Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3060▲ 560 respecto a la semana anterior
Críticas / altas1458▲ 280 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

2563 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaAlta (7.6)——Office Powerpoint MCP ServerAI1/10/20261/10/2026
Office-PowerPoint-MCP-Server through 2.0.7 contains a path traversal vulnerability that allows MCP callers to write and read files outside the working directory by supplying absolute paths or ../ sequences. Attackers can steer an AI agent via prompt injection to abuse save_presentation, open_presentation, or…
Pendiente de análisisAlta (7.5)0.35%—Microsoft Office OutlookAI25/9/202629/9/2026
Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
ExternaSin puntuar——Microsoft OfficeAI25/9/2026—
Microsoft Office vulnerability that allows information disclosure. The vulnerability was addressed by updates released in July 2026, though the CVE was inadvertently omitted from the initial security bulletin. This is an informational update for tracking purposes.
Pendiente de análisisCrítica (9.8)0.96%—Onlyoffice Document EditingAI25/9/202629/9/2026
When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zimbra.
AplazadaMedia (5.4)0.17%—LibreofficeAI22/9/202622/9/2026
LibreOffice can import PICT images, which may be embedded in documents. An out of bounds read existed when importing an image that uses a colour palette. The palette index held in the image data was used without being checked against the number of entries the palette has, so an index past the last entry read memory…
AplazadaMedia (5.4)0.17%—LibreofficeAI22/9/202622/9/2026
LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens when a document is exported to PDF, and CFF fonts may be embedded in documents. A stack buffer overflow existed in that conversion. The converted operators were written into a fixed size buffer with no check that they still fit, so a glyph…
AplazadaMedia (5.4)0.17%—LibreofficeAI22/9/202622/9/2026
LibreOffice can read CFF fonts, which may be embedded in documents. A stack buffer overflow existed when reading the hints of a glyph. The number of hints was checked against the wrong bound, so a glyph declaring more hints than the array can hold wrote past its end. In fixed versions the hint count is checked against…
AplazadaMedia (5.4)0.17%—Libreoffice DrawAI22/9/202622/9/2026
LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing a stream object. The length of the stream was taken from the object's own dictionary and was not checked against the number of bytes actually present, so copying the stream read and wrote past the end of the buffer holding it. In…
AplazadaMedia (5.4)0.11%—Libreoffice DrawAI22/9/202622/9/2026
LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing an encrypted document. The length of the decryption key was taken from the document's own encryption dictionary and was used to fill a fixed size key buffer without being checked against it, so a length larger than that buffer…
AplazadaMedia (5.4)0.17%—LibreofficeAI22/9/202622/9/2026
LibreOffice can import WMF graphics, which may be embedded in documents. A heap buffer overflow existed when importing a text record that carries its own character advance widths. The count of advance values and the length of the text were read separately from the file and were not required to agree, so drawing the…
Pendiente de análisisAlta (8.8)0.08%—Crowdstrike Falcon SensorAICrowdstrike Laroux Malware Cleanup ToolAIMicrosoft OfficeAI15/9/202618/9/2026
CrowdStrike released a security update to address a vulnerability in the Falcon sensor for Windows. The vulnerability only exists when the Microsoft Office File Malicious Macro Removal Windows policy setting is enabled and customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings.…
AplazadaBaja (2)0.33%—Fengoffice Feng OfficeAI13/9/202614/9/2026
A vulnerability was determined in Fengoffice Feng Office up to 3.11.13.11. Affected by this vulnerability is the function getTitle of the file application/views/task/add_task.php of the component Task Title Output. Executing a manipulation of the argument og_objects.name can lead to cross site scripting. The attack…
AplazadaBaja (2)0.33%—Fengoffice Feng OfficeAI13/9/202616/9/2026
A vulnerability was found in Fengoffice Feng Office up to 3.11.13.11. Affected is the function update_system_module_order/update_dimension_order of the file application/controllers/MoreController.class.php of the component Reorder Handlers. Performing a manipulation of the argument modules/dims results in sql…
AplazadaMedia (5.5)0.41%—Fengoffice Feng OfficeAI13/9/202614/9/2026
A vulnerability has been found in Fengoffice Feng Office up to 3.11.13.11. This impacts the function Contacts::instance->findAll of the file application/models/CompanyWebsite.class.php of the component Legacy API. Such manipulation of the argument auth leads to sql injection. The attack can be launched remotely. The…
AnalizadaMedia (5.5)0.54%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2016+38/9/202617/9/2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
AnalizadaMedia (5.5)0.54%—Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Office 2024+18/9/20268/9/2026
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
AnalizadaMedia (5.5)0.54%—Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Office 2024+18/9/20268/9/2026
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2016+38/9/202617/9/2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2016+38/9/202617/9/2026
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaMedia (5.5)0.54%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2016+38/9/202617/9/2026
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2016+38/9/202617/9/2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2016+48/9/202617/9/2026
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2016+38/9/202617/9/2026
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.47%—Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2016+38/9/202617/9/2026
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
AnalizadaAlta (8.8)0.82%—Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+28/9/202617/9/2026
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.