Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
2526 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 13% | — | Microsoft Internet Explorer | 11/9/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1236. | |
| Modificada | Alta (7.8) | 1.2% | — | Trendmicro Antivirus + Security 2019Trendmicro Internet Security 2019Trendmicro Maximum Security 2019Trendmicro Premium Security 2019+1 | 21/8/2019 | 17/6/2026 | A DLL hijacking vulnerability exists in the Trend Micro Security's 2019 consumer family of products (v15) Folder Shield component and the standalone Trend Micro Ransom Buster (1.0) tool in which, if exploited, would allow an attacker to load a malicious DLL, leading to elevated privileges. | |
| Modificada | Alta (7.8) | 0.59% | — | Trendmicro Antivirus + Security 2019Trendmicro Internet Security 2019Trendmicro Maximum Security 2019Trendmicro Premium Security 2019 | 21/8/2019 | 17/6/2026 | A local privilege escalation vulnerability exists in Trend Micro Security 2019 (v15.0) in which, if exploited, would allow an attacker to manipulate a specific product feature to load a malicious service. | |
| Modificada | Alta (7.5) | 3.4% | — | Microsoft Internet Explorer | 14/8/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the… | |
| Modificada | Media (6.4) | 3.1% | — | Microsoft Internet ExplorerMicrosoft Edge | 14/8/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the… | |
| Modificada | Media (4.3) | 3.7% | — | Microsoft Internet ExplorerMicrosoft Edge | 14/8/2019 | 17/6/2026 | A security feature bypass vulnerability exists when Microsoft browsers improperly handle requests of different origins. The vulnerability allows Microsoft browsers to bypass Same-Origin Policy (SOP) restrictions, and to allow requests that should otherwise be ignored. An attacker who successfully exploited the… | |
| Modificada | Alta (7.5) | 3.3% | — | Microsoft Internet Explorer | 14/8/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the… | |
| Modificada | Media (6.7) | 0.57% | — | Bitdefender Antivirus PlusBitdefender Endpoint Security ToolBitdefender Internet SecurityBitdefender Total Security | 30/7/2019 | 17/6/2026 | An issue was discovered in Bitdefender products for Windows (Bitdefender Endpoint Security Tool versions prior to 6.6.8.115; and Bitdefender Antivirus Plus, Bitdefender Internet Security, and Bitdefender Total Security versions prior to 23.0.24.120) that can lead to local code injection. A local attacker with… | |
| Modificada | Alta (7.1) | 0.46% | — | Comodo AntivirusComodo FirewallComodo Internet Security | 25/7/2019 | 17/6/2026 | Comodo Antivirus through 12.0.0.6870, Comodo Firewall through 12.0.0.6870, and Comodo Internet Security Premium through 12.0.0.6870, with the Comodo Container feature, are vulnerable to Sandbox Escape. | |
| Modificada | Alta (8.8) | 1.6% | — | HP Universal Internet OF Things | 19/7/2019 | 17/6/2026 | Security vulnerabilities in HPE UIoT versions 1.6, 1.5, 1.4.2, 1.4.1, 1.4.0, and 1.2.4.2 could allow unauthorized remote access and access to sensitive data. HPE has addressed this issue in HPE UIoT: * For customers with release UIoT 1.6, fixes are made available with 1.6 RP603 * For customers with release UIoT 1.5,… | |
| Modificada | Media (4.3) | 2.2% | — | Kaspersky Anti-virusKaspersky Free Anti-virusKaspersky Internet SecurityKaspersky Small Office Security+1 | 18/7/2019 | 17/6/2026 | Information Disclosure in Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security versions up to 2019 could potentially disclose unique Product ID by forcing victim to visit a specially crafted webpage (for example, via clicking phishing link). Vulnerability has CVSS v3.0 base score 2.6 | |
| Modificada | Alta (7.5) | 7.1% | — | Microsoft Internet ExplorerMicrosoft Edge | 15/7/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory Corruption Vulnerability'. | |
| Modificada | Alta (7.5) | 7.2% | — | Microsoft Internet Explorer | 15/7/2019 | 17/6/2026 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'. | |
| Modificada | Alta (7.5) | 7.8% | — | Microsoft Internet Explorer | 15/7/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1001, CVE-2019-1004, CVE-2019-1056. | |
| Modificada | Alta (7.5) | 7.8% | — | Microsoft Internet Explorer | 15/7/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1001, CVE-2019-1004, CVE-2019-1059. | |
| Modificada | Alta (7.5) | 7.8% | — | Microsoft Internet Explorer | 15/7/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1001, CVE-2019-1056, CVE-2019-1059. | |
| Modificada | Alta (7.5) | 8.1% | — | Microsoft ChakracoreMicrosoft Internet ExplorerMicrosoft Edge | 15/7/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1004, CVE-2019-1056, CVE-2019-1059. | |
| Modificada | Alta (7.8) | 0.81% | — | Londontrustmedia Private Internet Access VPN Client | 11/7/2019 | 17/6/2026 | A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux and macOS could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The PIA Linux/macOS binary openvpn_launcher.64 binary is setuid root. This binary accepts several parameters to update… | |
| Modificada | Alta (7.8) | 0.81% | — | Londontrustmedia Private Internet Access VPN Client | 11/7/2019 | 17/6/2026 | A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The openvpn_launcher.64 binary is setuid root. This binary executes /opt/pia/openvpn-64/openvpn, passing the parameters provided… | |
| Modificada | Alta (7.8) | 0.63% | — | Londontrustmedia Private Internet Access VPN Client | 11/7/2019 | 17/6/2026 | A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for macOS could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The macOS binary openvpn_launcher.64 is setuid root. This binary creates /tmp/pia_upscript.sh when executed. Because the file… | |
| Modificada | Alta (7.8) | 0.86% | — | Londontrustmedia Private Internet Access VPN Client | 11/7/2019 | 17/6/2026 | A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for macOS could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The openvpn_launcher binary is setuid root. This program is called during the connection process and executes several operating… | |
| Modificada | Alta (7.8) | 0.91% | — | Londontrustmedia Private Internet Access VPN Client | 11/7/2019 | 17/6/2026 | A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The root_runner.64 binary is setuid root. This binary executes /opt/pia/ruby/64/ruby, which in turn attempts to load several… | |
| Modificada | Alta (7.8) | 2.1% | — | Londontrustmedia Private Internet Access VPN Client | 11/7/2019 | 17/6/2026 | A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v1.0 for Windows could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The PIA client is vulnerable to a DLL injection vulnerability during the software update process. The updater loads several… | |
| Modificada | Alta (7.1) | 0.58% | — | Londontrustmedia Private Internet Access VPN Client | 11/7/2019 | 17/6/2026 | A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux and macOS could allow an authenticated, local attacker to overwrite arbitrary files. The openvpn_launcher binary is setuid root. This binary supports the --log option, which accepts a path as an argument. This parameter is… | |
| Modificada | Alta (7.1) | 0.64% | — | Londontrustmedia Private Internet Access VPN Client | 11/7/2019 | 17/6/2026 | A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v0.9.8 beta (build 02099) for macOS could allow an authenticated, local attacker to overwrite arbitrary files. When the client initiates a connection, the XML /tmp/pia-watcher.plist file is created. If the file exists, it will be… |