Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
920 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.8) | 2.8% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+4 | 11/11/2015 | 17/6/2026 | SChannel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 lacks the required extended master-secret binding support to ensure that a server's X.509 certificate is the same during renegotiation as it… | |
| Modificada | Alta (9.3) | 35% | 💥 Exploit | Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+5 | 11/11/2015 | 17/6/2026 | The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Windows… | |
| Modificada | Alta (9.3) | 35% | 💥 Exploit | Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+5 | 11/11/2015 | 17/6/2026 | The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Windows… | |
| Modificada | Baja (2.1) | 4.1% | 💥 Exploit | Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+5 | 11/11/2015 | 17/6/2026 | The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to bypass the KASLR protection mechanism, and consequently discover a driver base address, via… | |
| Modificada | Media (6.9) | 3.1% | 💥 Exploit | Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+5 | 11/11/2015 | 17/6/2026 | The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Elevation of Privilege… | |
| Modificada | Media (6.9) | 3.2% | 💥 Exploit | Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+5 | 11/11/2015 | 17/6/2026 | The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Elevation of Privilege… | |
| Modificada | Alta (7.2) | 4.0% | 💥 Exploit | Microsoft Windows 7Microsoft Windows Server 2008Microsoft Windows Vista | 11/11/2015 | 17/6/2026 | Buffer overflow in the Network Driver Interface Standard (NDIS) implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "Windows NDIS Elevation of Privilege Vulnerability." | |
| Modificada | Alta (9.3) | 21% | — | Microsoft Windows 7Microsoft Windows Server 2008Microsoft Windows Vista | 11/11/2015 | 17/6/2026 | Heap-based buffer overflow in Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted Journal (.jnt) file, aka "Windows Journal Heap Overflow Vulnerability." | |
| Modificada | Media (4.9) | 4.0% | 💥 PoC | Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+3 | 11/11/2015 | 17/6/2026 | Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandles password changes, which allows physically proximate attackers to bypass authentication, and conduct… | |
| Modificada | Alta (7.2) | 1.9% | — | Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+5 | 11/11/2015 | 17/6/2026 | Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application that triggers a Winsock call referencing an invalid address, aka… | |
| Modificada | Alta (7.2) | 3.6% | 💥 Exploit | Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+5 | 14/10/2015 | 17/6/2026 | The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Windows Object Reference Elevation of Privilege Vulnerability." | |
| Modificada | Alta (7.2) | 3.3% | 💥 Exploit | Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+5 | 14/10/2015 | 17/6/2026 | The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 mishandles junctions during mountpoint creation, which makes it easier for local users to gain privileges by leveraging certain… | |
| Modificada | Alta (7.2) | 1.7% | — | Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+5 | 14/10/2015 | 17/6/2026 | The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows physically proximate attackers to bypass the Trusted Boot protection mechanism, and consequently interfere with the integrity of code, BitLocker, Device Encryption, and Device Health… | |
| Modificada | Alta (7.2) | 1.9% | — | Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+5 | 14/10/2015 | 17/6/2026 | The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Windows Elevation of Privilege Vulnerability." | |
| Modificada | Alta (7.2) | 2.3% | — | Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+5 | 14/10/2015 | 17/6/2026 | The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Corruption Vulnerability." | |
| Modificada | Alta (9.3) | 25% | — | Microsoft Windows 7Microsoft Windows Vista | 14/10/2015 | 17/6/2026 | Use-after-free vulnerability in the Tablet Input Band in Windows Shell in Microsoft Windows Vista SP2 and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Microsoft Tablet Input Band Use After Free Vulnerability." | |
| Modificada | Alta (9.3) | 29% | — | Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+5 | 14/10/2015 | 17/6/2026 | Use-after-free vulnerability in Windows Shell in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows remote attackers to execute arbitrary code via a crafted toolbar object, aka "Toolbar… | |
| Analizada | Alta (8.2) | 10% | ⚠ Explotación activa💥 PoC | Microsoft Windows 10 1507Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+5 | 9/9/2015 | 14/8/2026 | The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Elevation of… | |
| Modificada | Alta (9.3) | 16% | — | Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+5 | 9/9/2015 | 17/6/2026 | Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows remote attackers to execute arbitrary code via a crafted .jnt file, aka "Windows Journal RCE Vulnerability," a… | |
| Modificada | Alta (7.2) | 3.3% | 💥 Exploit | Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+5 | 9/9/2015 | 17/6/2026 | Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "Windows Task Management Elevation of Privilege Vulnerability," a different vulnerability… | |
| Modificada | Alta (7.2) | 31% | 💥 Exploit | Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+5 | 9/9/2015 | 17/6/2026 | Task Scheduler in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to bypass intended filesystem restrictions and delete arbitrary files via unspecified vectors, aka… | |
| Modificada | Alta (9.3) | 14% | — | Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+5 | 9/9/2015 | 17/6/2026 | Integer overflow in Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows remote attackers to execute arbitrary code via a crafted .jnt file, aka "Windows Journal Integer… | |
| Modificada | Media (6.9) | 3.9% | 💥 Exploit | Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+5 | 9/9/2015 | 17/6/2026 | The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Elevation of… | |
| Modificada | Media (6.9) | 3.9% | 💥 Exploit | Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+5 | 9/9/2015 | 17/6/2026 | The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Elevation of… | |
| Modificada | Media (4.3) | 12% | — | Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+5 | 9/9/2015 | 17/6/2026 | Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows remote attackers to cause a denial of service (data loss) via a crafted .jnt file, aka "Windows Journal DoS… |