Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
2526 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 81% | ⚠ Explotación activa💥 PoC | Microsoft EdgeMicrosoft Internet Explorer | 11/3/2021 | 1/10/2026 | Internet Explorer Memory Corruption Vulnerability | |
| Modificada | Baja (2.4) | 0.27% | — | Samsung Internet | 4/3/2021 | 17/6/2026 | Improper permission grant check in Samsung Internet prior to version 13.0.1.60 allows access to files in internal storage without authorized STORAGE permission. | |
| Modificada | Alta (7.2) | 2.6% | — | Trendmicro Antivirus+ Security 2020Trendmicro Antivirus+ Security 2021Trendmicro Internet Security 2020Trendmicro Internet Security 2021+4 | 10/2/2021 | 17/6/2026 | The Trend Micro Security 2020 and 2021 families of consumer products are vulnerable to a code injection vulnerability which could allow an attacker to disable the program's password protection and disable protection. An attacker must already have administrator privileges on the machine to exploit this vulnerability. | |
| Modificada | Media (5.5) | 0.33% | — | Eset Endpoint AntivirusEset Endpoint SecurityEset File SecurityEset Internet Security+4 | 26/1/2021 | 17/6/2026 | A local (authenticated) low-privileged user can exploit a behavior in an ESET installer to achieve arbitrary file overwrite (deletion) of any file via a symlink, due to insecure permissions. The possibility of exploiting this vulnerability is limited and can only take place during the installation phase of ESET… | |
| Modificada | Alta (7.5) | 1.5% | — | IBM MQ Internet Pass-thru | 22/1/2021 | 17/6/2026 | IBM MQ Internet Pass-Thru 2.1 and 9.2 could allow a remote user to cause a denial of service by sending malformed MQ data requests which would consume all available resources. IBM X-Force ID: 188093. | |
| Modificada | Crítica (9.8) | 1.9% | — | Huorong Internet Security | 26/12/2020 | 17/6/2026 | Beijing Huorong Internet Security 5.0.55.2 allows a non-admin user to escalate privileges by injecting code into a process, and then waiting for a Huorong services restart or a system reboot. | |
| Modificada | Alta (7.8) | 0.57% | — | Trendmicro Antivirus+ Security 2020Trendmicro Internet Security 2020Trendmicro Maximum Security 2020Trendmicro Premium Security 2020 | 18/11/2020 | 17/6/2026 | Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placing a malicious DLL in a non-protected location with high privileges (symlink attack) which can lead to obtaining administrative privileges during the installation of the product. | |
| Modificada | Alta (7.8) | 0.47% | — | Trendmicro Antivirus+ Security 2020Trendmicro Internet Security 2020Trendmicro Maximum Security 2020Trendmicro Premium Security 2020 | 18/11/2020 | 17/6/2026 | Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placing a specific Windows system directory which can lead to obtaining administrative privileges during the installation of the product. | |
| Modificada | Alta (7.8) | 0.47% | — | Trendmicro Antivirus+ Security 2020Trendmicro Internet Security 2020Trendmicro Maximum Security 2020Trendmicro Premium Security 2020 | 18/11/2020 | 17/6/2026 | Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placing a malicious DLL in a local directory which can lead to obtaining administrative privileges during the installation of the product. | |
| Modificada | Alta (7.5) | 3.1% | — | Microsoft EdgeMicrosoft Internet Explorer | 11/11/2020 | 17/6/2026 | Microsoft Browser Memory Corruption Vulnerability | |
| Modificada | Alta (7.5) | 3.2% | — | Microsoft Internet Explorer | 11/11/2020 | 17/6/2026 | Internet Explorer Memory Corruption Vulnerability | |
| Modificada | Alta (8.1) | 2.7% | — | Microsoft Internet ExplorerMicrosoft Edge | 11/11/2020 | 17/6/2026 | Scripting Engine Memory Corruption Vulnerability | |
| Modificada | Media (6.3) | 0.30% | — | Trendmicro Antivirus+ 2020Trendmicro Internet Security 2020Trendmicro Maximum Security 2020Trendmicro Premium Security 2020 | 29/9/2020 | 17/6/2026 | The Trend Micro Security 2020 (v16) consumer family of products is vulnerable to a security race condition arbitrary file deletion vulnerability that could allow an unprivileged user to manipulate the product's secure erase feature to delete files with a higher set of privileges. | |
| Modificada | Alta (7.5) | 1.8% | — | Trendmicro Antivirus+ 2019Trendmicro Internet Security 2019Trendmicro Maximum Security 2019Trendmicro Officescan Cloud+1 | 24/9/2020 | 17/6/2026 | An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a malicious update instead of the expected one. CWE-295: Improper… | |
| Modificada | Alta (7.5) | 1.6% | — | Trendmicro Antivirus+ 2019Trendmicro Internet Security 2019Trendmicro Maximum Security 2019Trendmicro Officescan Cloud+1 | 24/9/2020 | 17/6/2026 | An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a malicious update instead of the expected one. CWE-494: Update files… | |
| Modificada | Alta (7.5) | 2.5% | — | Privateinternetaccess Private Internet Access VPN Client | 14/9/2020 | 17/6/2026 | A vulnerability in the Private Internet Access (PIA) VPN Client for Linux 1.5 through 2.3+ allows remote attackers to bypass an intended VPN kill switch mechanism and read sensitive information via intercepting network traffic. Since 1.5, PIA has supported a “split tunnel” OpenVPN bypass option. The PIA killswitch &… | |
| Modificada | Alta (8.8) | 2.1% | — | Microsoft Internet Explorer | 11/9/2020 | 17/6/2026 | <p>An elevation of privilege vulnerability exists in the way that the Wininit.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.</p> <p>There are multiple ways an attacker could exploit the vulnerability:</p> <ul> <li><p>In a web-based… | |
| Modificada | Alta (8.8) | 3.7% | — | Microsoft Internet Explorer | 11/9/2020 | 17/6/2026 | <p>An elevation of privilege vulnerability exists in the way that the Wininit.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.</p> <p>There are multiple ways an attacker could exploit the vulnerability:</p> <ul> <li><p>In a web-based… | |
| Analizada | Alta (7.5) | 2.7% | ⚠ Explotación activa | Microsoft Internet ExplorerMicrosoft EdgeMicrosoft Chakracore | 11/9/2020 | 17/6/2026 | <p>A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the… | |
| Modificada | Alta (7.5) | 8.8% | — | Microsoft Internet Explorer | 17/8/2020 | 17/6/2026 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the… | |
| Modificada | Alta (7.5) | 3.7% | — | Microsoft Internet Explorer | 17/8/2020 | 17/6/2026 | A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input. An attacker could execute arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take… | |
| Analizada | Alta (8.8) | 24% | ⚠ Explotación activa | Microsoft Internet Explorer | 17/8/2020 | 17/6/2026 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the… | |
| Modificada | Alta (8) | 0.81% | — | Swisscom Internet-box 2 FirmwareSwisscom Internet-box Standard FirmwareSwisscom Internet-box Plus FirmwareSwisscom Internet-box 3 Firmware+1 | 4/8/2020 | 17/6/2026 | An issue was discovered on Swisscom Internet Box 2, Internet Box Standard, Internet Box Plus prior to 10.04.38, Internet Box 3 prior to 11.01.20, and Internet Box light prior to 08.06.06. Given the (user-configurable) credentials for the local Web interface or physical access to a device's plus or reset button, an… | |
| Modificada | Alta (7.5) | 1.5% | — | Beronet Voice Over Internet Protocol Gateways Firmware | 29/7/2020 | 17/6/2026 | beroNet VoIP Gateways before 3.0.16 have a PHP script that allows downloading arbitrary files, including ones with credentials. | |
| Modificada | Alta (7.5) | 1.2% | — | Trendmicro Antivirus+ 2020Trendmicro Internet Security 2020Trendmicro Maximum Security 2020Trendmicro Premium Security 2020 | 15/7/2020 | 17/6/2026 | An invalid memory read vulnerability in a Trend Micro Secuity 2020 (v16.0.0.1302 and below) consumer family of products' driver could allow an attacker to manipulate the specific driver to do a system call operation with an invalid address, resulting in a potential system crash. |