Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
467 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 7.0% | — | Microsoft Exchange Server | 17/3/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Microsoft Exchange Outlook Web Access (OWA) allows remote attackers to inject arbitrary web script or HTML via a crafted email or chat client, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." | |
| Modificada | Media (6.1) | 8.2% | — | Microsoft Exchange Server | 14/9/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2016 Cumulative Update 1 and 2 allows remote attackers to inject arbitrary web script or HTML via a meeting-invitation request, aka "Microsoft Exchange Elevation of Privilege Vulnerability." | |
| Modificada | Alta (7.4) | 15% | — | Microsoft Exchange Server | 14/9/2016 | 17/6/2026 | Open redirect vulnerability in Microsoft Exchange Server 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumulative Update 1, and 2016 Cumulative Update 2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka "Microsoft Exchange Open… | |
| Modificada | Media (4.3) | 13% | — | Microsoft Exchange Server | 14/9/2016 | 17/6/2026 | Microsoft Exchange Server 2007 SP3, 2010 SP3, 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumulative Update 1, and 2016 Cumulative Update 2 misparses e-mail messages, which allows remote authenticated users to obtain sensitive Outlook application information by leveraging the Send As right,… | |
| Modificada | Alta (8.1) | 7.2% | — | HP Converged Infrastructure Solution Sizer SuiteHP Insight Management SizerHP Power AdvisorHP SAP Sizing Tool+11 | 22/8/2016 | 17/6/2026 | HPE Smart Update in Storage Sizing Tool before 13.0, Converged Infrastructure Solution Sizer Suite (CISSS) before 2.13.1, Power Advisor before 7.8.2, Insight Management Sizer before 16.12.1, Synergy Planning Tool before 3.3, SAP Sizing Tool before 16.12.1, Sizing Tool for SAP Business Suite powered by HANA before… | |
| Modificada | Alta (8.4) | 18% | 💥 Exploit | Symantec Norton SecuritySymantec Protection EngineSymantec Advanced Threat ProtectionSymantec Norton Bootable Removal Tool+14 | 30/6/2016 | 17/6/2026 | The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before… | |
| Modificada | Crítica (9.8) | 25% | 💥 Exploit | Symantec Norton SecuritySymantec Protection EngineSymantec Advanced Threat ProtectionSymantec Norton Bootable Removal Tool+14 | 30/6/2016 | 17/6/2026 | Integer overflow in the TNEF unpacker in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec… | |
| Modificada | Alta (8.4) | 18% | 💥 Exploit | Symantec Norton SecuritySymantec Protection EngineSymantec Advanced Threat ProtectionSymantec Norton Bootable Removal Tool+14 | 30/6/2016 | 17/6/2026 | The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before… | |
| Modificada | Alta (7.8) | 53% | — | Symantec Mail Security FOR Microsoft ExchangeSymantec Norton Power EraserSymantec Protection EngineSymantec Endpoint Protection+14 | 30/6/2016 | 17/6/2026 | The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before… | |
| Modificada | Alta (7.3) | 11% | 💥 Exploit | Symantec Mail Security FOR Microsoft ExchangeSymantec Norton Power EraserSymantec Protection EngineSymantec Endpoint Protection+14 | 30/6/2016 | 17/6/2026 | Buffer overflow in Dec2LHA.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint… | |
| Modificada | Alta (7.3) | 21% | 💥 Exploit | Symantec Mail Security FOR Microsoft ExchangeSymantec Norton Power EraserSymantec Protection EngineSymantec Endpoint Protection+14 | 30/6/2016 | 17/6/2026 | Buffer overflow in Dec2SS.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint… | |
| Modificada | Alta (8.4) | 18% | 💥 Exploit | Symantec Mail Security FOR Microsoft ExchangeSymantec Norton Power EraserSymantec Protection EngineSymantec Endpoint Protection+14 | 30/6/2016 | 17/6/2026 | The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before… | |
| Modificada | Media (5.1) | 1.1% | 💥 Exploit | Mcafee Active ResponseMcafee AgentMcafee Data Exchange LayerMcafee Data Loss Prevention Endpoint+3 | 8/4/2016 | 17/6/2026 | The McAfee VirusScan Console (mcconsol.exe) in McAfee Active Response (MAR) before 1.1.0.161, Agent (MA) 5.x before 5.0.2 Hotfix 1110392 (5.0.2.333), Data Exchange Layer 2.x (DXL) before 2.0.1.140.1, Data Loss Prevention Endpoint (DLPe) 9.3 before Patch 6 and 9.4 before Patch 1 HF3, Device Control (MDC) 9.3 before… | |
| Modificada | Media (6.1) | 7.6% | — | Microsoft Exchange Server | 13/1/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 PS1, 2013 Cumulative Update 10, 2013 Cumulative Update 11, and 2016 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Exchange Spoofing Vulnerability." | |
| Modificada | Media (6.1) | 7.6% | — | Microsoft Exchange Server | 13/1/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2016 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Exchange Spoofing Vulnerability," a different vulnerability than CVE-2016-0029. | |
| Modificada | Media (6.1) | 7.6% | — | Microsoft Exchange Server | 13/1/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 PS1, 2013 Cumulative Update 10, and 2016 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Exchange Spoofing Vulnerability." | |
| Modificada | Media (6.1) | 7.6% | — | Microsoft Exchange Server | 13/1/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2016 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Exchange Spoofing Vulnerability," a different vulnerability than CVE-2016-0031. | |
| Modificada | Baja (1.9) | 0.42% | — | IBM Tivoli Storage Manager FOR Databases Data Protection FOR Microsoft SQL ServerIBM Tivoli Storage Manager FOR Mail Data Protection FOR Microsoft Exchange ServerIBM Tivoli Storage Flashcopy Manager | 14/11/2015 | 17/6/2026 | IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server (aka Spectrum Protect for Databases) 5.5 before 5.5.6.2, 6.3 before 6.3.1.6, 6.4 before 6.4.1.8, and 7.1 before 7.1.4; Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server (aka Spectrum Protect for Mail) 5.5… | |
| Modificada | Baja (2.1) | 0.32% | — | Mcafee Threat Intelligence Exchange | 18/9/2015 | 17/6/2026 | The Secondary server in Threat Intelligence Exchange (TIE) before 1.2.0 uses weak permissions for unspecified (1) configuration files and (2) installation logs, which allows local users to obtain sensitive information by reading the files. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Auto-exchanger | 11/9/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Auto-Exchanger 5.1.0 allows remote attackers to hijack the authentication of users for requests that change a password via a request to signup.php. | |
| Modificada | Media (4.3) | 9.5% | — | Microsoft Exchange Server | 9/9/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 Cumulative Update 8 and 9 and SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted e-mail message, aka "Exchange Spoofing Vulnerability." | |
| Modificada | Media (4.3) | 9.5% | — | Microsoft Exchange Server | 9/9/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 Cumulative Update 8 and 9 allows remote attackers to inject arbitrary web script or HTML via a crafted e-mail message, aka "Exchange Spoofing Vulnerability." | |
| Modificada | Media (5) | 18% | — | Microsoft Exchange Server | 9/9/2015 | 17/6/2026 | Outlook Web Access (OWA) in Microsoft Exchange Server 2013 Cumulative Update 8 and 9 and SP1 allows remote attackers to obtain sensitive stacktrace information via a crafted request, aka "Exchange Information Disclosure Vulnerability." | |
| Modificada | Media (4) | 1.7% | — | IBM Tivoli Storage Fastback FOR Microsoft ExchangeIBM Tivoli Storage Flashcopy Manager FOR Microsoft Exchange ServerIBM Tivoli Storage Manager FOR Mail Data Protection FOR Microsoft Exchange Server | 23/8/2015 | 17/6/2026 | The mailbox-restore feature in IBM Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 6.1 before 6.1.3.6, 6.3 before 6.3.1.3, 6.4 before 6.4.1.4, and 7.1 before 7.1.0.2; Tivoli Storage FlashCopy Manager: FlashCopy Manager for Microsoft Exchange Server 2.1, 2.2, 3.1 before 3.1.1.5, 3.2… | |
| Modificada | Baja (2.1) | 0.33% | — | IBM Tivoli Storage Flashcopy ManagerIBM Tivoli Storage Manager FOR Databases Data Protection FOR Microsoft SQL ServerIBM Tivoli Storage Manager FOR Mail Data Protection FOR Microsoft Exchange Server | 23/8/2015 | 17/6/2026 | IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server 5.5 before 5.5.6.1, 6.3 before 6.3.1.5, 6.4 before 6.4.1.7, and 7.1 before 7.1.2; Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 5.5 before 5.5.1.1, 6.1 before 6.1.3.7, 6.3 before 6.3.1.5, 6.4 before… |