Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

467 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.50%—Mcafee Data Exchange Layer17/2/202017/6/2026
Unquoted service executable path in DXL Broker in McAfee Data eXchange Layer (DXL) Framework 6.0.0 and earlier allows local users to cause a denial of service and malicious file execution via carefully crafted and named executable files.
ModificadaMedia (5.5)1.4%—Avira Antivir MailgateAvira Antivir Mailgate SuiteAvira Antivir PersonalAvira Antivir Sharepoint+612/2/202016/6/2026
A Denial of Service (infinite loop) vulnerability exists in Avira AntiVir Engine before 8.2.12.58 via an unspecified function in the PDF Scanner Engine.
ModificadaAlta (8.1)3.3%—Microsoft Exchange Server11/2/202017/6/2026
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'.
AnalizadaAlta (8.8)100%⚠ Explotación activa💥 ExploitMicrosoft Exchange Server11/2/202017/6/2026
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.
ModificadaAlta (7.5)2.3%—Mozilla NSSDebian LinuxRedhat Enterprise LinuxSuse Linux Enterprise Server+2315/11/201917/6/2026
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.
ModificadaMedia (4.5)0.75%—Mcafee Threat Intelligence Exchange Server13/11/201917/6/2026
Abuse of Authorization vulnerability in APIs exposed by TIE server in McAfee Threat Intelligence Exchange Server (TIE Server) 3.0.0 allows remote authenticated users to modify stored reputation data via specially crafted messages.
ModificadaCrítica (9.8)22%—Microsoft Exchange Server12/11/201917/6/2026
A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Microsoft Exchange Remote Code Execution Vulnerability'.
ModificadaAlta (7.5)2.0%—Medtronic Valleylab Exchange ClientMedtronic Valleylab Ft10 Energy Platform FirmwareMedtronic Valleylab FX8 Energy Platform Firmware8/11/201917/6/2026
Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab FX8 Energy Platform (VLFX8GEN) software version 1.1.0 and below use multiple sets of hard-coded credentials. If discovered, they can be used to read files on the device.
ModificadaAlta (7.8)0.27%—Medtronic Valleylab Exchange ClientMedtronic Valleylab Ft10 Energy Platform FirmwareMedtronic Valleylab FX8 Energy Platform Firmware8/11/201917/6/2026
Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab FX8 Energy Platform (VLFX8GEN) software version 1.1.0 and below use the descrypt algorithm for OS password hashing. While interactive, network-based logons are disabled,…
ModificadaMedia (6.5)1.7%—Dell Bsafe Cert-jDell Bsafe Crypto-jDell Bsafe Ssl-jMcafee Threat Intelligence Exchange Server+1218/9/201917/6/2026
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A malicious remote attacker could potentially exploit this vulnerability to coerce two parties into computing the same predictable shared key.
ModificadaMedia (6.1)2.0%—Microsoft Exchange Server11/9/201917/6/2026
A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web App (OWA) fails to properly handle web requests, aka 'Microsoft Exchange Spoofing Vulnerability'.
ModificadaAlta (7.5)6.2%—Microsoft Exchange Server11/9/201917/6/2026
A denial of service vulnerability exists in Microsoft Exchange Server software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Denial of Service Vulnerability'.
ModificadaMedia (6.1)0.95%—Ithemes Exchange28/8/201917/6/2026
iThemes Exchange before 1.12.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
ModificadaCrítica (9.9)0.91%—Tibco API Exchange Gateway8/8/201917/6/2026
The authorization component of TIBCO Software Inc.'s TIBCO API Exchange Gateway, and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric contains a vulnerability that theoretically processes OAuth authorization incorrectly, leading to potential escalation of privileges for the specific customer endpoint,…
ModificadaMedia (5.4)1.6%—Microsoft Exchange Server15/7/201917/6/2026
A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted web request to an affected Exchange server, aka 'Microsoft Exchange Server Spoofing Vulnerability'.
ModificadaAlta (8.1)3.4%—Microsoft Exchange Server15/7/201917/6/2026
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'.
ModificadaMedia (6.5)5.3%—Microsoft Exchange ServerMicrosoft LyncMicrosoft Lync BasicMicrosoft Mail AND Calendar+515/7/201917/6/2026
An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security…
ModificadaMedia (5.5)1.3%—Sound Exchange Project Sound Exchange15/7/201917/6/2026
SoX - Sound eXchange 14.4.2 and earlier is affected by: Out-of-bounds Read. The impact is: Denial of Service. The component is: read_samples function at xa.c:219. The attack vector is: Victim must open specially crafted .xa file. NOTE: this may overlap CVE-2017-18189.
ModificadaMedia (5.5)1.1%—Sound Exchange Project Sound Exchange14/7/201917/6/2026
An issue was discovered in libsox.a in SoX 14.4.2. In sox-fmt.h (startread function), there is an integer overflow on the result of integer addition (wraparound to 0) fed into the lsx_calloc macro that wraps malloc. When a NULL pointer is returned, it is used without a prior check that it is a valid pointer, leading…
ModificadaMedia (4.4)0.24%—Mcafee Data Exchange LayerMcafee Threat Intelligence Exchange10/4/201917/6/2026
Information Disclosure vulnerability in McAfee DXL Platform and TIE Server in DXL prior to 5.0.1 HF2 and TIE prior to 2.3.1 HF1 allows Authenticated users to view sensitive information in plain text via the GUI or command line.
ModificadaMedia (6.1)2.1%—Microsoft Exchange Server9/4/201917/6/2026
A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests, aka 'Microsoft Exchange Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0817.
ModificadaMedia (5.4)2.3%—Microsoft Exchange Server9/4/201917/6/2026
A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests, aka 'Microsoft Exchange Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0858.
ModificadaAlta (8.1)24%—Microsoft Exchange Server5/3/201917/6/2026
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0686.
ModificadaAlta (7.4)5.0%—Microsoft Exchange Server5/3/201917/6/2026
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0724.
ModificadaMedia (5.9)17%—OpensslCanonical Ubuntu LinuxDebian LinuxNetapp Active IQ Unified Manager+7827/2/201917/6/2026
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid…
Orbitaley — Vulnerabilidades