Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

204 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
En análisisAlta (7.5)0.35%—Microsoft Office OutlookAI25/9/202629/9/2026
Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
En análisisAlta (8.8)0.44%—Microsoft OutlookAI23/9/202630/9/2026
Microsoft Office Outlook Remote Code Execution Vulnerability
AnalizadaMedia (6.5)0.92%—Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Office 2024+18/9/20269/9/2026
Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (8.8)0.82%—Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Office 2024+18/9/20269/9/2026
Use of uninitialized resource in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.82%—Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Office 2024+18/9/20269/9/2026
Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.82%—Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Office 2024+111/8/202614/8/2026
Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
AnalizadaMedia (4.3)0.67%—Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Office 2024+111/8/202614/8/2026
Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
AplazadaMedia (5.3)0.32%—Simple Google Calendar Outlook Events WidgetAI4/8/202626/8/2026
The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL before performing a server-side request, allowing unauthenticated attackers to perform Server-Side Request Forgery attacks and, in some cases, read the response of the internal request.
AplazadaMedia (6.5)0.16%—HCL Traveler FOR Microsoft OutlookAI17/7/202617/7/2026
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.
AnalizadaAlta (7.8)0.27%—Hcltech Traveler FOR Microsoft Outlook27/6/20266/7/2026
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of service. Since .NET Framework 4.5 has reached end-of-life and no longer receives security updates, it may expose the application to publicly known security weaknesses through vulnerable third-party…
AnalizadaMedia (5.5)0.15%—Hcltech Traveler FOR Microsoft Outlook27/6/202629/9/2026
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a sensitive data exposure vulnerability which could allow an attacker to exploit application information to then attempt additional attacks and cause unknown behavior in the application.
AnalizadaAlta (7.8)0.09%—Hcltech Traveler FOR Microsoft Outlook26/6/20261/10/2026
The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized application.
AnalizadaAlta (7.5)0.71%—Microsoft Outlook12/5/202617/6/2026
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network.
ModificadaAlta (7.1)0.54%—Microsoft 365 CopilotMicrosoft EdgeMicrosoft ExcelMicrosoft Loop+616/3/202617/6/2026
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
AplazadaMedia (6.9)0.12%—Outlook Password RecoveryAI11/3/202617/6/2026
Outlook Password Recovery 2.10 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload. Attackers can create a malicious text file containing 6000 bytes of data and paste it into the User Name and Registration Code field to trigger a denial of…
AplazadaMedia (4.6)0.42%—SpotoutlookAI11/2/202617/6/2026
SpotOutlook 1.2.6 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can overwrite the buffer by pasting 1000 'A' characters into the 'Name' field, causing the application to become unresponsive.
AnalizadaAlta (7.5)1.5%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Outlook+110/2/202617/6/2026
Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
AnalizadaMedia (5.5)0.16%—Hcltech Traveler FOR Microsoft Outlook16/10/20251/10/2026
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage which could allow an attacker to access other computers or applications.
AnalizadaAlta (7)0.35%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Outlook+28/7/202517/6/2026
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
AnalizadaMedia (6.7)1.7%—Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Outlook10/6/202517/6/2026
Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally.
AnalizadaCrítica (9.8)0.27%—Hcltech Traveler FOR Microsoft Outlook30/5/202517/6/2026
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.
AnalizadaCrítica (9.8)0.27%—Hcltech Traveler FOR Microsoft Outlook30/5/202517/6/2026
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.
AnalizadaAlta (7.5)1.5%—Microsoft Outlook8/4/202517/6/2026
Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a network.
AnalizadaMedia (5.3)1.2%—Microsoft Outlook11/2/202517/6/2026
Microsoft Outlook Spoofing Vulnerability
AnalizadaAlta (7.8)0.75%—Microsoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Outlook14/1/202517/6/2026
Microsoft Outlook Remote Code Execution Vulnerability