Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3142▲ 566 respecto a la semana anterior
Críticas / altas1456▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
2576 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 30% | 💥 Exploit | Microsoft Live MeetingMicrosoft LyncMicrosoft OfficeMicrosoft Skype FOR Business+8 | 14/10/2016 | 17/6/2026 | El componente Graphics en Microsoft Windows Vista SP2; Windows Server 2008 SP2 y R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold y R2; Windows RT 8.1; Windows 10 Gold, 1511 y 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee y Live… | |
| Modificada | Alta (7.8) | 24% | — | Microsoft Live MeetingMicrosoft LyncMicrosoft OfficeMicrosoft Skype FOR Business+8 | 14/10/2016 | 17/6/2026 | Graphics Device Interface (también conocido como GDI o GDI+) en Microsoft Windows Vista SP2; Windows Server 2008 SP2 y R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold y R2; Windows RT 8.1; Windows 10 Gold, 1511 y 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1;… | |
| Modificada | Media (5.5) | 32% | — | Microsoft Live MeetingMicrosoft LyncMicrosoft OfficeMicrosoft Skype FOR Business+8 | 14/10/2016 | 17/6/2026 | Graphics Device Interface (también conocido como GDI o GDI+) en Microsoft Windows Vista SP2; Windows Server 2008 SP2 y R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold y R2; Windows RT 8.1; Windows 10 Gold, 1511 y 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1;… | |
| Modificada | Media (5.5) | 32% | — | Microsoft Live MeetingMicrosoft LyncMicrosoft OfficeMicrosoft Skype FOR Business+8 | 14/10/2016 | 17/6/2026 | Graphics Device Interface (también conocido como GDI o GDI+) en Microsoft Windows Vista SP2; Windows Server 2008 SP2 y R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold y R2; Windows RT 8.1; Windows 10 Gold, 1511 y 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype para Business 2016; Lync 2013 SP1;… | |
| Modificada | Media (5.5) | 54% | 💥 Exploit | Microsoft .net FrameworkMicrosoft Live MeetingMicrosoft LyncMicrosoft Office+10 | 14/10/2016 | 17/6/2026 | Graphics Device Interface (también conocido como GDI o GDI+) en Microsoft Windows Vista SP2; Windows Server 2008 SP2 y R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold y R2; Windows RT 8.1; Windows 10 Gold, 1511 y 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1;… | |
| Modificada | Media (6.5) | 0.74% | — | Huawei Anyoffice Secureapp | 26/9/2016 | 17/6/2026 | Huawei AnyMail en versiones anteriores a 2.6.0301.0060 permite a atacantes remotos provocar una denegación de servicio (caída de aplicación) a través de un archivo adjunto de email comprimido manipulado. | |
| Modificada | Alta (7.8) | 15% | — | Microsoft ExcelMicrosoft Excel ViewerMicrosoft Office Compatibility Pack | 14/9/2016 | 17/6/2026 | Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3 y Excel Viewer permiten a atacantes remotos ejecutar código arbitrario a través de un documento manipulado, vulnerabilidad también conocida como "Microsoft Office Memory Corruption Vulnerability," una… | |
| Modificada | Alta (7.8) | 20% | — | Microsoft ExcelMicrosoft Excel ViewerMicrosoft Office Compatibility PackMicrosoft Office Online Server+1 | 14/9/2016 | 17/6/2026 | Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, Excel Viewer, Excel Services en SharePoint Server 2007 SP3, Excel Services en SharePoint Server 2010 SP2, Excel Automation Services en SharePoint Server 2013 SP1 y Office Online Server permiten a… | |
| Modificada | Alta (7.8) | 20% | — | Microsoft ExcelMicrosoft Excel ViewerMicrosoft Office Compatibility Pack | 14/9/2016 | 17/6/2026 | Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3 y Excel Viewer permiten a atacantes remotos ejecutar código arbitrario a través de un documento manipulado, vulnerabilidad también conocida como "Microsoft Office Memory Corruption Vulnerability", una… | |
| Modificada | Alta (7.8) | 17% | — | Microsoft ExcelMicrosoft Excel ViewerMicrosoft Office Compatibility PackMicrosoft Office Online Server+1 | 14/9/2016 | 17/6/2026 | Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, Excel Viewer, Excel Services en SharePoint Server 2007 SP3, Excel Services en SharePoint Server 2010 SP2, Excel Automation Services en SharePoint Server 2013 SP1 y Office Online Server permiten a… | |
| Modificada | Alta (7.8) | 17% | — | Microsoft Office Compatibility PackMicrosoft Office WEB AppsMicrosoft Office WEB Apps ServerMicrosoft Powerpoint+3 | 14/9/2016 | 17/6/2026 | Microsoft PowerPoint 2007 SP3, PowerPoint 2010 SP2, PowerPoint 2013 SP1, PowerPoint 2013 RT SP1, PowerPoint 2016 para Mac, Office Compatibility Pack SP3, PowerPoint Viewer, SharePoint Server 2013 SP1, Office Web Apps 2010 SP2 y Office Web Apps Server 2013 SP1 permiten a atacantes remotos ejecutar código arbitrario a… | |
| Modificada | Alta (7.8) | 17% | — | Microsoft ExcelMicrosoft Excel ViewerMicrosoft Office Compatibility Pack | 14/9/2016 | 17/6/2026 | Microsoft Excel 2007 SP3, Excel 2010 SP2, Office Compatibility Pack SP3 y Excel Viewer permiten a atacantes remotos ejecutar código arbitrario a través de un documento manipulado, vulnerabilidad también conocida como "Microsoft Office Memory Corruption Vulnerability". | |
| Modificada | Alta (7.8) | 18% | — | Microsoft ExcelMicrosoft Excel FOR MACMicrosoft Excel ViewerMicrosoft Office Compatibility Pack+2 | 14/9/2016 | 17/6/2026 | Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel 2016 para Mac, Office Compatibility Pack SP3, Excel Viewer, Excel Services en SharePoint Server 2007 SP3, Excel Services en SharePoint Server 2010 SP2, Excel Automation Services en SharePoint Server 2013 SP1 y Office Online… | |
| Modificada | Alta (7.8) | 55% | 💥 Exploit | Microsoft OfficeMicrosoft Office WEB AppsMicrosoft Office WEB Apps ServerMicrosoft Sharepoint Foundation+2 | 14/9/2016 | 17/6/2026 | Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word para Mac 2011, Word 2016 para Mac, Word Viewer, Word Automation Services en SharePoint Server 2010 SP2, SharePoint Server 2013 SP1, Excel Automation Services en SharePoint Server 2013 SP1, Word Automation Services en… | |
| Modificada | Media (6.5) | 4.9% | — | Microsoft Office | 14/9/2016 | 17/6/2026 | Las macros de Visual Basic en Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1 y 2016 exportan una clave privada del certificado de almacenamiento durante una operación de guardado de documento, lo que permite a atacantes obtener información sensible a través de vectores no especificados, vulnerabilidad también conocida… | |
| Modificada | Baja (3.3) | 6.8% | — | Microsoft Office | 14/9/2016 | 17/6/2026 | La implementación Click-to-Run (C2R) en Microsoft Office 2013 SP1 y 2016 permite a usuarios locales eludir el mecanismo de protección ASLR a través de una aplicación manipulada, vulnerabilidad también conocida como "Microsoft APP-V ASLR Bypass". | |
| Modificada | Alta (7.8) | 22% | — | Microsoft Office | 9/8/2016 | 17/6/2026 | Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1 y 2013 RT SP1 permiten a atacantes remotos ejecutar código arbitrario a través de un archivo manipulado, también conocida como "Graphics Component Memory Corruption Vulnerability". | |
| Modificada | Alta (7.8) | 22% | — | Microsoft OfficeMicrosoft WordMicrosoft Word FOR MACMicrosoft Word Viewer | 9/8/2016 | 17/6/2026 | Microsoft Office 2010 SP2, Word 2007 SP3, Word 2010 SP2, Word para Mac 2011, Word 2016 para Mac y Word Viewer permiten a atacantes remotos ejecutar código arbitrario a través de un archivo manipulado, también conocida como "Microsoft Office Memory Corruption Vulnerability". | |
| Modificada | Alta (7.8) | 50% | 💥 Exploit | Microsoft OfficeMicrosoft Word FOR MACMicrosoft Word Viewer | 9/8/2016 | 17/6/2026 | Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, 2013 RT SP1 y 2016, Word 2016 para Mac y Word Viewer permiten a atacantes remotos ejecutar código arbitrario a través de un archivo manipulado, también conocida como "Microsoft Office Memory Corruption Vulnerability". | |
| Modificada | Alta (7.8) | 51% | 💥 Exploit | Microsoft Live MeetingMicrosoft LyncMicrosoft OfficeMicrosoft Skype FOR Business+4 | 9/8/2016 | 17/6/2026 | La librería de fuente Windows en Microsoft Windows Vista SP2, Windows Server 2008 SP2 y R2 SP1, Windows 7 SP1, Office 2007 SP3, Office 2010 SP2, Word Viewer, Skype para Business 2016, Lync 2013 SP1, Lync 2010, Lync 2010 Attendee y Live Meeting 2007 Console permite a atacantes remotos ejecutar código arbitrario a… | |
| Modificada | Alta (7.8) | 51% | 💥 Exploit | Microsoft Live MeetingMicrosoft LyncMicrosoft OfficeMicrosoft Skype FOR Business+4 | 9/8/2016 | 17/6/2026 | La librería de fuente Windows en Microsoft Windows Vista SP2, Windows Server 2008 SP2 y R2 SP1, Windows 7 SP1, Office 2007 SP3, Office 2010 SP2, Word Viewer, Skype para Business 2016, Lync 2013 SP1, Lync 2010, Lync 2010 Attendee y Live Meeting 2007 Console permite a atacantes remotos ejecutar código arbitrario a… | |
| Modificada | Alta (7.8) | 44% | 💥 Exploit | Microsoft Live MeetingMicrosoft LyncMicrosoft OfficeMicrosoft Skype FOR Business+8 | 9/8/2016 | 17/6/2026 | La librería de fuente Windows en Microsoft Windows Vista SP2; Windows Server 2008 SP2 y R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold y R2; Windows RT 8.1; Windows 10 Gold, 1511 y 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype para Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee;… | |
| Modificada | Alta (7.8) | 4.3% | — | Apache Openoffice | 5/8/2016 | 17/6/2026 | La herramienta Impress en Apache OpenOffice 4.1.2 y versiones anteriores permite a atacantes remotos provocar una denegación de servicio (lectura o escritura fuera de rango) o ejecutar código arbitrario a través de MetaActions manipuladas en un archivo (1) ODP o (2) OTP. | |
| Modificada | Alta (7.8) | 20% | — | Microsoft ExcelMicrosoft Excel FOR MACMicrosoft Excel RTMicrosoft Excel Viewer+1 | 13/7/2016 | 17/6/2026 | Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel para Mac 2011, Excel 2016 para Mac, Office Compatibility Pack SP3 y Excel Viewer permiten a atacantes remotos ejecutar código arbitrario a través de un documento Office manipulado, también conocida como "Microsoft Office… | |
| Modificada | Alta (7.8) | 26% | — | Microsoft OfficeMicrosoft Office Compatibility PackMicrosoft Office Online ServerMicrosoft Office WEB Apps+6 | 13/7/2016 | 17/6/2026 | Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word para Mac 2011, Word 2016 para Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services en SharePoint Server 2010 SP2, Word Automation Services en SharePoint Server 2013 SP1, SharePoint Server… |