Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

1900 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)9.8%—Microsoft ChakracoreMicrosoft Internet ExplorerMicrosoft Edge8/4/201917/6/2026
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0639, CVE-2019-0680, CVE-2019-0769, CVE-2019-0770, CVE-2019-0771, CVE-2019-0773, CVE-2019-0783.
ModificadaMedia (6.1)1.5%—Ericsson Active Library Explorer21/3/201917/6/2026
XSS exists in Ericsson Active Library Explorer (ALEX) 14.3 in multiple parameters in the "/cgi-bin/alexserv" servlet, as demonstrated by the DB, FN, fn, or id parameter.
AnalizadaMedia (6.5)8.1%⚠ Explotación activaMicrosoft Internet Explorer5/3/201917/6/2026
An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited this vulnerability could test for the presence of files on disk, aka 'Internet Explorer Information Disclosure Vulnerability'.
ModificadaMedia (4.3)2.8%—Microsoft Internet ExplorerMicrosoft Edge5/3/201917/6/2026
A spoofing vulnerability exists when Microsoft browsers improperly handles specific redirects, aka 'Microsoft Browser Spoofing Vulnerability'.
ModificadaAlta (7.5)11%—Microsoft Internet Explorer5/3/201917/6/2026
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'.
ModificadaMedia (4.2)0.39%—Estrongs ES File Explorer File Manager15/2/201917/6/2026
The Help feature in the ES File Explorer File Manager application 4.1.9.7.4 for Android allows session hijacking by a Man-in-the-middle attacker on the local network because HTTPS is not used, and an attacker's web site is displayed in a WebView with no information about the URL.
ModificadaMedia (6.5)0.79%—Draeger Kappa FirmwareDraeger Infinity Explorer C700 FirmwareDraeger Delta XL FirmwareDraeger Infinity Delta Firmware28/1/201917/6/2026
Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. Log files are accessible over an unauthenticated network connection. By accessing the log files, an attacker is able to gain insights about internals of the patient monitor, the…
ModificadaMedia (6.5)0.77%—Draeger Kappa FirmwareDraeger Infinity Explorer C700 FirmwareDraeger Delta XL FirmwareDraeger Infinity Delta Firmware28/1/201917/6/2026
Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. A malformed network packet may cause the monitor to reboot. By repeatedly sending the malformed network packet, an attacker may be able to disrupt patient monitoring by causing the…
ModificadaAlta (7.8)0.39%—Draeger Kappa FirmwareDraeger Infinity Explorer C700 FirmwareDraeger Delta XL FirmwareDraeger Infinity Delta Firmware28/1/201917/6/2026
Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. Via a specific dialog it is possible to break out of the kiosk mode and reach the underlying operating system. By breaking out of the kiosk mode, an attacker is able to take…
ModificadaAlta (8.1)64%💥 ExploitEstrongs ES File Explorer File Manager16/1/201917/6/2026
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary files or execute applications via TCP port 59777 requests on the local Wi-Fi network. This TCP port remains open after the ES application has been launched once, and responds to unauthenticated…
AnalizadaAlta (8.8)53%⚠ Explotación activa💥 ExploitMicrosoft Internet ExplorerMicrosoft Excel ViewerMicrosoft OfficeMicrosoft Office 365 Proplus+18/1/201917/6/2026
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10,…
AnalizadaAlta (7.5)30%⚠ Explotación activaMicrosoft Internet Explorer20/12/201817/6/2026
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8643.
ModificadaAlta (7.5)9.9%—Microsoft Internet Explorer12/12/201817/6/2026
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.
ModificadaAlta (7.5)68%💥 ExploitMicrosoft Internet Explorer12/12/201817/6/2026
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.
ModificadaAlta (7.5)44%💥 ExploitMicrosoft Internet Explorer12/12/201817/6/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.
ModificadaAlta (7.5)45%💥 ExploitMicrosoft Internet Explorer12/12/201817/6/2026
A remote code execution vulnerability exists when the Internet Explorer VBScript execution policy does not properly restrict VBScript under specific conditions, aka "Internet Explorer Remote Code Execution Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.
ModificadaAlta (7.5)14%—Microsoft Internet Explorer14/11/201817/6/2026
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 11.
ModificadaAlta (7.5)51%💥 ExploitMicrosoft Internet Explorer14/11/201817/6/2026
An information disclosure vulnerability exists when VBScript improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user's computer or data, aka "Windows Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet…
ModificadaAlta (7.5)13%—Microsoft Internet Explorer10/10/201817/6/2026
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 11. This CVE ID is unique from CVE-2018-8460.
ModificadaAlta (7.5)21%—Microsoft Internet Explorer10/10/201817/6/2026
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 11. This CVE ID is unique from CVE-2018-8491.
ModificadaMedia (6.1)2.3%—Zohocorp Manageengine Assetexplorer2/10/201817/6/2026
In Zoho ManageEngine AssetExplorer, a Stored XSS vulnerability was discovered in the 6.2.0 version via the /AssetDef.do ciName or assetName parameter.
ModificadaMedia (6.1)3.3%—Microsoft Internet Explorer13/9/201817/6/2026
A security feature bypass vulnerability exists in Internet Explorer due to how scripts are handled that allows a universal cross-site scripting (UXSS) condition, aka "Internet Explorer Security Feature Bypass Vulnerability." This affects Internet Explorer 11.
ModificadaAlta (7.5)13%—Microsoft Internet Explorer13/9/201817/6/2026
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 11. This CVE ID is unique from CVE-2018-8447.
ModificadaAlta (7.5)13%—Microsoft Internet ExplorerMicrosoft Edge13/9/201817/6/2026
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 11, Microsoft Edge, Internet Explorer 10. This CVE ID is unique from CVE-2018-8354, CVE-2018-8391,…
ModificadaMedia (4.3)5.6%—Microsoft Internet ExplorerMicrosoft ChakracoreMicrosoft Edge13/9/201817/6/2026
An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft browsers, aka "Scripting Engine Information Disclosure Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge.