModificadaAlta (7.8)0.77%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel8/8/202310/8/2026
Microsoft Office Visio Remote Code Execution Vulnerability
ModificadaAlta (7.8)0.77%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel8/8/202310/8/2026
Vulnerabilidad de ejecución remota de código de Microsoft Office Visio
ModificadaAlta (7.8)0.99%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel8/8/202310/8/2026
Microsoft Office Visio Remote Code Execution Vulnerability
ModificadaAlta (7.8)0.99%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online Server8/8/202310/8/2026
Microsoft Office Remote Code Execution Vulnerability
ModificadaCrítica (9.8)12%💥 PoCTongda2000 Tongda Office Anywhere5/8/202317/6/2026
A vulnerability has been found in Tongda OA and classified as critical. This vulnerability affects unknown code of the file general/system/seal_manage/dianju/delete_log.php. The manipulation of the argument DELETE_STR leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to…
ModificadaCrítica (9.8)12%💥 PoCTongda2000 Tongda Office Anywhere5/8/202317/6/2026
A vulnerability, which was classified as critical, was found in Tongda OA. This affects an unknown part of the file general/system/seal_manage/iweboffice/delete_seal.php. The manipulation of the argument DELETE_STR leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to…
ModificadaBaja (3.2)0.36%—Open-xchange Appsuite Office2/8/202317/6/2026
In case Cacheservice was configured to use a sproxyd object-storage backend, it would follow HTTP redirects issued by that backend. An attacker with access to a local or restricted network with the capability to intercept and replay HTTP requests to sproxyd (or who is in control of the sproxyd service) could perform a…
ModificadaMedia (5.5)0.40%—Open-xchange Appsuite Office2/8/202317/6/2026
Cacheservice did not correctly check if relative cache object were pointing to the defined absolute location when accessing resources. An attacker with access to the database and a local or restricted network would be able to read arbitrary local file system resources that are accessible by the services system user…
ModificadaAlta (7.8)0.41%—Open-xchange Appsuite Office2/8/202317/6/2026
Se podía abusar de la API de Cache Service para inyectar indirectamente parámetros con sintaxis SQL que no estaban suficientemente sanitizados y que posteriormente se ejecutaban al crear nuevos grupos de caché. Los atacantes con acceso a una red local o restringida podían realizar consultas SQL arbitrarias. Se ha…
ModificadaAlta (7.8)0.43%—Open-xchange Appsuite Office2/8/202317/6/2026
Se podía abusar de la API de Cache Service para inyectar parámetros con sintaxis SQL que no estaba suficientemente sanitizada antes de ejecutarse como sentencia SQL. Los atacantes con acceso a una red local o restringida podían realizar consultas SQL arbitrarias, descubriendo los datos almacenados en caché de otros…
ModificadaCrítica (9.8)0.78%—Weaver E-office25/7/202317/6/2026
An arbitrary file upload vulnerability in eoffice before v9.5 allows attackers to execute arbitrary code via uploading a crafted file.
ModificadaMedia (6.1)0.53%—Mobisystems Office Suite20/7/202317/6/2026
Office Suite Premium Version v10.9.1.42602 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the filter parameter at /api?path=files.
ModificadaAlta (7.5)1.2%—Mobisystems Office Suite20/7/202317/6/2026
Office Suite Premium v10.9.1.42602 was discovered to contain a local file inclusion (LFI) vulnerability via the component /etc/hosts.
ModificadaMedia (6.1)0.53%—Mobisystems Office Suite20/7/202317/6/2026
Office Suite Premium Version v10.9.1.42602 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the id parameter at /api?path=profile.
ModificadaMedia (5.5)0.76%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online Server11/7/202317/6/2026
Microsoft Excel Information Disclosure Vulnerability