Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

445 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.58%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+19/9/202517/6/2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.58%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+19/9/202517/6/2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AplazadaAlta (8.7)0.32%—Scratch ChannelAI25/8/202517/6/2026
The Scratch Channel is a news website. In versions 1 and 1.1, a POST request to the endpoint used to publish articles, can be used to post an article in any category with any date, regardless of who's logged in. This issue has been patched in version 1.2.
AplazadaMedia (6.7)0.17%—Scratch ChannelAI25/8/202517/6/2026
The Scratch Channel is a news website. In version 1, it is possible to go to application in devtools and click local storage to edit the account's username locally. This issue has been patched in version 1.1.
AplazadaAlta (7.5)0.38%—Vertim Neon Channel Product Customizer FreeAI14/8/202517/6/2026
Missing Authorization vulnerability in vertim Neon Channel Product Customizer Free neon-channel-product-customizer-free allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Neon Channel Product Customizer Free: from n/a through <= 2.0.
AnalizadaAlta (8.4)0.50%—Microsoft 365 AppsMicrosoft Office Long Term Servicing Channel12/8/202517/6/2026
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.52%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Powerpoint12/8/202517/6/2026
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.52%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Office Online Server12/8/202517/6/2026
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.52%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+112/8/202517/6/2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (8.4)0.57%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel12/8/202517/6/2026
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.56%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+112/8/202517/6/2026
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.52%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Word12/8/202517/6/2026
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.53%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+112/8/202517/6/2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaMedia (6.2)0.50%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Enterprise Server+212/8/202517/6/2026
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
AnalizadaAlta (7.8)0.56%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+112/8/202517/6/2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.44%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel12/8/202517/6/2026
Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally.
AnalizadaAlta (8.4)0.55%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Enterprise Server+212/8/202517/6/2026
Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaAlta (8.4)0.57%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel12/8/202517/6/2026
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.42%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel12/8/202517/6/2026
Use after free in Microsoft Office Visio allows an unauthorized attacker to execute code locally.
AplazadaBaja (1.3)0.35%—Scratch ChannelAI15/7/202517/6/2026
The Scratch Channel is a news website that is under development as of time of this writing. The file `/api/users.js` doesn't properly sanitize text box inputs, leading to a potential vulnerability to cross-site scripting attacks. Commit 90b39eb56b27b2bac29001abb1a3cac0964b8ddb addresses this issue.
AnalizadaAlta (7.8)0.49%—Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+18/7/202517/6/2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.41%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Powerpoint8/7/202517/6/2026
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.67%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Sharepoint Server+18/7/202517/6/2026
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.63%—Microsoft 365 AppsMicrosoft 365 CopilotMicrosoft OfficeMicrosoft Office Long Term Servicing Channel8/7/202517/6/2026
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.41%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Word8/7/202517/6/2026
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Orbitaley — Vulnerabilidades