Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
742 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 15% | — | Microsoft Windows 7Microsoft Windows Server 2003Microsoft Windows VistaMicrosoft Windows XP | 20/2/2020 | 16/6/2026 | The IPv6 implementation in Microsoft Windows 7 and earlier allows remote attackers to cause a denial of service via a flood of ICMPv6 Router Advertisement packets containing multiple Routing entries. | |
| Modificada | Alta (7.5) | 15% | — | Microsoft Windows 7Microsoft Windows Server 2003Microsoft Windows VistaMicrosoft Windows XP | 20/2/2020 | 16/6/2026 | The IPv6 implementation in Microsoft Windows 7 and earlier allows remote attackers to cause a denial of service via a flood of ICMPv6 Neighbor Solicitation messages, a different vulnerability than CVE-2010-4669. | |
| Modificada | Alta (7.5) | 8.3% | — | Microsoft Windows XP | 10/12/2019 | 17/6/2026 | An information disclosure vulnerability exists when the Windows Remote Desktop Protocol (RDP) fails to properly handle objects in memory, aka 'Remote Desktop Protocol Information Disclosure Vulnerability'. | |
| Modificada | Alta (8.1) | 46% | — | Microsoft Windows Server 2003Microsoft Windows XP | 22/6/2017 | 17/6/2026 | A buffer overflow in Smart Card authentication code in gpkcsp.dll in Microsoft Windows XP through SP3 and Server 2003 through SP2 allows a remote attacker to execute arbitrary code on the target computer, provided that the computer is joined in a Windows domain and has Remote Desktop Protocol connectivity (or Terminal… | |
| Modificada | Alta (7.8) | 54% | 💥 Exploit | Microsoft Windows Server 2003Microsoft Windows XP | 15/6/2017 | 17/6/2026 | Windows OLE in Windows XP and Windows Server 2003 allows an attacker to execute code when a victim opens a specially crafted file or program aka "Windows olecnv32.dll Remote Code Execution Vulnerability." | |
| Modificada | Alta (7.8) | 20% | 💥 Exploit | Microsoft Windows Server 2003Microsoft Windows XP | 15/6/2017 | 17/6/2026 | Windows RPC with Routing and Remote Access enabled in Windows XP and Windows Server 2003 allows an attacker to execute code on a targeted RPC server which has Routing and Remote Access enabled via a specially crafted application, aka "Windows RPC Remote Code Execution Vulnerability." | |
| Modificada | Alta (7.2) | 23% | 💥 Exploit | Microsoft Windows XP | 26/7/2014 | 17/6/2026 | Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write data to arbitrary memory locations, and consequently gain privileges, via a crafted address in an IOCTL call, related to (1) the MQAC.sys driver in the MQ Access Control subsystem and (2) the… | |
| Modificada | Media (6.9) | 15% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+6 | 8/4/2014 | 17/6/2026 | Untrusted search path vulnerability in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a Trojan horse cmd.exe… | |
| Modificada | Media (6.6) | 2.9% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+6 | 12/3/2014 | 17/6/2026 | win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to obtain sensitive information from kernel… | |
| Modificada | Media (5.4) | 10% | — | Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Server 2012Microsoft Windows Vista+1 | 12/3/2014 | 17/6/2026 | The Security Account Manager Remote (SAMR) protocol implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows Server 2012 Gold and R2 does not properly determine the user-lockout state, which makes it easier for remote attackers to… | |
| Modificada | Alta (9.3) | 14% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows Server 2003+4 | 12/3/2014 | 17/6/2026 | Double free vulnerability in qedit.dll in DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via a crafted JPEG… | |
| Modificada | Alta (7.2) | 1.6% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+6 | 12/3/2014 | 17/6/2026 | win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application,… | |
| Modificada | Alta (7.1) | 19% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+6 | 12/2/2014 | 17/6/2026 | The XMLHTTP ActiveX controls in XML Core Services 3.0 in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to bypass the Same Origin… | |
| Modificada | Media (6.9) | 2.8% | 💥 Exploit | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+6 | 11/12/2013 | 16/6/2026 | Integer overflow in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows local users to gain privileges via a crafted application, aka "Win32k… | |
| Modificada | Alta (9.3) | 20% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+6 | 11/12/2013 | 16/6/2026 | Use-after-free vulnerability in the Scripting Runtime Object Library in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to… | |
| Modificada | Alta (7.2) | 2.3% | — | Microsoft Windows Server 2003Microsoft Windows XP | 11/12/2013 | 16/6/2026 | win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate addresses, which allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Vulnerability." | |
| Modificada | Media (6.9) | 1.7% | — | Microsoft Windows Server 2003Microsoft Windows XP | 11/12/2013 | 16/6/2026 | Stack-based buffer overflow in the LRPC client in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges by operating an LRPC server that sends a crafted LPC port message, aka "LRPC Client Buffer Overrun Vulnerability." | |
| Analizada | Alta (7.8) | 35% | ⚠ Explotación activa💥 Exploit | Microsoft Windows 2003 ServerMicrosoft Windows XP | 28/11/2013 | 16/6/2026 | NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in November 2013. | |
| Modificada | Alta (7.1) | 4.8% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+6 | 18/11/2013 | 16/6/2026 | DirectAccess in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly verify server X.509 certificates, which allows… | |
| Modificada | Alta (9.3) | 34% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+6 | 13/11/2013 | 16/6/2026 | Integer overflow in the Graphics Device Interface (GDI) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary… | |
| Modificada | Media (4.9) | 2.6% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows Server 2003Microsoft Windows Server 2008+3 | 13/11/2013 | 16/6/2026 | The Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 allows local users to obtain sensitive information from kernel memory by leveraging… | |
| Modificada | Media (5) | 17% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+6 | 13/11/2013 | 16/6/2026 | Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to cause a denial of service (daemon hang) via a web-service request containing a… | |
| Analizada | Alta (8.8) | 74% | ⚠ Explotación activa💥 Exploit | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+6 | 12/11/2013 | 16/6/2026 | The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to… | |
| Modificada | Alta (8.1) | 43% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows RTMicrosoft Windows Server 2003+4 | 9/10/2013 | 16/6/2026 | The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allow remote attackers to execute arbitrary code via a crafted CMAP table in a TrueType font (TTF) file, aka… | |
| Modificada | Alta (7.2) | 1.8% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows RTMicrosoft Windows Server 2003+4 | 9/10/2013 | 16/6/2026 | Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application, aka… |