Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

445 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.56%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+19/12/202517/6/2026
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.66%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel9/12/202517/6/2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7)0.52%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+19/12/202530/9/2026
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.43%—Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel9/12/202530/9/2026
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.60%—Microsoft 365 AppsMicrosoft AccessMicrosoft OfficeMicrosoft Office Long Term Servicing Channel9/12/202530/9/2026
Relative path traversal in Microsoft Office Access allows an unauthorized attacker to execute code locally.
AplazadaAlta (7.2)0.29%—Codisto Omnichannel FOR WoocommerceAI4/12/202517/6/2026
The Omnichannel for WooCommerce: Google, Amazon, eBay & Walmart Integration – Powered by Codisto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sync() function in all versions up to, and including, 1.3.65 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaAlta (7.2)0.23%—Telegram BOT ChannelAI25/11/202517/6/2026
The Telegram Bot & Channel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Telegram username in all versions up to, and including, 4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…
AnalizadaCrítica (9.8)0.49%—Microsoft Dynamics Omnichannel SDK Storage Containers20/11/202517/6/2026
Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privileges over a network.
AplazadaMedia (5.1)0.31%—Xcally OmnichannelAI13/11/202517/6/2026
Cross-site Scripting (XSS) vulnerability reflected in xCally's Omnichannel v3.30.1. This vulnerability allowsan attacker to executed JavaScript code in the victim's browser by sending them a malicious URL using the 'failureMessage' parameter in '/login'. This vulnerability can be exploited to steal sentitive user…
AnalizadaAlta (7.8)0.41%—Microsoft 365 AppsMicrosoft Office Long Term Servicing Channel11/11/202517/6/2026
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.41%—Microsoft 365 AppsMicrosoft Office Long Term Servicing Channel11/11/202517/6/2026
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.51%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+111/11/202517/6/2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.1)0.52%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+111/11/202517/6/2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
AnalizadaAlta (7.8)0.48%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+111/11/202517/6/2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.48%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+111/11/202517/6/2026
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
ModificadaAlta (7.8)0.76%—Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft ExcelMicrosoft Office Long Term Servicing Channel11/11/202517/6/2026
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
AnalizadaMedia (4.3)0.72%—Microsoft 365 AppsMicrosoft Office Long Term Servicing Channel11/11/202517/6/2026
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (7.8)0.64%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+111/11/202517/6/2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.1)0.58%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+111/11/202517/6/2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
AnalizadaCrítica (9.8)5.9%—Microsoft 365 CopilotMicrosoft Office Long Term Servicing ChannelMicrosoft Windows 10 1607Microsoft Windows 10 1809+1211/11/202517/6/2026
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
AnalizadaMedia (5.5)0.59%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel11/11/202517/6/2026
Exposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
AplazadaAlta (7.1)0.25%—Selloio Sello ChannelconnectorAI22/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in selloio Sello ChannelConnector sello-channelconnector allows Reflected XSS.This issue affects Sello ChannelConnector: from n/a through <= 1.6.3.
AnalizadaAlta (7.8)0.45%—Microsoft 365 AppsMicrosoft Office Long Term Servicing Channel14/10/202517/6/2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.38%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Powerpoint14/10/202517/6/2026
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.42%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online Server14/10/202517/6/2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Orbitaley — Vulnerabilidades