Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
103 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.3) | 0.57% | — | Microsoft 365 Word Copilot | 9/10/2025 | 17/6/2026 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (5.5) | 0.78% | — | Microsoft 365 CopilotMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809+12 | 9/9/2025 | 17/6/2026 | Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally. | |
| Aplazada | Media (5.1) | 0.10% | — | Obsidian Github Copilot PluginAI | 5/9/2025 | 17/6/2026 | Obsidian GitHub Copilot Plugin versions prior to 1.1.7 store Github API token in cleartext form. As a result, an attacker may perform unauthorized operations on the linked Github account. | |
| Analizada | Crítica (9.8) | 8.0% | — | Microsoft 365 CopilotMicrosoft OfficeMicrosoft Windows 10 1507Microsoft Windows 10 1607+13 | 12/8/2025 | 17/6/2026 | Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.8) | 0.48% | — | Microsoft 365 CopilotMicrosoft Office | 12/8/2025 | 17/6/2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.5) | 0.71% | — | Microsoft 365 Copilot Chat | 7/8/2025 | 17/6/2026 | Microsoft 365 Copilot BizChat Information Disclosure Vulnerability | |
| Analizada | Alta (7.5) | 0.61% | — | Microsoft 365 Copilot Chat | 7/8/2025 | 17/6/2026 | Microsoft 365 Copilot BizChat Information Disclosure Vulnerability | |
| Analizada | Alta (7.8) | 0.63% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 8/7/2025 | 17/6/2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (8.4) | 0.51% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 8/7/2025 | 17/6/2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (8.4) | 0.61% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 8/7/2025 | 17/6/2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (8.4) | 0.66% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 8/7/2025 | 17/6/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Modificada | Alta (7.5) | 8.0% | 💥 PoC | Microsoft 365 Copilot | 11/6/2025 | 17/6/2026 | Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (8.4) | 0.54% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 10/6/2025 | 17/6/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (8.4) | 0.67% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 10/6/2025 | 17/6/2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (8.4) | 0.66% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 10/6/2025 | 17/6/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (8.4) | 0.77% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 10/6/2025 | 17/6/2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 4.2% | — | Microsoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Windows 10 1507+14 | 13/5/2025 | 17/6/2026 | Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.65% | — | Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 13/5/2025 | 17/6/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.5) | 1.1% | — | Microsoft 365 CopilotMicrosoft OfficeMicrosoft Windows 10 1507Microsoft Windows 10 1607+13 | 8/4/2025 | 17/6/2026 | Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.6) | 0.96% | — | Microsoft Copilot Studio | 26/11/2024 | 17/6/2026 | Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorized attacker leads to elevation of privilege over a network. | |
| Aplazada | Alta (7.5) | 0.42% | — | Butterfly Effect Limited Monica Your AI CopilotAI | 24/10/2024 | 17/6/2026 | A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica Your AI Copilot powered by ChatGPT4 v6.3.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message. | |
| Analizada | Alta (7.5) | 1.1% | — | Microsoft Copilot Studio | 9/10/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through network attack vector | |
| Aplazada | Media (5.3) | 0.42% | — | M-files Connector FOR CopilotAI | 2/10/2024 | 17/6/2026 | Permissions bypass in M-Files Connector for Copilot before version 24.9.3 allows authenticated user to access limited amount of documents via incorrect access control list calculation | |
| Analizada | Alta (7.8) | 0.70% | — | Microsoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Windows 10 1507+13 | 10/9/2024 | 10/8/2026 | Windows Graphics Component Elevation of Privilege Vulnerability | |
| Modificada | Media (6.5) | 12% | — | Microsoft Copilot Studio | 6/8/2024 | 17/6/2026 | An authenticated attacker can bypass Server-Side Request Forgery (SSRF) protection in Microsoft Copilot Studio to leak sensitive information over a network. |