Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3060▲ 560 respecto a la semana anterior
Críticas / altas1458▲ 280 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
2563 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (7.6) | — | — | Office Powerpoint MCP ServerAI | 1/10/2026 | 1/10/2026 | Office-PowerPoint-MCP-Server through 2.0.7 contains a path traversal vulnerability that allows MCP callers to write and read files outside the working directory by supplying absolute paths or ../ sequences. Attackers can steer an AI agent via prompt injection to abuse save_presentation, open_presentation, or… | |
| Pendiente de análisis | Alta (7.5) | 0.35% | — | Microsoft Office OutlookAI | 25/9/2026 | 29/9/2026 | Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | |
| Externa | Sin puntuar | — | — | Microsoft OfficeAI | 25/9/2026 | — | Microsoft Office vulnerability that allows information disclosure. The vulnerability was addressed by updates released in July 2026, though the CVE was inadvertently omitted from the initial security bulletin. This is an informational update for tracking purposes. | |
| Pendiente de análisis | Crítica (9.8) | 0.96% | — | Onlyoffice Document EditingAI | 25/9/2026 | 29/9/2026 | When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zimbra. | |
| Aplazada | Media (5.4) | 0.17% | — | LibreofficeAI | 22/9/2026 | 22/9/2026 | LibreOffice can import PICT images, which may be embedded in documents. An out of bounds read existed when importing an image that uses a colour palette. The palette index held in the image data was used without being checked against the number of entries the palette has, so an index past the last entry read memory… | |
| Aplazada | Media (5.4) | 0.17% | — | LibreofficeAI | 22/9/2026 | 22/9/2026 | LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens when a document is exported to PDF, and CFF fonts may be embedded in documents. A stack buffer overflow existed in that conversion. The converted operators were written into a fixed size buffer with no check that they still fit, so a glyph… | |
| Aplazada | Media (5.4) | 0.17% | — | LibreofficeAI | 22/9/2026 | 22/9/2026 | LibreOffice can read CFF fonts, which may be embedded in documents. A stack buffer overflow existed when reading the hints of a glyph. The number of hints was checked against the wrong bound, so a glyph declaring more hints than the array can hold wrote past its end. In fixed versions the hint count is checked against… | |
| Aplazada | Media (5.4) | 0.17% | — | Libreoffice DrawAI | 22/9/2026 | 22/9/2026 | LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing a stream object. The length of the stream was taken from the object's own dictionary and was not checked against the number of bytes actually present, so copying the stream read and wrote past the end of the buffer holding it. In… | |
| Aplazada | Media (5.4) | 0.11% | — | Libreoffice DrawAI | 22/9/2026 | 22/9/2026 | LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing an encrypted document. The length of the decryption key was taken from the document's own encryption dictionary and was used to fill a fixed size key buffer without being checked against it, so a length larger than that buffer… | |
| Aplazada | Media (5.4) | 0.17% | — | LibreofficeAI | 22/9/2026 | 22/9/2026 | LibreOffice can import WMF graphics, which may be embedded in documents. A heap buffer overflow existed when importing a text record that carries its own character advance widths. The count of advance values and the length of the text were read separately from the file and were not required to agree, so drawing the… | |
| Pendiente de análisis | Alta (8.8) | 0.08% | — | Crowdstrike Falcon SensorAICrowdstrike Laroux Malware Cleanup ToolAIMicrosoft OfficeAI | 15/9/2026 | 18/9/2026 | CrowdStrike released a security update to address a vulnerability in the Falcon sensor for Windows. The vulnerability only exists when the Microsoft Office File Malicious Macro Removal Windows policy setting is enabled and customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings.… | |
| Aplazada | Baja (2) | 0.33% | — | Fengoffice Feng OfficeAI | 13/9/2026 | 14/9/2026 | A vulnerability was determined in Fengoffice Feng Office up to 3.11.13.11. Affected by this vulnerability is the function getTitle of the file application/views/task/add_task.php of the component Task Title Output. Executing a manipulation of the argument og_objects.name can lead to cross site scripting. The attack… | |
| Aplazada | Baja (2) | 0.33% | — | Fengoffice Feng OfficeAI | 13/9/2026 | 16/9/2026 | A vulnerability was found in Fengoffice Feng Office up to 3.11.13.11. Affected is the function update_system_module_order/update_dimension_order of the file application/controllers/MoreController.class.php of the component Reorder Handlers. Performing a manipulation of the argument modules/dims results in sql… | |
| Aplazada | Media (5.5) | 0.41% | — | Fengoffice Feng OfficeAI | 13/9/2026 | 14/9/2026 | A vulnerability has been found in Fengoffice Feng Office up to 3.11.13.11. This impacts the function Contacts::instance->findAll of the file application/models/CompanyWebsite.class.php of the component Legacy API. Such manipulation of the argument auth leads to sql injection. The attack can be launched remotely. The… | |
| Analizada | Media (5.5) | 0.54% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2016+3 | 8/9/2026 | 17/9/2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | |
| Analizada | Media (5.5) | 0.54% | — | Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Office 2024+1 | 8/9/2026 | 8/9/2026 | Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |
| Analizada | Media (5.5) | 0.54% | — | Microsoft 365 AppsMicrosoft Office 2019Microsoft Office 2021Microsoft Office 2024+1 | 8/9/2026 | 8/9/2026 | Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2016+3 | 8/9/2026 | 17/9/2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2016+3 | 8/9/2026 | 17/9/2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Media (5.5) | 0.54% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2016+3 | 8/9/2026 | 17/9/2026 | Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2016+3 | 8/9/2026 | 17/9/2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2016+4 | 8/9/2026 | 17/9/2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2016+3 | 8/9/2026 | 17/9/2026 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft 365Microsoft Office 2016+3 | 8/9/2026 | 17/9/2026 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft 365 AppsMicrosoft 365Microsoft Office 2016Microsoft Office 2019+2 | 8/9/2026 | 17/9/2026 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. |