Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2544▼ 345 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
135 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.6) | 0.29% | — | Office Powerpoint MCP ServerAI | 1/10/2026 | 2/10/2026 | Office-PowerPoint-MCP-Server through 2.0.7 contains a path traversal vulnerability that allows MCP callers to write and read files outside the working directory by supplying absolute paths or ../ sequences. Attackers can steer an AI agent via prompt injection to abuse save_presentation, open_presentation, or… | |
| Analizada | Media (5.5) | 0.54% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 8/9/2026 | 17/9/2026 | Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | |
| Analizada | Media (6.5) | 0.97% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 8/9/2026 | 17/9/2026 | Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (6.5) | 0.92% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 8/9/2026 | 17/9/2026 | Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 8/9/2026 | 17/9/2026 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 8/9/2026 | 17/9/2026 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 8/9/2026 | 17/9/2026 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network. | |
| Analizada | Media (5.5) | 0.43% | — | Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Office 2024+1 | 11/8/2026 | 14/8/2026 | Incomplete cleanup in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 14/7/2026 | 16/7/2026 | Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 14/7/2026 | 15/7/2026 | Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2019Microsoft Office 2021+2 | 14/7/2026 | 16/7/2026 | Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.1) | 0.44% | — | Microsoft ExcelMicrosoft PowerpointMicrosoft Word | 9/6/2026 | 23/7/2026 | Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft ExcelMicrosoft PowerpointMicrosoft WordMicrosoft Windows 10 1607+12 | 9/6/2026 | 23/7/2026 | Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft ExcelMicrosoft PowerpointMicrosoft WordMicrosoft Windows 10 1607+12 | 9/6/2026 | 23/7/2026 | Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (5.5) | 0.31% | — | Microsoft Powerpoint | 12/5/2026 | 17/6/2026 | Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Powerpoint | 14/4/2026 | 17/6/2026 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | |
| Modificada | Alta (7.1) | 0.54% | — | Microsoft 365 CopilotMicrosoft EdgeMicrosoft ExcelMicrosoft Loop+6 | 16/3/2026 | 17/6/2026 | AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (7.8) | 0.38% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Powerpoint | 14/10/2025 | 17/6/2026 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.60% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Powerpoint | 9/9/2025 | 17/6/2026 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.52% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Powerpoint | 12/8/2025 | 17/6/2026 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.41% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Powerpoint | 8/7/2025 | 17/6/2026 | Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7) | 0.35% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Outlook+2 | 8/7/2025 | 17/6/2026 | Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 2.4% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Powerpoint | 10/6/2025 | 17/6/2026 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | |
| Analizada | Crítica (9.1) | 0.89% | — | Microsoft Powerpoint | 18/12/2024 | 17/6/2026 | A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can leverage PowerPoint's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and then make use of the… | |
| Analizada | Alta (7.8) | 0.93% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Powerpoint | 13/8/2024 | 17/6/2026 | Microsoft PowerPoint Remote Code Execution Vulnerability |