Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 306 respecto a la semana anterior
Críticas / altas1347▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
147 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 6.4% | — | Microsoft ExcelMicrosoft Excel ViewerMicrosoft OfficeMicrosoft Office 365 Proplus+1 | 5/3/2019 | 17/6/2026 | An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information Disclosure Vulnerability'. | |
| Modificada | Media (5.5) | 13% | — | Microsoft Excel ViewerMicrosoft OfficeMicrosoft Office 365 ProplusMicrosoft Powerpoint Viewer+1 | 5/3/2019 | 17/6/2026 | A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft Office Security Feature Bypass Vulnerability'. | |
| Analizada | Alta (8.8) | 53% | ⚠ Explotación activa | Microsoft Internet ExplorerMicrosoft Excel ViewerMicrosoft OfficeMicrosoft Office 365 Proplus+1 | 8/1/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10,… | |
| Modificada | Media (5.5) | 8.6% | — | Microsoft ExcelMicrosoft Excel ViewerMicrosoft OfficeMicrosoft Office 365 Proplus+2 | 12/12/2018 | 17/6/2026 | An information disclosure vulnerability exists when Microsoft Excel software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Office, Office 365 ProPlus, Microsoft Excel, Microsoft… | |
| Modificada | Alta (7.8) | 19% | — | Microsoft ExcelMicrosoft Excel ViewerMicrosoft OfficeMicrosoft Office 365 Proplus+2 | 14/11/2018 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Office, Office 365 ProPlus, Microsoft Excel, Microsoft Excel Viewer, Excel. This CVE ID is unique from… | |
| Modificada | Alta (7.8) | 20% | — | Microsoft Excel ViewerMicrosoft OfficeMicrosoft Office 365 ProplusMicrosoft Office Compatibility Pack+6 | 10/10/2018 | 17/6/2026 | A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka "Microsoft Graphics Components Remote Code Execution Vulnerability." This affects Windows 7, Microsoft Office, Microsoft Office Word Viewer, Office 365 ProPlus, Microsoft Excel Viewer, Microsoft… | |
| Modificada | Media (5.5) | 2.3% | — | Microsoft Excel ViewerMicrosoft OfficeMicrosoft Office 365 ProplusMicrosoft Office Compatibility Pack+3 | 10/10/2018 | 17/6/2026 | An information disclosure vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka "Microsoft Graphics Components Information Disclosure Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Office 365 ProPlus, Windows Server 2008, Microsoft PowerPoint… | |
| Modificada | Media (5.5) | 12% | — | Microsoft ExcelMicrosoft Excel ViewerMicrosoft OfficeMicrosoft Office Compatibility Pack+1 | 13/9/2018 | 17/6/2026 | An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel. | |
| Modificada | Media (5.5) | 12% | — | Microsoft ExcelMicrosoft Excel 2013 RTMicrosoft Excel ViewerMicrosoft Office+1 | 15/8/2018 | 17/6/2026 | An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel. | |
| Modificada | Media (5.5) | 8.2% | — | Microsoft Excel ViewerMicrosoft OfficeMicrosoft Office Compatibility PackMicrosoft Office WEB Apps+5 | 15/8/2018 | 17/6/2026 | An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory, aka "Microsoft Office Information Disclosure Vulnerability." This affects Word, Microsoft SharePoint Server, Microsoft Office Word… | |
| Modificada | Alta (7.8) | 16% | — | Microsoft ExcelMicrosoft Excel ViewerMicrosoft OfficeMicrosoft Office Compatibility Pack | 15/8/2018 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel. This CVE ID is unique from CVE-2018-8379. | |
| Modificada | Media (5.5) | 19% | — | Microsoft ExcelMicrosoft Excel ViewerMicrosoft OfficeMicrosoft Office Compatibility Pack | 14/6/2018 | 17/6/2026 | An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel. | |
| Modificada | Alta (7.8) | 21% | — | Microsoft ExcelMicrosoft Excel ViewerMicrosoft Office Compatibility Pack | 12/4/2018 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel. This CVE ID is unique from CVE-2018-0920,… | |
| Modificada | Alta (8.8) | 23% | — | Microsoft ExcelMicrosoft Excel ViewerMicrosoft OfficeMicrosoft Office Compatibility Pack | 10/1/2018 | 17/6/2026 | Microsoft Excel in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Excel Remote Code Execution Vulnerability". | |
| Modificada | Alta (7.8) | 6.2% | — | Microsoft ExcelMicrosoft Excel ViewerMicrosoft Office Compatibility Pack | 15/11/2017 | 17/6/2026 | Microsoft Excel 2007 Service Pack 3, Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Microsoft Excel 2013 RT Service Pack 1, Microsoft Excel 2016, Microsoft Office Compatibility Pack Service Pack 3, and Microsoft Excel Viewer 2007 Service Pack 3 allow an attacker to run arbitrary code in the… | |
| Modificada | Media (5.5) | 4.5% | — | Microsoft ExcelMicrosoft Excel ViewerMicrosoft Office Compatibility Pack | 15/11/2017 | 17/6/2026 | Microsoft Excel 2007 Service Pack 3, Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Microsoft Excel 2013 RT Service Pack 1, Microsoft Excel 2016, Microsoft Office Compatibility Pack Service Pack 3, Microsoft Excel Viewer 2007 Service Pack 3, and Microsoft Excel 2016 for Mac allow a security… | |
| Modificada | Alta (7.8) | 17% | — | Microsoft ExcelMicrosoft Excel ViewerMicrosoft Excel WEB APPMicrosoft Office Compatibility Pack+2 | 13/9/2017 | 17/6/2026 | A remote code execution vulnerability exists in Excel Services, Microsoft Excel 2007 Service Pack 3, Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Microsoft Excel 2013 RT Service Pack 1, Microsoft Excel 2016, Microsoft Office Web Apps 2013, Microsoft Office Compatibility Pack Service Pack… | |
| Modificada | Alta (7.8) | 23% | — | Microsoft ExcelMicrosoft Excel ViewerMicrosoft OfficeMicrosoft Office Compatibility Pack+2 | 11/7/2017 | 17/6/2026 | Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8502. | |
| Modificada | Alta (7.8) | 17% | — | Microsoft ExcelMicrosoft Excel ViewerMicrosoft Office Compatibility PackMicrosoft Sharepoint Server | 17/3/2017 | 17/6/2026 | Microsoft Office Compatibility Pack SP3, Excel 2007 SP3, Excel Viewer, and Excel Services on SharePoint Server 2007 SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." This vulnerability is… | |
| Modificada | Alta (7.8) | 17% | — | Microsoft ExcelMicrosoft Excel ViewerMicrosoft Office Compatibility PackMicrosoft Sharepoint Server | 17/3/2017 | 17/6/2026 | Microsoft Excel 2007 SP3, Office Compatibility Pack SP3, Excel Viewer, and Excel Services on SharePoint Server 2007 SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." This vulnerability is… | |
| Modificada | Alta (7.8) | 22% | — | Microsoft ExcelMicrosoft Excel FOR MACMicrosoft Excel ViewerMicrosoft Office Compatibility Pack | 20/12/2016 | 17/6/2026 | Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, Excel Viewer, and Excel 2016 for Mac mishandle a registry check, which allows user-assisted remote attackers to execute arbitrary commands via crafted embedded content in a document, aka "Microsoft… | |
| Modificada | Alta (7.1) | 23% | — | Microsoft ExcelMicrosoft Excel ViewerMicrosoft Office Compatibility PackMicrosoft Sharepoint Server | 20/12/2016 | 17/6/2026 | Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, Excel Viewer, Excel Services on SharePoint Server 2007 SP3, and Excel Services on SharePoint Server 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a… | |
| Modificada | Alta (7.1) | 23% | — | Microsoft ExcelMicrosoft Excel FOR MACMicrosoft Excel ViewerMicrosoft Office Compatibility Pack | 20/12/2016 | 17/6/2026 | Microsoft Excel 2007 SP3, Office Compatibility Pack SP3, Excel Viewer, Excel for Mac 2011, and Excel 2016 for Mac allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted document, aka "Microsoft Office Information Disclosure… | |
| Analizada | Alta (7.8) | 58% | ⚠ Explotación activa | Microsoft ExcelMicrosoft Excel ViewerMicrosoft Office Compatibility Pack | 20/12/2016 | 17/6/2026 | Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-assisted remote attackers to execute arbitrary commands via a crafted cell that is mishandled upon a click, aka "Microsoft Office Security Feature Bypass Vulnerability." | |
| Modificada | Alta (7.8) | 19% | — | Microsoft ExcelMicrosoft Excel FOR MACMicrosoft Excel ViewerMicrosoft Office Compatibility Pack | 10/11/2016 | 17/6/2026 | Microsoft Excel 2007 SP3, Excel for Mac 2011, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability." |