Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3085▲ 506 respecto a la semana anterior
Críticas / altas1460▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
1973 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 19% | — | Microsoft WordMicrosoft Works | 15/12/2003 | 16/6/2026 | Microsoft Excel 97, 2000 y 2002 permite a atacantes remotos ejecutar código arbitrario mediante una hoja de cálculo con una macro XLM (Excel 4) que evita el modelo de seguridad de macros. | |
| Modificada | Alta (7.5) | 26% | — | Microsoft WordMicrosoft Works | 15/12/2003 | 16/6/2026 | Micrososft Word 97, 98(J), 2000 y 2002, y Micrososft Works Suites 2001 a 2004, no comprueban adecuadamente la longitud de valor de datos "Macro Names", lo que podría permitir a atacantes remotos ejecutar código arbitrario mediante un ataque de desbordamiento de búfer. | |
| Modificada | Alta (7.5) | 22% | 💥 Exploit | Microsoft Wordperfect Converter | 20/10/2003 | 16/6/2026 | Buffer overflow in Microsoft Wordperfect Converter allows remote attackers to execute arbitrary code via modified data offset and data size parameters in a Corel WordPerfect file. | |
| Modificada | Alta (7.5) | 4.1% | — | Microsoft WordMicrosoft Works | 20/10/2003 | 16/6/2026 | Microsoft Word 2002, 2000, 97, and 98(J) does not properly check certain properties of a document, which allows attackers to bypass the macro security model and automatically execute arbitrary macros via a malicious document. | |
| Modificada | Media (5) | 54% | 💥 Exploit | Microsoft ExcelMicrosoft Word | 11/4/2003 | 16/6/2026 | Microsoft Word y Excel permite a atacantes remotos robar información sensible mediante ciertos códigos de campo que insertan la información cuando el documento es devuelto al atacante, como ha sido demostrado en Word usando INCLUDETEXT o INCLUDEPICTURE, tambien conocido como "Fallo en campos de Word y actualizaciones… | |
| Modificada | Media (5.1) | 1.3% | — | Cgiscript.net Cspassword | 4/10/2002 | 16/6/2026 | CGIScript.net csPassword.cgi stores usernames and unencrypted passwords in the password.cgi.tmp temporary file while modifying data, which could allow local users (and possibly remote attackers) to gain privileges by stealing the file before it has been processed. | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Cgiscript.net Cspassword | 4/10/2002 | 16/6/2026 | CGIScript.net csPassword.cgi leaks sensitive information such as the pathname of the server in debug messages that are presented when the script fails, which allows remote attackers to obtain the information via a "remove" option in the command parameter, which generates an error. | |
| Modificada | Alta (7.5) | 2.4% | — | Cgiscript.net Cspassword | 4/10/2002 | 16/6/2026 | CGIScript.net csPassword.cgi stores .htpasswd files under the web document root, which could allow remote authenticated users to download the file and crack the passwords of other users. | |
| Modificada | Alta (7.5) | 3.5% | — | Wordtrans-web | 4/10/2002 | 16/6/2026 | wordtrans 1.1pre8 y anteriores en el paquete wordtrans-web permite a atacantes remotos ejecutar código arbitrario o llevar a cabo ataques de guiones en sitios cruzados (cross-site scripting) mediante ciertos parámetros (posiblemente "dict") en el guión wordtrans.php. | |
| Modificada | Alta (7.5) | 3.1% | 💥 Exploit | Cgiscript.net Cspassword | 4/10/2002 | 16/6/2026 | CGIScript.net csPassword.cgi allows remote authenticated users to modify the .htaccess file and gain privileges via newlines in the title field of the edit page. | |
| Modificada | Alta (7.5) | 19% | — | Microsoft OutlookMicrosoft Word | 16/5/2002 | 16/6/2026 | Microsoft Outlook 2000 y 2002, cuando están configurados para usar Microsoft Word como editor de correo, no bloquea secuencias de comandos (scripts) en usjo mientras se editan mensajes en HTML o Formato de Texto Enriquecido (RTF), lo que podría permitir a atacantes remotos ejecutar scripts arbitrarios mediante un… | |
| Modificada | Media (5) | 3.7% | — | Nrl.navy One-time Passwords IN Everything | 31/12/2001 | 16/6/2026 | One-Time Passwords In Everything (a.k.a OPIE) 2.32 and 2.4 allows remote attackers to determine the existence of user accounts by printing random passphrases if the user account does not exist and static passphrases if the user account does exist. | |
| Modificada | Media (4.6) | 0.35% | — | Counterpane Password Safe | 13/9/2001 | 16/6/2026 | Password Safe 1.7(1) leaves cleartext passwords in memory when a user copies the password to the clipboard and minimizes Password Safe with the "Clear the password when minimized" and "Lock password database on minimize and prompt on restore" options enabled, which could allow an attacker with access to the memory… | |
| Modificada | Alta (7.2) | 2.2% | — | Microsoft Word | 14/8/2001 | 16/6/2026 | Microsoft Word 2000 does not check AutoRecovery (.asd) files for macros, which allows a local attacker to execute arbitrary macros with the user ID of the Word user. | |
| Modificada | Media (4.6) | 1.7% | — | Microsoft Word | 21/7/2001 | 16/6/2026 | Microsoft Word 2002 and earlier allows attackers to automatically execute macros without warning the user by embedding the macros in a manner that escapes detection by the security scanner. | |
| Modificada | Media (4.6) | 1.4% | — | Microsoft Word | 27/6/2001 | 16/6/2026 | Microsoft Word before Word 2002 allows attackers to automatically execute macros without warning the user via a Rich Text Format (RTF) document that links to a template with the embedded macro. | |
| Modificada | Alta (10) | 8.4% | — | Microsoft AccessMicrosoft Word | 20/10/2000 | 16/6/2026 | The Mail Merge tool in Microsoft Word does not prompt the user before executing Visual Basic (VBA) scripts in an Access database, which could allow an attacker to execute arbitrary commands. | |
| Modificada | Media (5.1) | 4.0% | — | Microsoft ExcelMicrosoft PowerpointMicrosoft Word | 20/10/2000 | 16/6/2026 | Buffer overflow in the HTML interpreter in Microsoft Office 2000 allows an attacker to execute arbitrary commands via a long embedded object tag, aka the "Microsoft Office HTML Object Tag" vulnerability. | |
| Modificada | Alta (7.5) | 21% | — | Microsoft AccessMicrosoft ExcelMicrosoft FrontpageMicrosoft Office+6 | 11/5/2000 | 16/6/2026 | The Office 2000 UA ActiveX Control is marked as "safe for scripting," which allows remote attackers to conduct unauthorized activities via the "Show Me" function in Office Help, aka the "Office 2000 UA Control" vulnerability. | |
| Modificada | Alta (7.2) | 1.9% | — | Microsoft OfficeMicrosoft Office Converter PackMicrosoft PowerpointMicrosoft Word | 20/1/2000 | 16/6/2026 | Buffer overflow in the conversion utilities for Japanese, Korean and Chinese Word 5 documents allows an attacker to execute commands, aka the "Malformed Conversion Data" vulnerability. | |
| Modificada | Alta (7.5) | 5.2% | — | Microsoft Internet ExplorerMicrosoft Word | 1/11/1999 | 16/6/2026 | Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the IE client through the Word 97 template, which doesn't warn the user that the template contains executable content. Also applies to Outlook when the client views a malicious email message. | |
| Modificada | Alta (10) | 1.6% | — | Quakenbush NT Password AppraiserAI | 1/1/1999 | 16/6/2026 | The demo version of the Quakenbush NT Password Appraiser sends passwords across the network in plaintext. | |
| Modificada | Baja (2.1) | 1.5% | — | Corel Wordperfect | 18/12/1998 | 16/6/2026 | Corel Word Perfect 8 for Linux creates a temporary working directory with world-writable permissions, which allows local users to (1) modify Word Perfect behavior by modifying files in the working directory, or (2) modify files of other users via a symlink attack. |