Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
95 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.7) | 6.2% | — | Microsoft ExcelMicrosoft OfficeMicrosoft Office 365 Proplus | 12/12/2018 | 17/6/2026 | An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Excel. This CVE ID is unique from CVE-2018-8627. | |
| Modificada | Alta (7.8) | 16% | — | Microsoft ExcelMicrosoft OfficeMicrosoft Office 365Microsoft Office Compatibility Pack | 12/12/2018 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Excel. This CVE ID is unique from CVE-2018-8636. | |
| Modificada | Alta (7.8) | 29% | 💥 PoC | Microsoft OfficeMicrosoft Office 365 Proplus | 12/12/2018 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook. | |
| Modificada | Alta (8.8) | 19% | — | Microsoft Office 365 ProplusMicrosoft OutlookMicrosoft Outlook RTMicrosoft Windows Server 2019 | 14/11/2018 | 17/6/2026 | A remote code execution vulnerability exists in the way that Microsoft Outlook parses specially modified rule export files, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook. This CVE ID is unique from CVE-2018-8522, CVE-2018-8524,… | |
| Modificada | Media (6.5) | 6.3% | — | Microsoft OfficeMicrosoft Office 365 Proplus | 14/11/2018 | 17/6/2026 | An information disclosure vulnerability exists when attaching files to Outlook messages, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Office 365 ProPlus, Microsoft Office. This CVE ID is unique from CVE-2018-8558. | |
| Modificada | Alta (7.8) | 19% | — | Microsoft ExcelMicrosoft Excel ViewerMicrosoft OfficeMicrosoft Office 365 Proplus+2 | 14/11/2018 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Office, Office 365 ProPlus, Microsoft Excel, Microsoft Excel Viewer, Excel. This CVE ID is unique from… | |
| Modificada | Alta (7.8) | 19% | — | Microsoft OfficeMicrosoft Office 365 ProplusMicrosoft Outlook | 14/11/2018 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook. This CVE ID is unique from CVE-2018-8522, CVE-2018-8524,… | |
| Modificada | Alta (7.8) | 20% | — | Microsoft Office 365 ProplusMicrosoft Project | 14/11/2018 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Project software when it fails to properly handle objects in memory, aka "Microsoft Project Remote Code Execution Vulnerability." This affects Microsoft Project, Office 365 ProPlus, Microsoft Project Server. | |
| Modificada | Alta (7.8) | 19% | — | Microsoft OfficeMicrosoft Office 365 Proplus | 14/11/2018 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Excel. This CVE ID is unique from CVE-2018-8577. | |
| Modificada | Alta (7.8) | 19% | — | Microsoft OfficeMicrosoft Office 365 ProplusMicrosoft Word | 14/11/2018 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka "Microsoft Word Remote Code Execution Vulnerability." This affects Microsoft Word, Office 365 ProPlus, Microsoft Office. This CVE ID is unique from CVE-2018-8539. | |
| Modificada | Media (6.5) | 5.6% | — | Microsoft OfficeMicrosoft Office 365 Proplus | 14/11/2018 | 17/6/2026 | An information disclosure vulnerability exists when Microsoft Outlook fails to respect "Default link type" settings configured via the SharePoint Online Admin Center, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Office 365 ProPlus, Microsoft Office. This CVE ID is unique from… | |
| Modificada | Media (5.9) | 5.5% | — | Microsoft LyncMicrosoft Lync BasicMicrosoft OfficeMicrosoft Office 365 Proplus+2 | 14/11/2018 | 17/6/2026 | A denial of service vulnerability exists in Skype for Business, aka "Microsoft Skype for Business Denial of Service Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Lync, Skype. | |
| Modificada | Alta (7.8) | 19% | — | Microsoft OfficeMicrosoft Office 365 ProplusMicrosoft OutlookMicrosoft Outlook RT | 14/11/2018 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook. This CVE ID is unique from CVE-2018-8522, CVE-2018-8576,… | |
| Modificada | Alta (7.8) | 19% | — | Microsoft OfficeMicrosoft Office 365 ProplusMicrosoft OutlookMicrosoft Outlook RT | 14/11/2018 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook. This CVE ID is unique from CVE-2018-8524, CVE-2018-8576,… | |
| Modificada | Alta (8.8) | 20% | — | Microsoft OfficeMicrosoft Office 365 ProplusMicrosoft Office WEB AppsMicrosoft Sharepoint Server+1 | 10/10/2018 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Word software when the software fails to properly handle objects in Protected View, aka "Microsoft Word Remote Code Execution Vulnerability." This affects Microsoft SharePoint Server, Office 365 ProPlus, Microsoft Office, Microsoft Word. | |
| Modificada | Alta (8.8) | 20% | — | Microsoft ExcelMicrosoft OfficeMicrosoft Office 365 Proplus | 10/10/2018 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in Protected View, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Excel. | |
| Modificada | Alta (8.8) | 20% | — | Microsoft OfficeMicrosoft Office 365 ProplusMicrosoft PowerpointMicrosoft Powerpoint Viewer | 10/10/2018 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in Protected View, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Office 365 ProPlus, PowerPoint Viewer, Microsoft Office, Microsoft PowerPoint. | |
| Modificada | Alta (7.8) | 20% | — | Microsoft Excel ViewerMicrosoft OfficeMicrosoft Office 365 ProplusMicrosoft Office Compatibility Pack+6 | 10/10/2018 | 17/6/2026 | A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka "Microsoft Graphics Components Remote Code Execution Vulnerability." This affects Windows 7, Microsoft Office, Microsoft Office Word Viewer, Office 365 ProPlus, Microsoft Excel Viewer, Microsoft… | |
| Modificada | Media (5.5) | 2.3% | — | Microsoft Excel ViewerMicrosoft OfficeMicrosoft Office 365 ProplusMicrosoft Office Compatibility Pack+3 | 10/10/2018 | 17/6/2026 | An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka "Microsoft Graphics Components Information Disclosure Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Office 365 ProPlus, Windows Server 2008, Microsoft PowerPoint… | |
| Modificada | Crítica (9.1) | 0.76% | — | Vaultive Office 365 Security | 3/5/2017 | 17/6/2026 | PGP/MIME encrypted messages injected into a Vaultive O365 (before 4.5.21) frontend via IMAP or SMTP have their Content-Type changed from 'Content-Type: multipart/encrypted; protocol="application/pgp-encrypted"; boundary="abc123abc123"' to 'Content-Type: text/plain' - this results in the encrypted message being… |