Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
828 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 56% | ⚠ Explotación activa💥 Exploit | Microsoft Windows 2003 ServerMicrosoft Windows 7Microsoft Windows Server 2008Microsoft Windows Vista | 21/4/2015 | 14/8/2026 | Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in April 2015, aka "Win32k Elevation of Privilege Vulnerability." | |
| Modificada | Alta (9.3) | 25% | — | Microsoft Windows 7Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Vista | 14/4/2015 | 17/6/2026 | Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allow remote attackers to execute arbitrary code via a crafted Enhanced Metafile (EMF) image, aka "EMF Processing Remote Code Execution Vulnerability." | |
| Modificada | Alta (7.2) | 1.6% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 14/4/2015 | 17/6/2026 | Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka… | |
| Modificada | Alta (7.2) | 2.7% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 14/4/2015 | 17/6/2026 | Microsoft Windows Server 2003 R2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka… | |
| Modificada | Alta (9.3) | 71% | 💥 Exploit | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a Trojan horse DLL in the current working… | |
| Modificada | Media (5.6) | 2.7% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to cause a denial of service (NULL pointer dereference and blue screen), or obtain… | |
| Modificada | Baja (2.1) | 2.6% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly restrict the availability of address information during a function call, which makes… | |
| Modificada | Alta (9.3) | 21% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font… | |
| Modificada | Alta (9.3) | 17% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font… | |
| Modificada | Alta (9.3) | 20% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font… | |
| Modificada | Alta (9.3) | 20% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font… | |
| Modificada | Media (5) | 21% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to obtain sensitive information from kernel memory, and possibly bypass the KASLR… | |
| Modificada | Alta (9.3) | 20% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font… | |
| Modificada | Media (5) | 23% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to obtain sensitive information from kernel memory, and possibly bypass the KASLR… | |
| Modificada | Alta (9.3) | 24% | 💥 Exploit | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | Windows Text Services (WTS) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "WTS… | |
| Modificada | Media (4.3) | 15% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly initialize memory for rendering of malformed PNG images, which allows remote attackers to obtain sensitive… | |
| Modificada | Baja (2.1) | 2.4% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly initialize function buffers, which allows local users to obtain sensitive information… | |
| Modificada | Media (4.3) | 15% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+4 | 11/3/2015 | 17/6/2026 | The photo-decoder implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly initialize memory for rendering of JXR images, which allows remote attackers to obtain sensitive… | |
| Modificada | Alta (7.2) | 1.6% | — | Microsoft Windows 2003 ServerMicrosoft Windows 7Microsoft Windows Server 2008Microsoft Windows Vista | 11/3/2015 | 17/6/2026 | The kernel in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 does not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "Impersonation Level Check Elevation of Privilege Vulnerability." | |
| Modificada | Media (4.3) | 15% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly allocate memory, which allows remote attackers to cause a denial of service via a crafted… | |
| Modificada | Alta (7.2) | 1.8% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | The Windows Registry Virtualization feature in the kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly restrict changes to virtual stores, which allows local users to gain… | |
| Modificada | Media (4.3) | 13% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 6/3/2015 | 17/6/2026 | Schannel (aka Secure Channel) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly restrict TLS state transitions, which makes it easier for remote attackers to… | |
| Modificada | Media (4.3) | 19% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/2/2015 | 17/6/2026 | Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly initialize memory for TIFF images, which allows remote attackers to obtain sensitive information from process… | |
| Modificada | Media (4.7) | 3.8% | 💥 Exploit | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/2/2015 | 17/6/2026 | The font mapper in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly scale fonts, which allows local users to cause a… | |
| Modificada | Alta (7.2) | 13% | 💥 Exploit | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/2/2015 | 17/6/2026 | win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Elevation… |