Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

2526 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)81%⚠ Explotación activa💥 PoCMicrosoft EdgeMicrosoft Internet Explorer11/3/20211/10/2026
Internet Explorer Memory Corruption Vulnerability
ModificadaBaja (2.4)0.27%—Samsung Internet4/3/202117/6/2026
Improper permission grant check in Samsung Internet prior to version 13.0.1.60 allows access to files in internal storage without authorized STORAGE permission.
ModificadaAlta (7.2)2.6%—Trendmicro Antivirus+ Security 2020Trendmicro Antivirus+ Security 2021Trendmicro Internet Security 2020Trendmicro Internet Security 2021+410/2/202117/6/2026
The Trend Micro Security 2020 and 2021 families of consumer products are vulnerable to a code injection vulnerability which could allow an attacker to disable the program's password protection and disable protection. An attacker must already have administrator privileges on the machine to exploit this vulnerability.
ModificadaMedia (5.5)0.33%—Eset Endpoint AntivirusEset Endpoint SecurityEset File SecurityEset Internet Security+426/1/202117/6/2026
A local (authenticated) low-privileged user can exploit a behavior in an ESET installer to achieve arbitrary file overwrite (deletion) of any file via a symlink, due to insecure permissions. The possibility of exploiting this vulnerability is limited and can only take place during the installation phase of ESET…
ModificadaAlta (7.5)1.5%—IBM MQ Internet Pass-thru22/1/202117/6/2026
IBM MQ Internet Pass-Thru 2.1 and 9.2 could allow a remote user to cause a denial of service by sending malformed MQ data requests which would consume all available resources. IBM X-Force ID: 188093.
ModificadaCrítica (9.8)1.9%—Huorong Internet Security26/12/202017/6/2026
Beijing Huorong Internet Security 5.0.55.2 allows a non-admin user to escalate privileges by injecting code into a process, and then waiting for a Huorong services restart or a system reboot.
ModificadaAlta (7.8)0.57%—Trendmicro Antivirus+ Security 2020Trendmicro Internet Security 2020Trendmicro Maximum Security 2020Trendmicro Premium Security 202018/11/202017/6/2026
Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placing a malicious DLL in a non-protected location with high privileges (symlink attack) which can lead to obtaining administrative privileges during the installation of the product.
ModificadaAlta (7.8)0.47%—Trendmicro Antivirus+ Security 2020Trendmicro Internet Security 2020Trendmicro Maximum Security 2020Trendmicro Premium Security 202018/11/202017/6/2026
Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placing a specific Windows system directory which can lead to obtaining administrative privileges during the installation of the product.
ModificadaAlta (7.8)0.47%—Trendmicro Antivirus+ Security 2020Trendmicro Internet Security 2020Trendmicro Maximum Security 2020Trendmicro Premium Security 202018/11/202017/6/2026
Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placing a malicious DLL in a local directory which can lead to obtaining administrative privileges during the installation of the product.
ModificadaAlta (7.5)3.1%—Microsoft EdgeMicrosoft Internet Explorer11/11/202017/6/2026
Microsoft Browser Memory Corruption Vulnerability
ModificadaAlta (7.5)3.2%—Microsoft Internet Explorer11/11/202017/6/2026
Internet Explorer Memory Corruption Vulnerability
ModificadaAlta (8.1)2.7%—Microsoft Internet ExplorerMicrosoft Edge11/11/202017/6/2026
Scripting Engine Memory Corruption Vulnerability
ModificadaMedia (6.3)0.30%—Trendmicro Antivirus+ 2020Trendmicro Internet Security 2020Trendmicro Maximum Security 2020Trendmicro Premium Security 202029/9/202017/6/2026
The Trend Micro Security 2020 (v16) consumer family of products is vulnerable to a security race condition arbitrary file deletion vulnerability that could allow an unprivileged user to manipulate the product's secure erase feature to delete files with a higher set of privileges.
ModificadaAlta (7.5)1.8%—Trendmicro Antivirus+ 2019Trendmicro Internet Security 2019Trendmicro Maximum Security 2019Trendmicro Officescan Cloud+124/9/202017/6/2026
An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a malicious update instead of the expected one. CWE-295: Improper…
ModificadaAlta (7.5)1.6%—Trendmicro Antivirus+ 2019Trendmicro Internet Security 2019Trendmicro Maximum Security 2019Trendmicro Officescan Cloud+124/9/202017/6/2026
An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a malicious update instead of the expected one. CWE-494: Update files…
ModificadaAlta (7.5)2.5%—Privateinternetaccess Private Internet Access VPN Client14/9/202017/6/2026
A vulnerability in the Private Internet Access (PIA) VPN Client for Linux 1.5 through 2.3+ allows remote attackers to bypass an intended VPN kill switch mechanism and read sensitive information via intercepting network traffic. Since 1.5, PIA has supported a “split tunnel” OpenVPN bypass option. The PIA killswitch &…
ModificadaAlta (8.8)2.1%—Microsoft Internet Explorer11/9/202017/6/2026
<p>An elevation of privilege vulnerability exists in the way that the Wininit.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.</p> <p>There are multiple ways an attacker could exploit the vulnerability:</p> <ul> <li><p>In a web-based…
ModificadaAlta (8.8)3.7%—Microsoft Internet Explorer11/9/202017/6/2026
<p>An elevation of privilege vulnerability exists in the way that the Wininit.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.</p> <p>There are multiple ways an attacker could exploit the vulnerability:</p> <ul> <li><p>In a web-based…
AnalizadaAlta (7.5)2.7%⚠ Explotación activaMicrosoft Internet ExplorerMicrosoft EdgeMicrosoft Chakracore11/9/202017/6/2026
<p>A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the…
ModificadaAlta (7.5)8.8%—Microsoft Internet Explorer17/8/202017/6/2026
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the…
ModificadaAlta (7.5)3.7%—Microsoft Internet Explorer17/8/202017/6/2026
A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input. An attacker could execute arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take…
AnalizadaAlta (8.8)24%⚠ Explotación activaMicrosoft Internet Explorer17/8/202017/6/2026
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the…
ModificadaAlta (8)0.81%—Swisscom Internet-box 2 FirmwareSwisscom Internet-box Standard FirmwareSwisscom Internet-box Plus FirmwareSwisscom Internet-box 3 Firmware+14/8/202017/6/2026
An issue was discovered on Swisscom Internet Box 2, Internet Box Standard, Internet Box Plus prior to 10.04.38, Internet Box 3 prior to 11.01.20, and Internet Box light prior to 08.06.06. Given the (user-configurable) credentials for the local Web interface or physical access to a device's plus or reset button, an…
ModificadaAlta (7.5)1.5%—Beronet Voice Over Internet Protocol Gateways Firmware29/7/202017/6/2026
beroNet VoIP Gateways before 3.0.16 have a PHP script that allows downloading arbitrary files, including ones with credentials.
ModificadaAlta (7.5)1.2%—Trendmicro Antivirus+ 2020Trendmicro Internet Security 2020Trendmicro Maximum Security 2020Trendmicro Premium Security 202015/7/202017/6/2026
An invalid memory read vulnerability in a Trend Micro Secuity 2020 (v16.0.0.1302 and below) consumer family of products' driver could allow an attacker to manipulate the specific driver to do a system call operation with an invalid address, resulting in a potential system crash.