Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2724▼ 159 respecto a la semana anterior
Críticas / altas1243▼ 302 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 198 respecto a la semana anterior
–

2573 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)22%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Outlook1/6/202317/6/2026
Vulnerabilidad de denegación de servicios encontrada en Microsoft Outlook.
ModificadaMedia (5.4)0.40%—Collaboraoffice Collabora Online31/5/202317/6/2026
Collabora Online is a collaborative online office suite. A stored cross-site scripting (XSS) vulnerability was found in Collabora Online prior to versions 22.05.13, 21.11.9.1, and 6.4.27. An attacker could create a document with an XSS payload as a document name. Later, if an administrator opened the admin console and…
ModificadaMedia (5.3)2.2%💥 PoCLibreofficeDebian Linux25/5/202317/6/2026
Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of LibreOffice documents that used "floating frames" linked to external files, would load the contents of…
ModificadaAlta (7.8)0.30%—LibreofficeDebian Linux25/5/202317/6/2026
Improper Validation of Array Index vulnerability in the spreadsheet component of The Document Foundation LibreOffice allows an attacker to craft a spreadsheet document that will cause an array index underflow when loaded. In the affected versions of LibreOffice certain malformed spreadsheet formulas, such as…
ModificadaAlta (7.8)0.12%—Acronis Cyber Protect Home Office18/5/202317/6/2026
Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40208.
ModificadaAlta (7.5)54%💥 ExploitWeaver E-office17/5/202317/6/2026
A vulnerability was found in Weaver OA 9.5 and classified as problematic. This issue affects some unknown processing of the file /building/backmgr/urlpage/mobileurl/configfile/jx2_config.ini. The manipulation leads to files or directories accessible. The attack may be initiated remotely. The exploit has been disclosed…
ModificadaAlta (7.5)2.2%—Weaver E-office17/5/202317/6/2026
A vulnerability has been found in Weaver OA up to 9.5 and classified as problematic. This vulnerability affects unknown code of the file /E-mobile/App/System/File/downfile.php. The manipulation of the argument url leads to absolute path traversal. The attack can be initiated remotely. The exploit has been disclosed to…
ModificadaCrítica (9.8)0.87%—Tongda2000 Tongda Office Anywhere16/5/202317/6/2026
A vulnerability classified as critical has been found in Tongda OA 11.10. This affects the function actionGetdata of the file GatewayController.php. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The…
ModificadaCrítica (9.8)28%💥 ExploitWeaver E-office11/5/202317/6/2026
A vulnerability was found in Weaver E-Office 9.5. It has been classified as critical. This affects an unknown part of the file /inc/jquery/uploadify/uploadify.php. The manipulation of the argument Filedata leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to…
ModificadaAlta (8.8)7.0%—Weaver E-office11/5/202317/6/2026
A vulnerability was found in Weaver E-Office 9.5 and classified as critical. Affected by this issue is some unknown functionality of the file /webroot/inc/utility_all.php of the component File Upload Handler. The manipulation leads to command injection. The attack may be launched remotely. The exploit has been…
ModificadaAlta (7.5)1.2%—Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 20h2+129/5/202317/6/2026
Microsoft Word Security Feature Bypass Vulnerability
ModificadaBaja (3.3)0.56%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel9/5/202317/6/2026
Microsoft Access Denial of Service Vulnerability
ModificadaAlta (7.8)0.70%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+19/5/202317/6/2026
Microsoft Excel Remote Code Execution Vulnerability
ModificadaCrítica (9.8)33%💥 PoCE-office4/5/202317/6/2026
A vulnerability was found in Weaver E-Office 9.5. It has been rated as critical. Affected by this issue is some unknown functionality of the file App/Ajax/ajax.php?action=mobile_upload_save. The manipulation of the argument upload_quwan leads to unrestricted upload. The attack may be launched remotely. The exploit has…
ModificadaMedia (6.1)0.58%💥 PoCGroup-office Group Office27/4/20239/7/2026
Reflected Cross Site Scripting (XSS) in Intermesh BV Group-Office version 6.6.145, allows attackers to gain escalated privileges and gain sensitive information via the GO_LANGUAGE cookie.
ModificadaAlta (7.8)2.7%💥 ExploitMicrosoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel11/4/202317/6/2026
Microsoft Word Remote Code Execution Vulnerability
ModificadaAlta (7.8)3.0%💥 ExploitMicrosoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel11/4/202317/6/2026
Microsoft Office Remote Code Execution Vulnerability
ModificadaAlta (7.5)0.78%—Amano Xoffice28/3/202317/6/2026
amano Xparc parking solutions 7.1.3879 was discovered to be vulnerable to local file inclusion.
ModificadaAlta (7.8)0.96%—Apache Openoffice24/3/202317/6/2026
Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes are defined for this purpose. Links can be activated by clicks, or by automatic document events. The execution of such links must be subject to user approval. In the affected versions of OpenOffice,…
ModificadaAlta (7.8)0.87%—Apache Openoffice24/3/202317/6/2026
Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code from the current directory.
ModificadaAlta (7.8)0.30%—Onlyoffice Document Server19/3/202317/6/2026
ONLYOFFICE Docs through 7.3 on certain Linux distributions allows local users to gain privileges via a Trojan horse libgcc_s.so.1 in the current working directory, which may be any directory in which an ONLYOFFICE document is located.
ModificadaAlta (7.8)0.39%—Microsoft 365Microsoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Windows 10 1607+1114/3/202317/6/2026
Windows Graphics Component Elevation of Privilege Vulnerability
ModificadaAlta (7.8)2.5%💥 ExploitMicrosoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+214/3/202317/6/2026
Microsoft Excel Remote Code Execution Vulnerability
ModificadaAlta (7.1)0.62%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel14/3/202317/6/2026
Microsoft Excel Spoofing Vulnerability
AnalizadaCrítica (9.8)97%⚠ Explotación activa💥 PoCMicrosoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Outlook14/3/202317/6/2026
Microsoft Outlook Elevation of Privilege Vulnerability