Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
2526 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.65% | — | Kyrol Internet Security | 10/1/2020 | 17/6/2026 | An invalid pointer vulnerability in IOCTL Handling in the kyrld.sys driver in Kyrol Internet Security 9.0.6.9 allows an attacker to achieve privilege escalation, denial-of-service, and code execution via usermode because 0x9C402405 using METHOD_NEITHER results in a read primitive. | |
| Modificada | Alta (7.8) | 0.71% | — | Symantec Endpoint ProtectionSymantec Endpoint Protection CloudSymantec Norton 360Symantec Norton Antivirus+5 | 9/1/2020 | 17/6/2026 | A Privilege Escalation vulnerability exists in Symantec Norton Antivirus, Norton AntiVirus with Backup, Norton Security, Norton Security with Backup, Norton Internet Security, Norton 360, Endpoint Protection Small Business Edition Cloud, and Endpoint Protection Cloud Client due to a DLL-preloading without path… | |
| Modificada | Alta (7.1) | 0.60% | — | Trendmicro Antivirus+ Security 2020Trendmicro Internet Security 2020Trendmicro Maximum Security 2020Trendmicro Premium Security 2020 | 20/12/2019 | 17/6/2026 | The Trend Micro Security 2020 consumer family of products contains a vulnerability that could allow a local attacker to disclose sensitive information or to create a denial-of-service condition on affected installations. An attacker must first obtain the ability to execute low-privileged code on the target system in… | |
| Modificada | Alta (7.5) | 2.1% | — | HP Universal Internet OF Things | 18/12/2019 | 17/6/2026 | Security vulnerabilities in HPE UIoT version 1.2.4.2 could allow unauthorized remote access and access to sensitive data. HPE has addressed this issue in HPE UIoT: For customers with release UIoT 1.2.4.2 fixes are made available with 1.2.4.2 RP3 HF1. For customers with release older than 1.2.4.2, such as 1.2.4.1,… | |
| Modificada | Alta (7.5) | 8.2% | — | Microsoft Internet Explorer | 10/12/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. | |
| Modificada | Crítica (9.8) | 2.7% | — | Trendmicro Antivirus+ Security 2020Trendmicro Internet Security 2020Trendmicro Maximum Security 2020Trendmicro Premium Security 2020 | 9/12/2019 | 17/6/2026 | Trend Micro Security (Consumer) 2020 (v16.x) is affected by a vulnerability in where null pointer dereference errors result in the crash of application, which could potentially lead to possible unsigned code execution under certain circumstances. | |
| Modificada | Media (6.7) | 0.77% | — | Kaspersky Internet SecurityKaspersky Secure ConnectionKaspersky Security CloudKaspersky Total Security | 2/12/2019 | 17/6/2026 | Kaspersky Secure Connection, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Security Cloud prior to version 2020 patch E have bug that allows a local user to execute arbitrary code via execution compromised file placed by an attacker with administrator rights. No privilege escalation. Possible… | |
| Modificada | Alta (7.8) | 0.52% | — | Trendmicro Antivirus + Security 2020Trendmicro Internet Security 2020Trendmicro Maximum Security 2020Trendmicro Premium Security 2020 | 2/12/2019 | 17/6/2026 | Trend Micro Security (Consumer) 2020 (v16.0.1221 and below) is affected by a DLL hijacking vulnerability that could allow an attacker to use a specific service as an execution and/or persistence mechanism which could execute a malicious program each time the service is started. | |
| Modificada | Media (6.1) | 2.1% | — | Kaspersky Anti-virusKaspersky Internet SecurityKaspersky Security CloudKaspersky Small Office Security+1 | 26/11/2019 | 17/6/2026 | Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component did not adequately inform the user about the threat of redirecting to an untrusted site. Bypass. | |
| Modificada | Media (6.5) | 1.6% | — | Kaspersky Anti-virusKaspersky Internet SecurityKaspersky Security CloudKaspersky Small Office Security+1 | 26/11/2019 | 17/6/2026 | Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component was vulnerable to remote disclosure of various information about the user's system (like Windows version and version… | |
| Modificada | Media (4.3) | 0.77% | — | Kaspersky Anti-virusKaspersky Internet SecurityKaspersky Security CloudKaspersky Small Office Security+1 | 26/11/2019 | 17/6/2026 | Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component allowed an attacker remotely disable various anti-virus protection features. DoS, Bypass. | |
| Modificada | Media (4.3) | 0.84% | — | Kaspersky Anti-virusKaspersky Internet SecurityKaspersky Security CloudKaspersky Small Office Security+1 | 26/11/2019 | 17/6/2026 | Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small Office Security, Kaspersky Security Cloud up to 2020, the web protection component allowed an attacker remotely disable such product's security features as private browsing and anti-banner. Bypass. | |
| Modificada | Alta (7.8) | 0.57% | — | Kyrolsecuritylabs Kyrol Internet Security | 21/11/2019 | 17/6/2026 | IOCTL Handling in the kyrld.sys driver in Kyrol Internet Security 9.0.6.9 allows an attacker to achieve privilege escalation, denial-of-service, and code execution via usermode because 0x9C402401 using METHOD_NEITHER results in a read primitive. | |
| Modificada | Alta (7.8) | 0.59% | — | Comodo Internet Security | 18/11/2019 | 17/6/2026 | An issue was discovered in signmgr.dll 6.5.0.819 in Comodo Internet Security through 12.0. A DLL Preloading vulnerability allows an attacker to implant an unsigned DLL named iLog.dll in a partially unprotected product directory. This DLL is then loaded into a high-privileged service before the binary signature… | |
| Modificada | Media (6.7) | 0.66% | — | Mcafee Anti-virus PlusMcafee Internet SecurityMcafee Total Protection | 13/11/2019 | 17/6/2026 | A Privilege Escalation vulnerability in the Microsoft Windows client in McAfee Total Protection 16.0.R22 and earlier allows administrators to execute arbitrary code via carefully placing malicious files in specific locations protected by administrator permission. | |
| Analizada | Alta (7.5) | 77% | ⚠ Explotación activa💥 Exploit | Microsoft Internet Explorer | 12/11/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1426, CVE-2019-1427, CVE-2019-1428. | |
| Modificada | Alta (7.5) | 7.8% | — | Microsoft Internet Explorer | 12/11/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. | |
| Modificada | Alta (7.5) | 7.4% | — | Microsoft Internet Explorer | 10/10/2019 | 17/6/2026 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'. | |
| Modificada | Media (4.3) | 2.3% | — | Microsoft Internet ExplorerMicrosoft Edge | 10/10/2019 | 17/6/2026 | A spoofing vulnerability exists when Microsoft Browsers improperly handle browser cookies, aka 'Microsoft Browser Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0608. | |
| Modificada | Alta (7.5) | 7.5% | — | Microsoft Internet Explorer | 10/10/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1238. | |
| Modificada | Media (6.4) | 5.9% | — | Microsoft Internet Explorer | 10/10/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1239. | |
| Modificada | Media (4.3) | 2.4% | — | Microsoft Internet ExplorerMicrosoft Edge | 10/10/2019 | 17/6/2026 | A spoofing vulnerability exists when Microsoft Browsers does not properly parse HTTP content, aka 'Microsoft Browser Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1357. | |
| Analizada | Alta (7.5) | 52% | ⚠ Explotación activa💥 PoC | Microsoft Internet Explorer | 23/9/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1221. | |
| Modificada | Alta (7.5) | 19% | 💥 PoC | Microsoft Internet Explorer | 11/9/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. | |
| Modificada | Media (4.3) | 3.8% | — | Microsoft Internet ExplorerMicrosoft Edge | 11/9/2019 | 17/6/2026 | A security feature bypass vulnerability exists when Microsoft Browsers fail to validate the correct Security Zone of requests for specific URLs, aka 'Microsoft Browser Security Feature Bypass Vulnerability'. |