Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

621 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.7)0.66%—Excelize10/7/202616/7/2026
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the streaming worksheet reader used by Rows and GetRows does not enforce the TotalRows limit on the row r attribute, allowing a small XLSX file with a row number above 1048576 and no cell coordinate to make GetRows…
AnalizadaAlta (7.5)0.61%—Excelize10/7/202616/7/2026
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the checkSheet() function in github.com/xuri/excelize/v2 uses an attacker-controlled <row r="N"> XML attribute value directly as the length argument to make([]xlsxRow, row) without validating it against the Excel…
AplazadaMedia (4.6)0.19%—Actual-app CLIAIMicrosoft ExcelAILibreoffice CalcAIGoogle SheetsAI7/7/20268/7/2026
Actual is a local-first personal finance app. Prior to 26.6.0, @actual-app/cli ships a hand-rolled CSV serializer in packages/cli/src/output.ts used whenever the global --format csv option is passed, whose escapeCsv helper only handles RFC 4180 delimiter, quote, and newline escaping and does not neutralize standard…
AnalizadaAlta (7.1)0.44%—Microsoft ExcelMicrosoft PowerpointMicrosoft Word9/6/202623/7/2026
Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+39/6/202623/7/2026
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
ModificadaMedia (4.3)0.76%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+39/6/202623/7/2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
ModificadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+39/6/202623/7/2026
Numeric truncation error in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (8.2)0.60%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+39/6/202623/7/2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
ModificadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+39/6/202623/7/2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
ModificadaAlta (7)0.28%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+39/6/202623/7/2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
ModificadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2019+39/6/202623/7/2026
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.47%—Microsoft ExcelMicrosoft PowerpointMicrosoft WordMicrosoft Windows 10 1607+129/6/202623/7/2026
Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.47%—Microsoft ExcelMicrosoft PowerpointMicrosoft WordMicrosoft Windows 10 1607+129/6/202623/7/2026
Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.
AplazadaBaja (2.1)0.29%—Ishayoyo Excel-mcpAI1/6/202622/7/2026
A vulnerability was determined in ishayoyo excel-mcp up to 1.0.2. Impacted is an unknown function of the file src/index.ts of the component read_file/write_file. Executing a manipulation of the argument filePath/outputPath can lead to path traversal. It is possible to launch the attack remotely. The exploit has been…
AnalizadaMedia (5.5)0.31%—Microsoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Word12/5/202617/6/2026
Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.
ModificadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+112/5/202617/6/2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+112/5/202617/6/2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+112/5/202617/6/2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AplazadaCrítica (9.4)0.64%—Excel-mcp-serverAI21/4/202617/6/2026
excel-mcp-server is a Model Context Protocol server for Excel file manipulation. A path traversal vulnerability exists in excel-mcp-server versions up to and including 0.1.7. When running in SSE or Streamable-HTTP transport mode (the documented way to use this server remotely), an unauthenticated attacker on the…
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+114/4/202617/6/2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+114/4/202617/6/2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+114/4/202617/6/2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+114/4/202617/6/2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.1)0.53%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+114/4/202617/6/2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
AnalizadaAlta (8.6)0.25%—Passfab Excel Password Recovery26/3/202617/6/2026
PassFab Excel Password Recovery 8.3.1 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload in the registration code field. Attackers can craft a buffer overflow payload with a pop-pop-ret gadget and shellcode that…
Orbitaley — Vulnerabilidades