Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
95 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.92% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office 2021+3 | 14/7/2026 | 15/7/2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | |
| Aplazada | Media (6.4) | 0.27% | — | Miniorange Wordpress Office 365 Azure AD LoginAI | 23/5/2024 | 17/6/2026 | The WordPress + Microsoft Office 365 / Azure AD | LOGIN plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pintra' shortcode in all versions up to, and including, 27.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modificada | Media (6.1) | 0.34% | — | Wpo365 Mail Integration FOR Office 365 / Outlook | 23/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPO365 | Mail Integration for Office 365 / Outlook plugin <= 1.9.0 versions. | |
| Modificada | Media (6.1) | 0.97% | — | Wpo365 Wordpress + Azure AD / Microsoft Office 365 | 19/11/2021 | 17/6/2026 | The “WPO365 | LOGIN” WordPress plugin (up to and including version 15.3) by wpo365.com is vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability (also known as Stored or Second-Order XSS). Persistent XSS vulnerabilities occur when the application stores and retrieves client supplied data without proper… | |
| Modificada | Alta (7.5) | 2.1% | — | Wpo365 Wordpress + Azure AD / Microsoft Office 365 | 2/10/2020 | 17/6/2026 | The wpo365-login plugin before v11.7 for WordPress allows use of a symmetric algorithm to decrypt a JWT token. This leads to authentication bypass. | |
| Modificada | Alta (7.8) | 12% | — | Microsoft OfficeMicrosoft Office 365 Proplus | 15/4/2020 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka 'Microsoft Office Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0760. | |
| Modificada | Alta (7.8) | 12% | — | Microsoft OfficeMicrosoft Office 365 ProplusMicrosoft Office Online ServerMicrosoft Office WEB Apps+3 | 15/4/2020 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. | |
| Modificada | Alta (8.8) | 12% | — | Microsoft Office 365 Proplus | 15/4/2020 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0906. | |
| Modificada | Alta (7.8) | 12% | — | Microsoft OfficeMicrosoft Office 365 Proplus | 15/4/2020 | 17/6/2026 | A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. | |
| Modificada | Alta (8.8) | 12% | — | Microsoft ExcelMicrosoft OfficeMicrosoft Office 365 Proplus | 15/4/2020 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0979. | |
| Modificada | Alta (8.8) | 8.8% | — | Microsoft AccessMicrosoft ExcelMicrosoft OfficeMicrosoft Office 365 Proplus+6 | 15/4/2020 | 17/6/2026 | A remote code execution vulnerability exists when Microsoft Office improperly loads arbitrary type libraries, aka 'Microsoft Office Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0991. | |
| Modificada | Alta (7.8) | 12% | — | Microsoft OfficeMicrosoft Office 365 ProplusMicrosoft Office Online ServerMicrosoft Office WEB Apps+4 | 12/3/2020 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0850, CVE-2020-0851, CVE-2020-0852, CVE-2020-0855. | |
| Modificada | Alta (7.8) | 12% | — | Microsoft OfficeMicrosoft Office 365 Proplus | 12/3/2020 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0850, CVE-2020-0851, CVE-2020-0852, CVE-2020-0892. | |
| Modificada | Alta (7.8) | 12% | — | Microsoft OfficeMicrosoft Office 365 Proplus | 12/3/2020 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0850, CVE-2020-0852, CVE-2020-0855, CVE-2020-0892. | |
| Modificada | Alta (8.8) | 8.8% | — | Microsoft OfficeMicrosoft Office 365 ProplusMicrosoft Office Online ServerMicrosoft Sharepoint Enterprise Server+3 | 12/3/2020 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0851, CVE-2020-0852, CVE-2020-0855, CVE-2020-0892. | |
| Modificada | Alta (8.8) | 15% | — | Microsoft ExcelMicrosoft Office 365 Proplus | 11/2/2020 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. | |
| Modificada | Alta (7.8) | 0.90% | — | Microsoft Office 365 Proplus | 11/2/2020 | 17/6/2026 | An elevation of privilege vulnerability exists in Microsoft Office OLicenseHeartbeat task, where an attacker who successfully exploited this vulnerability could run this task as SYSTEM.To exploit the vulnerability, an authenticated attacker would need to place a specially crafted file in a specific location, thereby… | |
| Modificada | Media (6.5) | 5.0% | — | Microsoft OfficeMicrosoft Office 365 ProplusMicrosoft Outlook | 11/2/2020 | 17/6/2026 | A security feature bypass vulnerability exists in Microsoft Outlook software when it improperly handles the parsing of URI formats, aka 'Microsoft Outlook Security Feature Bypass Vulnerability'. | |
| Modificada | Alta (7.8) | 21% | — | Microsoft Office 365 Proplus | 14/1/2020 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0650, CVE-2020-0651. | |
| Modificada | Alta (7.8) | 17% | — | Microsoft ExcelMicrosoft Office 365 Proplus | 14/1/2020 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka 'Microsoft Office Memory Corruption Vulnerability'. | |
| Modificada | Alta (7.8) | 17% | — | Microsoft ExcelMicrosoft Office 365 Proplus | 14/1/2020 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0650, CVE-2020-0653. | |
| Modificada | Alta (7.8) | 17% | — | Microsoft ExcelMicrosoft Office 365 Proplus | 14/1/2020 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0651, CVE-2020-0653. | |
| Modificada | Media (5.5) | 8.7% | — | Microsoft ExcelMicrosoft OfficeMicrosoft Office 365 Proplus | 10/12/2019 | 17/6/2026 | An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information Disclosure Vulnerability'. | |
| Modificada | Media (5.5) | 2.3% | — | Microsoft OfficeMicrosoft Office 365 Proplus | 10/12/2019 | 17/6/2026 | An information disclosure vulnerability exists in Microsoft Access software when the software fails to properly handle objects in memory, aka 'Microsoft Access Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1400. | |
| Modificada | Alta (7.8) | 18% | — | Microsoft OfficeMicrosoft Office 365 ProplusMicrosoft Powerpoint | 10/12/2019 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka 'Microsoft PowerPoint Remote Code Execution Vulnerability'. |