Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
467 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 1.6% | — | Sound Exchange Project Sound Exchange | 15/2/2019 | 17/6/2026 | An issue was discovered in SoX 14.4.2. lsx_make_lpf in effect_i_dsp.c allows a NULL pointer dereference. | |
| Modificada | Media (5.5) | 1.8% | — | Sound Exchange Project Sound Exchange | 15/2/2019 | 17/6/2026 | An issue was discovered in SoX 14.4.2. One of the arguments to bitrv2 in fft4g.c is not guarded, such that it can lead to write access outside of the statically declared array, aka a stack-based buffer overflow. | |
| Modificada | Media (5.5) | 1.7% | — | Sound Exchange Project Sound Exchange | 15/2/2019 | 17/6/2026 | An issue was discovered in SoX 14.4.2. In xmalloc.h, there is an integer overflow on the result of multiplication fed into the lsx_valloc macro that wraps malloc. When the buffer is allocated, it is smaller than expected, leading to a heap-based buffer overflow in channels_start in remix.c. | |
| Modificada | Media (5) | 1.6% | — | Sound Exchange Project Sound ExchangeDebian LinuxCanonical Ubuntu Linux | 15/2/2019 | 17/6/2026 | An issue was discovered in SoX 14.4.2. lsx_make_lpf in effect_i_dsp.c has an integer overflow on the result of multiplication fed into malloc. When the buffer is allocated, it is smaller than expected, leading to a heap-based buffer overflow. | |
| Modificada | Media (6.5) | 4.6% | — | Microsoft Exchange Server | 8/1/2019 | 17/6/2026 | An information disclosure vulnerability exists when the Microsoft Exchange PowerShell API grants calendar contributors more view permissions than intended, aka "Microsoft Exchange Information Disclosure Vulnerability." This affects Microsoft Exchange Server. | |
| Modificada | Crítica (9.8) | 15% | — | Microsoft Exchange Server | 8/1/2019 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server. | |
| Modificada | Media (4.3) | 2.4% | — | Microsoft Exchange Server | 12/12/2018 | 17/6/2026 | A tampering vulnerability exists when Microsoft Exchange Server fails to properly handle profile data, aka "Microsoft Exchange Server Tampering Vulnerability." This affects Microsoft Exchange Server. | |
| Analizada | Alta (7.4) | 27% | ⚠ Explotación activa💥 PoC | Microsoft Exchange Server | 14/11/2018 | 17/6/2026 | An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server. | |
| Modificada | Media (5.4) | 3.2% | — | Microsoft Exchange Server | 10/10/2018 | 17/6/2026 | An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server. | |
| Modificada | Alta (7.8) | 19% | — | Microsoft Exchange Server | 10/10/2018 | 17/6/2026 | A remote code execution vulnerability exists in the way Microsoft Exchange software parses specially crafted email messages, aka "Microsoft Exchange Remote Code Execution Vulnerability." This affects Microsoft Exchange Server. | |
| Modificada | Media (5.9) | 0.70% | — | Mcafee Threat Intelligence Exchange Server | 3/10/2018 | 17/6/2026 | SSH host keys generation vulnerability in the server in McAfee Threat Intelligence Exchange Server (TIE Server) 1.3.0, 2.0.x, 2.1.x, 2.2.0 allows man-in-the-middle attackers to spoof servers via acquiring keys from another environment. | |
| Modificada | Crítica (9.8) | 1.8% | — | Viabtc Exchange Server | 26/9/2018 | 17/6/2026 | utils/ut_ws_svr.c in ViaBTC Exchange Server before 2018-08-21 has an integer overflow leading to memory corruption. | |
| Modificada | Crítica (9.8) | 1.7% | — | Viabtc Exchange Server | 26/9/2018 | 17/6/2026 | network/nw_buf.c in ViaBTC Exchange Server before 2018-08-21 has an integer overflow leading to memory corruption. | |
| Modificada | Crítica (9.8) | 1.8% | — | Viabtc Exchange Server | 26/9/2018 | 17/6/2026 | utils/ut_rpc.c in ViaBTC Exchange Server before 2018-08-21 has an integer overflow leading to memory corruption. | |
| Modificada | Alta (8.6) | 11% | — | Microsoft Exchange Server | 21/9/2018 | 17/6/2026 | Rollup 18 for Microsoft Exchange Server 2010 SP3 and previous versions has an SSRF vulnerability via the username parameter in /owa/auth/logon.aspx in the OWA (Outlook Web Access) login page. | |
| Modificada | Media (5.9) | 3.0% | — | Ietf Internet KEY Exchange | 6/9/2018 | 17/6/2026 | The Internet Key Exchange v1 main mode is vulnerable to offline dictionary or brute force attacks. Reusing a key pair across different versions and modes of IKE could lead to cross-protocol authentication bypasses. It is well known, that the aggressive mode of IKEv1 PSK is vulnerable to offline dictionary or brute… | |
| Modificada | Media (4.3) | 3.0% | — | Microsoft Exchange Server | 15/8/2018 | 17/6/2026 | A tampering vulnerability exists when Microsoft Exchange Server fails to properly handle profile data, aka "Microsoft Exchange Server Tampering Vulnerability." This affects Microsoft Exchange Server. | |
| Modificada | Crítica (9.8) | 26% | — | Microsoft Exchange Server | 15/8/2018 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server. | |
| Modificada | Alta (7.5) | 0.99% | — | Stex Exchange ICO Project Stex Exchange ICO | 5/7/2018 | 17/6/2026 | The sell function of a smart contract implementation for STeX Exchange ICO (STE), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets. | |
| Modificada | Alta (7.5) | 0.92% | — | Carbonexchangecointoken Project Carbonexchangecointoken | 3/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for Carbon Exchange Coin Token (CEC), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Crítica (9.8) | 1.6% | — | Mcafee Threat Intelligence Exchange | 13/6/2018 | 17/6/2026 | Code Injection vulnerability in the ePolicy Orchestrator (ePO) extension in McAfee Threat Intelligence Exchange (TIE) Server 2.1.0 and earlier allows remote attackers to execute arbitrary HTML code to be reflected in the response web page via unspecified vector. | |
| Modificada | Media (5.4) | 3.6% | — | Microsoft Exchange Server | 9/5/2018 | 17/6/2026 | An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server. | |
| Modificada | Crítica (9.8) | 24% | — | Microsoft Exchange Server | 9/5/2018 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server. This CVE ID is unique from CVE-2018-8151. | |
| Modificada | Media (5.4) | 3.5% | — | Microsoft Exchange Server | 9/5/2018 | 17/6/2026 | A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Spoofing Vulnerability." This affects Microsoft Exchange Server. | |
| Modificada | Media (5.4) | 3.6% | — | Microsoft Exchange Server | 9/5/2018 | 17/6/2026 | An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server. |