Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

2526 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)1.0%—Trendmicro Antivirus+ 2020Trendmicro Internet Security 2020Trendmicro Maximum Security 2020Trendmicro Premium Security 202015/7/202017/6/2026
An untrusted search path remote code execution (RCE) vulnerability in the Trend Micro Secuity 2020 (v16.0.0.1146 and below) consumer family of products could allow an attacker to run arbitrary code on a vulnerable system. As the Trend Micro installer tries to load DLL files from its current directory, an arbitrary DLL…
ModificadaAlta (7.7)1.3%—Oracle Internet Expenses15/7/202017/6/2026
Vulnerability in the Oracle Internet Expenses product of Oracle E-Business Suite (component: Mobile Expenses Admin Utilities). Supported versions that are affected are 12.2.4-12.2.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Internet Expenses.…
ModificadaAlta (7.7)1.0%—Oracle Internet Expenses15/7/202017/6/2026
Vulnerability in the Oracle Internet Expenses product of Oracle E-Business Suite (component: Mobile Expenses Admin Utilities). Supported versions that are affected are 12.2.4-12.2.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Internet Expenses.…
ModificadaMedia (4.3)4.5%—Microsoft Internet Explorer14/7/202017/6/2026
An information disclosure vulnerability exists when Skype for Business is accessed via Internet Explorer, aka 'Skype for Business via Internet Explorer Information Disclosure Vulnerability'.
ModificadaAlta (7.5)10%—Microsoft Internet Explorer14/7/202017/6/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'.
ModificadaAlta (8.8)1.7%—Tibco Managed File Transfer Command CenterTibco Managed File Transfer Internet Server30/6/202017/6/2026
The MFT admin service component of TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center and TIBCO Managed File Transfer Internet Server contains a vulnerability that theoretically allows an authenticated user with specific permissions to obtain the session identifier of another user. The session identifier…
ModificadaCrítica (9.6)1.3%—Tibco Managed File Transfer Command CenterTibco Managed File Transfer Internet Server30/6/202017/6/2026
The MFT Browser file transfer client and MFT Browser admin client components of TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center and TIBCO Managed File Transfer Internet Server contain a vulnerability that theoretically allows an attacker to craft an URL that will execute arbitrary commands on the…
ModificadaMedia (5.3)3.8%—Microsoft Internet Explorer9/6/202017/6/2026
An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory, aka 'Internet Explorer Information Disclosure Vulnerability'.
ModificadaAlta (7.5)7.2%—Microsoft Internet Explorer9/6/202017/6/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1214, CVE-2020-1215, CVE-2020-1216, CVE-2020-1230.
ModificadaAlta (7.5)7.1%—Microsoft Internet Explorer9/6/202017/6/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1214, CVE-2020-1215, CVE-2020-1216, CVE-2020-1260.
ModificadaAlta (7.5)19%—Microsoft Internet ExplorerMicrosoft EdgeMicrosoft Chakracore9/6/202017/6/2026
A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory Corruption Vulnerability'.
ModificadaAlta (7.5)7.2%—Microsoft Internet Explorer9/6/202017/6/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1214, CVE-2020-1215, CVE-2020-1230, CVE-2020-1260.
ModificadaAlta (7.5)8.0%—Microsoft Internet Explorer9/6/202017/6/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1214, CVE-2020-1216, CVE-2020-1230, CVE-2020-1260.
ModificadaAlta (7.5)8.0%—Microsoft Internet Explorer9/6/202017/6/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1215, CVE-2020-1216, CVE-2020-1230, CVE-2020-1260.
ModificadaAlta (7.5)7.2%—Microsoft Internet Explorer9/6/202017/6/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1214, CVE-2020-1215, CVE-2020-1216, CVE-2020-1230, CVE-2020-1260.
ModificadaAlta (7.5)3.2%—Microsoft Internet Explorer21/5/202019/8/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same…
ModificadaAlta (7.5)3.2%—Microsoft Internet Explorer21/5/202019/8/2026
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same…
ModificadaAlta (7.5)3.2%—Microsoft Internet Explorer21/5/202019/8/2026
A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input. An attacker could execute arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take…
ModificadaAlta (7.5)6.2%—Microsoft Internet Explorer21/5/202019/8/2026
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same…
ModificadaAlta (7.5)3.2%—Microsoft Internet Explorer21/5/202019/8/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same…
ModificadaAlta (7.5)3.2%—Microsoft Internet Explorer21/5/202019/8/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same…
ModificadaAlta (7.5)3.2%—Microsoft Internet Explorer21/5/202019/8/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same…
ModificadaCrítica (9.8)1.3%—Jenzabar Internet Campus Solution19/5/202017/6/2026
Jenzabar JICS (aka Internet Campus Solution) before 9.0.1 Patch 3, 9.1 before 9.1.2 Patch 2, and 9.2 before 9.2.2 Patch 8 has session cookies that are a deterministic function of the username. There is a hard-coded password to supply a PBKDF feeding into AES to encrypt a username and base64 encode it to a client-side…
ModificadaAlta (8.8)1.6%—Internet-formation Wp-advanced-search5/5/202017/6/2026
The Import feature in the wp-advanced-search plugin 3.3.6 for WordPress is vulnerable to authenticated SQL injection via an uploaded .sql file. An attacker can use this to execute SQL commands without any validation.
ModificadaAlta (7.8)0.38%—Eset Antivirus AND AntispywareEset Endpoint AntivirusEset Endpoint SecurityEset File Security+429/4/202017/6/2026
ESET Antivirus and Antispyware Module module 1553 through 1560 allows a user with limited access rights to create hard links in some ESET directories and then force the product to write through these links into files that would normally not be write-able by the user, thus achieving privilege escalation.