Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
1900 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 9.8% | — | Microsoft ChakracoreMicrosoft Internet ExplorerMicrosoft Edge | 8/4/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0639, CVE-2019-0680, CVE-2019-0769, CVE-2019-0770, CVE-2019-0771, CVE-2019-0773, CVE-2019-0783. | |
| Modificada | Media (6.1) | 1.5% | — | Ericsson Active Library Explorer | 21/3/2019 | 17/6/2026 | XSS exists in Ericsson Active Library Explorer (ALEX) 14.3 in multiple parameters in the "/cgi-bin/alexserv" servlet, as demonstrated by the DB, FN, fn, or id parameter. | |
| Analizada | Media (6.5) | 8.1% | ⚠ Explotación activa | Microsoft Internet Explorer | 5/3/2019 | 17/6/2026 | An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited this vulnerability could test for the presence of files on disk, aka 'Internet Explorer Information Disclosure Vulnerability'. | |
| Modificada | Media (4.3) | 2.8% | — | Microsoft Internet ExplorerMicrosoft Edge | 5/3/2019 | 17/6/2026 | A spoofing vulnerability exists when Microsoft browsers improperly handles specific redirects, aka 'Microsoft Browser Spoofing Vulnerability'. | |
| Modificada | Alta (7.5) | 11% | — | Microsoft Internet Explorer | 5/3/2019 | 17/6/2026 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'. | |
| Modificada | Media (4.2) | 0.39% | — | Estrongs ES File Explorer File Manager | 15/2/2019 | 17/6/2026 | The Help feature in the ES File Explorer File Manager application 4.1.9.7.4 for Android allows session hijacking by a Man-in-the-middle attacker on the local network because HTTPS is not used, and an attacker's web site is displayed in a WebView with no information about the URL. | |
| Modificada | Media (6.5) | 0.79% | — | Draeger Kappa FirmwareDraeger Infinity Explorer C700 FirmwareDraeger Delta XL FirmwareDraeger Infinity Delta Firmware | 28/1/2019 | 17/6/2026 | Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. Log files are accessible over an unauthenticated network connection. By accessing the log files, an attacker is able to gain insights about internals of the patient monitor, the… | |
| Modificada | Media (6.5) | 0.77% | — | Draeger Kappa FirmwareDraeger Infinity Explorer C700 FirmwareDraeger Delta XL FirmwareDraeger Infinity Delta Firmware | 28/1/2019 | 17/6/2026 | Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. A malformed network packet may cause the monitor to reboot. By repeatedly sending the malformed network packet, an attacker may be able to disrupt patient monitoring by causing the… | |
| Modificada | Alta (7.8) | 0.39% | — | Draeger Kappa FirmwareDraeger Infinity Explorer C700 FirmwareDraeger Delta XL FirmwareDraeger Infinity Delta Firmware | 28/1/2019 | 17/6/2026 | Drager Infinity Delta, Infinity Delta, all versions, Delta XL, all versions, Kappa, all version, and Infinity Explorer C700, all versions. Via a specific dialog it is possible to break out of the kiosk mode and reach the underlying operating system. By breaking out of the kiosk mode, an attacker is able to take… | |
| Modificada | Alta (8.1) | 64% | 💥 Exploit | Estrongs ES File Explorer File Manager | 16/1/2019 | 17/6/2026 | The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary files or execute applications via TCP port 59777 requests on the local Wi-Fi network. This TCP port remains open after the ES application has been launched once, and responds to unauthenticated… | |
| Analizada | Alta (8.8) | 53% | ⚠ Explotación activa💥 Exploit | Microsoft Internet ExplorerMicrosoft Excel ViewerMicrosoft OfficeMicrosoft Office 365 Proplus+1 | 8/1/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10,… | |
| Analizada | Alta (7.5) | 30% | ⚠ Explotación activa | Microsoft Internet Explorer | 20/12/2018 | 17/6/2026 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8643. | |
| Modificada | Alta (7.5) | 9.9% | — | Microsoft Internet Explorer | 12/12/2018 | 17/6/2026 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. | |
| Modificada | Alta (7.5) | 68% | 💥 Exploit | Microsoft Internet Explorer | 12/12/2018 | 17/6/2026 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. | |
| Modificada | Alta (7.5) | 44% | 💥 Exploit | Microsoft Internet Explorer | 12/12/2018 | 17/6/2026 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. | |
| Modificada | Alta (7.5) | 45% | 💥 Exploit | Microsoft Internet Explorer | 12/12/2018 | 17/6/2026 | A remote code execution vulnerability exists when the Internet Explorer VBScript execution policy does not properly restrict VBScript under specific conditions, aka "Internet Explorer Remote Code Execution Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. | |
| Modificada | Alta (7.5) | 14% | — | Microsoft Internet Explorer | 14/11/2018 | 17/6/2026 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 11. | |
| Modificada | Alta (7.5) | 51% | 💥 Exploit | Microsoft Internet Explorer | 14/11/2018 | 17/6/2026 | An information disclosure vulnerability exists when VBScript improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user's computer or data, aka "Windows Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet… | |
| Modificada | Alta (7.5) | 13% | — | Microsoft Internet Explorer | 10/10/2018 | 17/6/2026 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 11. This CVE ID is unique from CVE-2018-8460. | |
| Modificada | Alta (7.5) | 21% | — | Microsoft Internet Explorer | 10/10/2018 | 17/6/2026 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 11. This CVE ID is unique from CVE-2018-8491. | |
| Modificada | Media (6.1) | 2.3% | — | Zohocorp Manageengine Assetexplorer | 2/10/2018 | 17/6/2026 | In Zoho ManageEngine AssetExplorer, a Stored XSS vulnerability was discovered in the 6.2.0 version via the /AssetDef.do ciName or assetName parameter. | |
| Modificada | Media (6.1) | 3.3% | — | Microsoft Internet Explorer | 13/9/2018 | 17/6/2026 | A security feature bypass vulnerability exists in Internet Explorer due to how scripts are handled that allows a universal cross-site scripting (UXSS) condition, aka "Internet Explorer Security Feature Bypass Vulnerability." This affects Internet Explorer 11. | |
| Modificada | Alta (7.5) | 13% | — | Microsoft Internet Explorer | 13/9/2018 | 17/6/2026 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 11. This CVE ID is unique from CVE-2018-8447. | |
| Modificada | Alta (7.5) | 13% | — | Microsoft Internet ExplorerMicrosoft Edge | 13/9/2018 | 17/6/2026 | A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 11, Microsoft Edge, Internet Explorer 10. This CVE ID is unique from CVE-2018-8354, CVE-2018-8391,… | |
| Modificada | Media (4.3) | 5.6% | — | Microsoft Internet ExplorerMicrosoft ChakracoreMicrosoft Edge | 13/9/2018 | 17/6/2026 | An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft browsers, aka "Scripting Engine Information Disclosure Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge. |