Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
489 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 63% | 💥 Exploit | Microsoft Exchange ServerMicrosoft Security EssentialsMicrosoft Forefront Endpoint Protection 2010Microsoft Intune Endpoint Protection+2 | 4/4/2018 | 17/6/2026 | A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially crafted file, leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability." This affects Windows Defender, Windows Intune Endpoint Protection,… | |
| Modificada | Alta (8.8) | 2.3% | 💥 Exploit | Frontaccounting | 16/2/2018 | 17/6/2026 | FrontAccounting 2.4.3 suffers from a CSRF flaw, which leads to adding a user account via admin/users.php (aka the "add user" feature of the User Permissions page). | |
| Modificada | Media (6.5) | 1.2% | — | Efrontlearning Efront | 5/2/2018 | 17/6/2026 | Absolute path traversal vulnerability in eFront CMS 3.6.15.4 and earlier allows remote Professor users to obtain sensitive information via a full pathname in the other parameter. | |
| Modificada | Baja (2.7) | 1.1% | — | Oracle Peoplesoft Enterprise Staffing Front Office | 19/10/2017 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise FSCM component of Oracle PeopleSoft Products (subcomponent: Staffing Front Office). The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FSCM.… | |
| Modificada | Media (4.3) | 1.4% | — | Oracle Peoplesoft Enterprise FIN Staffing Front Office | 19/10/2017 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise FSCM component of Oracle PeopleSoft Products (subcomponent: Staffing Front Office). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FSCM. Successful… | |
| Modificada | Baja (2.7) | 1.4% | — | Oracle Peoplesoft Enterprise Staffing Front Office | 8/8/2017 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise FSCM component of Oracle PeopleSoft Products (subcomponent: Staffing Front Office). The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FSCM.… | |
| Modificada | Media (6.5) | 1.2% | — | Efrontlearning Efront | 25/7/2017 | 17/6/2026 | The file_manager component in eFront CMS before 3.6.15.5 allows remote authenticated users to bypass intended file-upload restrictions by appending a crafted parameter to the file URL. | |
| Modificada | Media (6.5) | 1.1% | — | Efrontlearning Efront | 25/7/2017 | 17/6/2026 | Absolute path traversal vulnerability in the file_manager component of eFront CMS before 3.6.15.5 allows remote authenticated users to read arbitrary files via a full pathname in the "Upload file from url" field in the file manager for professor.php. | |
| Modificada | Alta (7.8) | 44% | 💥 Exploit | Microsoft Windows DefenderMicrosoft Endpoint ProtectionMicrosoft Forefront Endpoint ProtectionMicrosoft Security Essentials+1 | 29/6/2017 | 17/6/2026 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on 32-bit versions of Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703 does not properly scan a specially crafted… | |
| Modificada | Media (5.5) | 6.0% | — | Microsoft Forefront SecurityMicrosoft Malware Protection EngineMicrosoft Windows Defender | 26/5/2017 | 17/6/2026 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and… | |
| Modificada | Alta (7.8) | 48% | 💥 Exploit | Microsoft Forefront SecurityMicrosoft Malware Protection EngineMicrosoft Windows Defender | 26/5/2017 | 17/6/2026 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and… | |
| Analizada | Alta (7.8) | 72% | ⚠ Explotación activa💥 Exploit | Microsoft Malware Protection EngineMicrosoft Endpoint ProtectionMicrosoft Exchange ServerMicrosoft Forefront Endpoint Protection+5 | 26/5/2017 | 17/6/2026 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and… | |
| Modificada | Media (5.5) | 6.0% | — | Microsoft Forefront SecurityMicrosoft Malware Protection EngineMicrosoft Windows Defender | 26/5/2017 | 17/6/2026 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and… | |
| Modificada | Alta (7.8) | 50% | 💥 Exploit | Microsoft Forefront SecurityMicrosoft Malware Protection EngineMicrosoft Windows Defender | 26/5/2017 | 17/6/2026 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and… | |
| Modificada | Media (5.5) | 17% | 💥 Exploit | Microsoft Windows DefenderMicrosoft Endpoint ProtectionMicrosoft Exchange ServerMicrosoft Forefront Endpoint Protection+3 | 26/5/2017 | 17/6/2026 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and… | |
| Modificada | Media (5.5) | 17% | 💥 Exploit | Microsoft Windows DefenderMicrosoft Endpoint ProtectionMicrosoft Exchange ServerMicrosoft Forefront Endpoint Protection+3 | 26/5/2017 | 17/6/2026 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and… | |
| Modificada | Media (5.5) | 17% | 💥 Exploit | Microsoft Windows DefenderMicrosoft Endpoint ProtectionMicrosoft Exchange ServerMicrosoft Forefront Endpoint Protection+3 | 26/5/2017 | 17/6/2026 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and… | |
| Modificada | Alta (7.8) | 81% | 💥 Exploit | Microsoft Forefront SecurityMicrosoft Malware Protection EngineMicrosoft Windows Defender | 9/5/2017 | 17/6/2026 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 does not properly scan a specially… | |
| Modificada | Alta (7.8) | 1.2% | — | Justsystems HanakoJustsystems Hanako PoliceJustsystems Hanako PROJustsystems Just Frontier+5 | 28/4/2017 | 17/6/2026 | Untrusted search path vulnerability in Hanako 2017, Hanako 2016, Hanako 2015, Hanako Pro 3, JUST Office 3 [Standard], JUST Office 3 [Eco Print Package], JUST Office 3 & Tri-De DataProtect Package, JUST Government 3, JUST Jump Class 2, JUST Frontier 3, JUST School 6 Premium, Hanako Police 5, JUST Police 3, Hanako 2017… | |
| Modificada | Media (6.1) | 1.2% | — | Open-xchange Documentconverter-apiOpen-xchange Office WEBOpen-xchange Appsuite BackendOpen-xchange Appsuite Frontend | 29/3/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite backend before 7.6.2-rev59, 7.8.0 before 7.8.0-rev38, 7.8.2 before 7.8.2-rev8; AppSuite frontend before 7.6.2-rev47, 7.8.0 before 7.8.0-rev30, and 7.8.2 before 7.8.2-rev8; Office Web before 7.6.2-rev16, 7.8.0 before 7.8.0-rev10, and 7.8.2 before… | |
| Modificada | Alta (8.6) | 1.4% | — | American Auto-matrix Aspect-matrix Building Automation Front-end Solutions ApplicationAmerican Auto-matrix Aspect-nexus Building Automation Front-end Solutions Application | 5/10/2016 | 17/6/2026 | American Auto-Matrix Aspect-Nexus Building Automation Front-End Solutions application before 3.0.0 and Aspect-Matrix Building Automation Front-End Solutions application store passwords in cleartext, which allows remote attackers to obtain sensitive information by reading a file. | |
| Modificada | Alta (7.5) | 1.5% | — | American Auto-matrix Aspect-matrix Building Automation Front-end Solutions ApplicationAmerican Auto-matrix Aspect-nexus Building Automation Front-end Solutions Application | 5/10/2016 | 17/6/2026 | American Auto-Matrix Aspect-Nexus Building Automation Front-End Solutions application before 3.0.0 and Aspect-Matrix Building Automation Front-End Solutions application allow remote attackers to read arbitrary files via unspecified vectors, as demonstrated by the configuration file. | |
| Modificada | Media (5.9) | 0.40% | — | RSI Video Technologies Frontel Protocol | 27/12/2015 | 17/6/2026 | The Frontel protocol before 3 on RSI Video Technologies Videofied devices does not use integrity protection, which makes it easier for man-in-the-middle attackers to (1) initiate a false alarm or (2) deactivate an alarm by modifying the client-server data stream. | |
| Modificada | Baja (3.7) | 0.65% | — | RSI Video Technologies Frontel Protocol | 27/12/2015 | 17/6/2026 | The Frontel protocol before 3 on RSI Video Technologies Videofied devices sets up AES encryption but sends all traffic in cleartext, which allows remote attackers to obtain sensitive (1) message or (2) MJPEG video data by sniffing the network. | |
| Modificada | Media (5.9) | 1.4% | — | RSI Video Technologies Frontel Protocol | 27/12/2015 | 17/6/2026 | The Frontel protocol before 3 on RSI Video Technologies Videofied devices sends a cleartext serial number, which allows remote attackers to determine a hardcoded key by sniffing the network and performing a "jumbled up" calculation with this number. |