Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2727▼ 513 respecto a la semana anterior
Críticas / altas1294▼ 200 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
283 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 5.9% | — | Microsoft Windows NT | 1/1/1999 | 16/6/2026 | Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service. | |
| Modificada | Alta (10) | 5.9% | — | Microsoft Windows NT | 1/1/1999 | 16/6/2026 | A system-critical Windows NT file or directory has inappropriate permissions. | |
| Modificada | Alta (10) | 3.2% | — | Microsoft Windows NTAI | 1/1/1999 | 16/6/2026 | A Windows NT account policy does not forcibly disconnect remote users from the server when their logon hours expire. | |
| Modificada | Alta (10) | 1.9% | — | Microsoft Windows NTAI | 1/1/1999 | 16/6/2026 | An event log in Windows NT has inappropriate access permissions. | |
| Modificada | Alta (10) | 6.1% | — | Microsoft Windows NT | 1/1/1999 | 16/6/2026 | Windows NT is not using a password filter utility, e.g. PASSFILT.DLL. | |
| Modificada | Media (4.6) | 1.5% | — | Microsoft Windows NT | 1/1/1999 | 16/6/2026 | A Windows NT system's registry audit policy does not log an event success or failure for security-critical registry keys. | |
| Modificada | Media (4.6) | 1.2% | — | Microsoft OfficeMicrosoft OutlookMicrosoft ProjectMicrosoft Visual Basic+2 | 1/1/1999 | 16/6/2026 | The Forms 2.0 ActiveX control (included with Visual Basic for Applications 5.0) can be used to read text from a user's clipboard when the user accesses documents with ActiveX content. | |
| Modificada | Alta (10) | 6.2% | — | Microsoft Windows NT | 1/1/1999 | 16/6/2026 | A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories. | |
| Modificada | Media (4.9) | 2.2% | — | Microsoft Windows NT | 1/1/1999 | 16/6/2026 | The default setting for the Winlogon key entry ShutdownWithoutLogon in Windows NT allows users with physical access to shut down a Windows NT system without logging in. | |
| Modificada | Alta (10) | 1.9% | — | Microsoft Windows NTAI | 1/1/1999 | 16/6/2026 | A system-critical Windows NT registry key has an inappropriate value. | |
| Modificada | Alta (10) | 1.9% | — | Microsoft Windows NTAI | 1/1/1999 | 16/6/2026 | A system-critical Windows NT registry key has inappropriate permissions. | |
| Modificada | Alta (7.2) | 1.8% | — | Microsoft Windows NT | 1/1/1999 | 16/6/2026 | Windows NT automatically logs in an administrator upon rebooting. | |
| Modificada | Alta (10) | 1.9% | — | Microsoft Windows NTAI | 1/1/1999 | 16/6/2026 | A Windows NT system does not restrict access to removable media drives such as a floppy disk drive or CDROM drive. | |
| Modificada | Alta (10) | 1.9% | — | Microsoft Windows NTAI | 1/1/1999 | 16/6/2026 | A Windows NT log file has an inappropriate maximum size or retention period. | |
| Modificada | Alta (10) | 1.6% | — | Windows NT FTP ServerAI | 1/1/1999 | 16/6/2026 | Windows NT FTP server (WFTP) with the guest account enabled without a password allows an attacker to log into the FTP server using any username and password. | |
| Modificada | Media (5) | 13% | — | Microsoft Windows 95Microsoft Windows NT | 5/10/1998 | 16/6/2026 | TCP/IP implementation in Microsoft Windows 95, Windows NT 4.0, and possibly others, allows remote attackers to reset connections by forcing a reset (RST) via a PSH ACK or other means, obtaining the target's last sequence number from the resulting packet, then spoofing a reset to the target. | |
| Modificada | Media (4.6) | 1.7% | — | Microsoft Windows NT | 1/10/1998 | 16/6/2026 | The Windows NT guest account is enabled. | |
| Modificada | Alta (7.2) | 17% | — | Microsoft Windows 2000Microsoft Windows NT | 1/10/1998 | 16/6/2026 | A Windows NT domain user or administrator account has a default, null, blank, or missing password. | |
| Modificada | Alta (7.2) | 1.8% | — | Microsoft Windows 2000Microsoft Windows NT | 1/10/1998 | 16/6/2026 | A Windows NT domain user or administrator account has a guessable password. | |
| Modificada | Media (5) | 13% | — | Microsoft Windows NT | 29/9/1998 | 16/6/2026 | The Windows NT RPC service allows remote attackers to conduct a denial of service using spoofed malformed RPC packets which generate an error message that is sent to the spoofed host, potentially setting up a loop, aka Snork. | |
| Modificada | Media (5) | 21% | 💥 Exploit | Microsoft Windows NT | 1/8/1998 | 16/6/2026 | The WINS server in Microsoft Windows NT 4.0 before SP4 allows remote attackers to cause a denial of service (process termination) via invalid UDP frames to port 137 (NETBIOS Name Service), as demonstrated via a flood of random packets. | |
| Modificada | Alta (7.2) | 1.4% | — | Microsoft Windows NT | 1/8/1998 | 16/6/2026 | NT users can gain debug-level access on a system process using the Sechole exploit. | |
| Modificada | Media (5) | 65% | 💥 Exploit | Microsoft Internet Information ServerMicrosoft Windows NT | 1/6/1998 | 16/6/2026 | In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL. | |
| Modificada | Media (6.4) | 8.6% | — | Microsoft Windows NT | 9/5/1998 | 16/6/2026 | Windows NT 3.51 and 4.0 running WINS (Windows Internet Name Service) allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed packets, which causes the server to slow down and fill the event logs with error messages. | |
| Modificada | Media (5) | 18% | — | Microsoft Windows NT | 14/2/1998 | 16/6/2026 | Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed SMB logon request in which the actual data size does not match the specified size. |