Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
204 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| En análisis | Alta (7.5) | 0.35% | — | Microsoft Office OutlookAI | 25/9/2026 | 29/9/2026 | Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | |
| En análisis | Alta (8.8) | 0.44% | — | Microsoft OutlookAI | 23/9/2026 | 30/9/2026 | Microsoft Office Outlook Remote Code Execution Vulnerability | |
| Analizada | Media (6.5) | 0.92% | — | Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Office 2024+1 | 8/9/2026 | 9/9/2026 | Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Office 2024+1 | 8/9/2026 | 9/9/2026 | Use of uninitialized resource in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Office 2024+1 | 8/9/2026 | 9/9/2026 | Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Office 2024+1 | 11/8/2026 | 14/8/2026 | Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | |
| Analizada | Media (4.3) | 0.67% | — | Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Office 2024+1 | 11/8/2026 | 14/8/2026 | Insufficiently protected credentials in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. | |
| Aplazada | Media (5.3) | 0.32% | — | Simple Google Calendar Outlook Events WidgetAI | 4/8/2026 | 26/8/2026 | The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL before performing a server-side request, allowing unauthenticated attackers to perform Server-Side Request Forgery attacks and, in some cases, read the response of the internal request. | |
| Aplazada | Media (6.5) | 0.16% | — | HCL Traveler FOR Microsoft OutlookAI | 17/7/2026 | 17/7/2026 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content. | |
| Analizada | Alta (7.8) | 0.27% | — | Hcltech Traveler FOR Microsoft Outlook | 27/6/2026 | 6/7/2026 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of service. Since .NET Framework 4.5 has reached end-of-life and no longer receives security updates, it may expose the application to publicly known security weaknesses through vulnerable third-party… | |
| Analizada | Media (5.5) | 0.15% | — | Hcltech Traveler FOR Microsoft Outlook | 27/6/2026 | 29/9/2026 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a sensitive data exposure vulnerability which could allow an attacker to exploit application information to then attempt additional attacks and cause unknown behavior in the application. | |
| Analizada | Alta (7.8) | 0.09% | — | Hcltech Traveler FOR Microsoft Outlook | 26/6/2026 | 1/10/2026 | The HCL Traveler for Microsoft Outlook libraries are being flagged as potentially malicious software or an unrecognized application. | |
| Analizada | Alta (7.5) | 0.71% | — | Microsoft Outlook | 12/5/2026 | 17/6/2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network. | |
| Modificada | Alta (7.1) | 0.54% | — | Microsoft 365 CopilotMicrosoft EdgeMicrosoft ExcelMicrosoft Loop+6 | 16/3/2026 | 17/6/2026 | AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. | |
| Aplazada | Media (6.9) | 0.12% | — | Outlook Password RecoveryAI | 11/3/2026 | 17/6/2026 | Outlook Password Recovery 2.10 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload. Attackers can create a malicious text file containing 6000 bytes of data and paste it into the User Name and Registration Code field to trigger a denial of… | |
| Aplazada | Media (4.6) | 0.42% | — | SpotoutlookAI | 11/2/2026 | 17/6/2026 | SpotOutlook 1.2.6 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can overwrite the buffer by pasting 1000 'A' characters into the 'Name' field, causing the application to become unresponsive. | |
| Analizada | Alta (7.5) | 1.5% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Outlook+1 | 10/2/2026 | 17/6/2026 | Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. | |
| Analizada | Media (5.5) | 0.16% | — | Hcltech Traveler FOR Microsoft Outlook | 16/10/2025 | 1/10/2026 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakage which could allow an attacker to access other computers or applications. | |
| Analizada | Alta (7) | 0.35% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Outlook+2 | 8/7/2025 | 17/6/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (6.7) | 1.7% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Outlook | 10/6/2025 | 17/6/2026 | Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally. | |
| Analizada | Crítica (9.8) | 0.27% | — | Hcltech Traveler FOR Microsoft Outlook | 30/5/2025 | 17/6/2026 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content. | |
| Analizada | Crítica (9.8) | 0.27% | — | Hcltech Traveler FOR Microsoft Outlook | 30/5/2025 | 17/6/2026 | HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content. | |
| Analizada | Alta (7.5) | 1.5% | — | Microsoft Outlook | 8/4/2025 | 17/6/2026 | Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (5.3) | 1.2% | — | Microsoft Outlook | 11/2/2025 | 17/6/2026 | Microsoft Outlook Spoofing Vulnerability | |
| Analizada | Alta (7.8) | 0.75% | — | Microsoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Outlook | 14/1/2025 | 17/6/2026 | Microsoft Outlook Remote Code Execution Vulnerability |