Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
2526 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.93% | — | Londontrustmedia Private Internet Access | 21/6/2019 | 17/6/2026 | A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client 1.0.2 (build 02363) for Windows could allow an authenticated, local attacker to run arbitrary code with elevated privileges. On startup, the PIA Windows service (pia-service.exe) loads the OpenSSL library from %PROGRAMFILES%\Private… | |
| Modificada | Media (4.2) | 2.3% | — | Microsoft EdgeMicrosoft Internet Explorer | 12/6/2019 | 17/6/2026 | An information disclosure vulnerability exists when affected Microsoft browsers improperly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit the vulnerability, in a web-based attack scenario, an attacker… | |
| Modificada | Alta (7.5) | 3.3% | — | Microsoft Internet Explorer | 12/6/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability… | |
| Modificada | Alta (7.5) | 3.3% | — | Microsoft Internet Explorer | 12/6/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability… | |
| Modificada | Alta (7.5) | 3.3% | — | Microsoft Internet ExplorerMicrosoft Edge | 12/6/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the… | |
| Modificada | Alta (7.5) | 3.3% | — | Microsoft Internet Explorer | 12/6/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability… | |
| Modificada | Alta (7.5) | 5.7% | — | Microsoft Internet Explorer | 12/6/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability… | |
| Modificada | Media (4.3) | 5.5% | — | Microsoft Internet Explorer | 12/6/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability… | |
| Modificada | Crítica (9.8) | 3.5% | — | Pandasecurity Panda AntivirusPandasecurity Panda Antivirus PROPandasecurity Panda DomePandasecurity Panda Global Protection+2 | 23/5/2019 | 17/6/2026 | Insecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSharedMemoryChange in Panda products before 18.07.03 allow attackers to queue an event (as an encrypted JSON string) to the system service AgentSvc.exe, which leads to privilege escalation when the… | |
| Modificada | Alta (7.8) | 1.5% | — | F-secure Client SecurityF-secure Computer ProtectionF-secure Internet SecurityF-secure PSB Workstation Security+1 | 17/5/2019 | 17/6/2026 | In the F-Secure installer in F-Secure SAFE for Windows before 17.6, F-Secure Internet Security before 17.6, F-Secure Anti-Virus before 17.6, F-Secure Client Security Standard and Premium before 14.10, F-Secure PSB Workstation Security before 12.01, and F-Secure Computer Protection Standard and Premium before 19.3, a… | |
| Modificada | Alta (8.8) | 4.9% | — | Microsoft Internet Explorer | 16/5/2019 | 17/6/2026 | A security feature bypass vulnerability exists when urlmon.dll improperly handles certain Mark of the Web queries, aka 'Internet Explorer Security Feature Bypass Vulnerability'. | |
| Modificada | Alta (7.5) | 23% | — | Microsoft Internet ExplorerMicrosoft Edge | 16/5/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory Corruption Vulnerability'. | |
| Modificada | Media (6.5) | 6.6% | — | Microsoft Internet Explorer | 16/5/2019 | 17/6/2026 | An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory, aka 'Internet Explorer Information Disclosure Vulnerability'. | |
| Modificada | Alta (7.5) | 8.1% | — | Microsoft Internet Explorer | 16/5/2019 | 17/6/2026 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'. | |
| Modificada | Media (6.5) | 3.3% | — | Microsoft Internet Explorer | 16/5/2019 | 17/6/2026 | An spoofing vulnerability exists when Internet Explorer improperly handles URLs, aka 'Internet Explorer Spoofing Vulnerability'. | |
| Modificada | Alta (7.5) | 8.0% | — | Microsoft Internet Explorer | 16/5/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0884, CVE-2019-0911. | |
| Modificada | Alta (7.5) | 9.1% | — | Microsoft ChakracoreMicrosoft Internet ExplorerMicrosoft Edge | 16/5/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0884, CVE-2019-0918. | |
| Modificada | Alta (7.5) | 7.5% | — | Microsoft Internet ExplorerMicrosoft Edge | 16/5/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0911, CVE-2019-0918. | |
| Modificada | Alta (7.5) | 92% | 💥 Exploit | Apache AxisOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+33 | 1/5/2019 | 17/6/2026 | A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version… | |
| Modificada | Alta (7.5) | 11% | — | Microsoft Internet Explorer | 9/4/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0739, CVE-2019-0752, CVE-2019-0753. | |
| Modificada | Media (6.5) | 6.7% | — | Microsoft Internet Explorer | 9/4/2019 | 17/6/2026 | An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory, aka 'Microsoft Scripting Engine Information Disclosure Vulnerability'. | |
| Modificada | Media (6.5) | 3.6% | — | Microsoft Internet ExplorerMicrosoft Edge | 9/4/2019 | 17/6/2026 | A tampering vulnerability exists when Microsoft browsers do not properly validate input under specific conditions, aka 'Microsoft Browsers Tampering Vulnerability'. | |
| Modificada | Alta (7.5) | 9.2% | — | Microsoft Internet Explorer | 9/4/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0739, CVE-2019-0752, CVE-2019-0862. | |
| Analizada | Alta (7.5) | 82% | ⚠ Explotación activa💥 Exploit | Microsoft Internet Explorer | 9/4/2019 | 12/8/2026 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0739, CVE-2019-0753, CVE-2019-0862. | |
| Modificada | Alta (7.5) | 8.1% | — | Microsoft Internet Explorer | 9/4/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0609, CVE-2019-0639, CVE-2019-0680, CVE-2019-0769, CVE-2019-0770, CVE-2019-0771, CVE-2019-0773. |