Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 119 respecto a la semana anterior
Críticas / altas1267▼ 261 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 186 respecto a la semana anterior
2573 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.63% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 11/7/2023 | 17/6/2026 | Microsoft Excel Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 0.63% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 11/7/2023 | 17/6/2026 | Microsoft Excel Remote Code Execution Vulnerability | |
| Modificada | Alta (8.8) | 1.0% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 11/7/2023 | 17/6/2026 | Microsoft Outlook Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 0.53% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 11/7/2023 | 17/6/2026 | Microsoft ActiveX Remote Code Execution Vulnerability | |
| Modificada | Media (6.5) | 3.4% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 11/7/2023 | 17/6/2026 | Microsoft Outlook Spoofing Vulnerability | |
| Modificada | Crítica (9.6) | 2.1% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Word | 11/7/2023 | 17/6/2026 | Microsoft Office Security Feature Bypass Vulnerability | |
| Modificada | Alta (7.8) | 0.63% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 11/7/2023 | 17/6/2026 | Microsoft Office Graphics Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 2.1% | 💥 Exploit | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 11/7/2023 | 17/6/2026 | Microsoft Office Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.5) | 16% | ⚠ Explotación activa | Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Outlook | 11/7/2023 | 8/10/2026 | Microsoft Outlook Security Feature Bypass Vulnerability | |
| Modificada | Media (5.5) | 65% | — | LibreofficeFedoraproject FedoraRedhat Enterprise Linux | 10/7/2023 | 17/6/2026 | A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker. | |
| Modificada | Media (5.3) | 0.52% | — | Dzzoffice | 27/6/2023 | 17/6/2026 | Incorrect access control in the component /index.php?mod=system&op=orgtree of dzzoffice 2.02.1_SC_UTF8 allows unauthenticated attackers to browse departments and usernames. | |
| Modificada | Media (6.1) | 0.60% | 💥 Exploit | Dzzoffice | 27/6/2023 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in the zero parameter of dzzoffice 2.02.1_SC_UTF8 allows attackers to execute arbitrary web scripts or HTML. | |
| Modificada | Crítica (9.8) | 5.0% | — | Onlyoffice | 22/6/2023 | 17/6/2026 | Onlyoffice Community Server before v12.5.2 was discovered to contain a remote code execution (RCE) vulnerability via the component UploadProgress.ashx. | |
| Modificada | Alta (7.8) | 0.74% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Publisher | 17/6/2023 | 17/6/2026 | Microsoft Publisher Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 0.74% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Publisher | 17/6/2023 | 17/6/2026 | Microsoft Publisher Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 0.84% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 14/6/2023 | 17/6/2026 | Microsoft Office Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 2.7% | 💥 Exploit | Microsoft OfficeMicrosoft Office Online Server | 14/6/2023 | 17/6/2026 | Microsoft Excel Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 44% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online Server | 14/6/2023 | 17/6/2026 | Microsoft Excel Remote Code Execution Vulnerability | |
| Modificada | Alta (8.8) | 5.7% | 💥 Exploit | Microsoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft OutlookMicrosoft Outlook RT | 14/6/2023 | 17/6/2026 | Microsoft Outlook Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 54% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 14/6/2023 | 17/6/2026 | Microsoft Excel Remote Code Execution Vulnerability | |
| Modificada | Alta (8.1) | 1.1% | — | Kingsoft WPS Office | 13/6/2023 | 17/6/2026 | OS command injection vulnerability exists in WPS Office version 10.8.0.6186. If a remote attacker who can conduct a man-in-the-middle attack connects the product to a malicious server and sends a specially crafted data, an arbitrary OS command may be executed on the system where the product is installed. | |
| Modificada | Alta (7.8) | 0.92% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 5/6/2023 | 17/6/2026 | Microsoft Office Remote Code Execution Vulnerability | |
| Modificada | Alta (7.5) | 1.1% | — | Harbingergroup Office Player | 5/6/2023 | 17/6/2026 | El archivo ejecutable "OfflinePlayerService.exe" en Harbinger Offline Player v4.0.6.0.2 permite el salto de directorios como LocalSystem a través de ..\ en una URL. | |
| Modificada | Media (5.4) | 0.56% | — | Gougucms Pythagorean OA Office System | 1/6/2023 | 17/6/2026 | A vulnerability has been found in Guangdong Pythagorean OA Office System up to 4.50.31 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Schedule Handler. The manipulation of the argument description leads to cross site scripting. The attack can be launched… | |
| Modificada | Alta (8.8) | 0.44% | — | Pythagorean OA Office System Project Pythagorean OA Office System | 1/6/2023 | 17/6/2026 | A vulnerability has been found in Guangdong Pythagorean OA Office System up to 4.50.31 and classified as problematic. This vulnerability affects unknown code of the file /note/index/delete. The manipulation of the argument id leads to cross-site request forgery. The attack can be initiated remotely. The exploit has… |