Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
2526 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 8.0% | — | Microsoft Internet ExplorerMicrosoft Edge | 9/4/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory Corruption Vulnerability'. | |
| Modificada | Media (4.3) | 49% | 💥 Exploit | Microsoft Internet Explorer | 9/4/2019 | 17/6/2026 | A security feature bypass vulnerability exists when Internet Explorer VBScript execution policy does not properly restrict VBScript under specific conditions, and to allow requests that should otherwise be ignored, aka 'Internet Explorer Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0761. | |
| Modificada | Alta (7.5) | 8.1% | — | Microsoft Internet Explorer | 9/4/2019 | 17/6/2026 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'. | |
| Modificada | Media (4.3) | 4.5% | — | Microsoft Internet ExplorerMicrosoft Edge | 9/4/2019 | 17/6/2026 | A security feature bypass vulnerability exists when Microsoft browsers improperly handle requests of different origins, aka 'Microsoft Browsers Security Feature Bypass Vulnerability'. | |
| Modificada | Media (6.5) | 3.9% | — | Microsoft Internet Explorer | 9/4/2019 | 17/6/2026 | A security feature bypass vulnerability exists when Internet Explorer fails to validate the correct Security Zone of requests for specific URLs, aka 'Internet Explorer Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0768. | |
| Modificada | Media (6.5) | 6.6% | — | Microsoft Internet ExplorerMicrosoft EdgeMicrosoft Chakracore | 9/4/2019 | 17/6/2026 | An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft Edge, aka 'Scripting Engine Information Disclosure Vulnerability'. | |
| Modificada | Alta (7.5) | 8.1% | — | Microsoft Internet Explorer | 9/4/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0609, CVE-2019-0639, CVE-2019-0769, CVE-2019-0770, CVE-2019-0771, CVE-2019-0773, CVE-2019-0783. | |
| Modificada | Alta (7.5) | 31% | 💥 Exploit | Microsoft Internet Explorer | 8/4/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0665, CVE-2019-0666, CVE-2019-0772. | |
| Modificada | Alta (7.5) | 20% | — | Microsoft Internet Explorer | 8/4/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0665, CVE-2019-0667, CVE-2019-0772. | |
| Modificada | Alta (7.5) | 8.3% | — | Microsoft Internet Explorer | 8/4/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0666, CVE-2019-0667, CVE-2019-0772. | |
| Modificada | Alta (7.5) | 12% | — | Microsoft Internet Explorer | 8/4/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0609, CVE-2019-0680, CVE-2019-0769, CVE-2019-0770, CVE-2019-0771, CVE-2019-0773, CVE-2019-0783. | |
| Modificada | Alta (7.5) | 9.8% | — | Microsoft ChakracoreMicrosoft Internet ExplorerMicrosoft Edge | 8/4/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0639, CVE-2019-0680, CVE-2019-0769, CVE-2019-0770, CVE-2019-0771, CVE-2019-0773, CVE-2019-0783. | |
| Modificada | Alta (7.5) | 1.6% | — | Jenzabar Internet Campus SolutionTiny Moxiemanager | 25/3/2019 | 17/6/2026 | Jenzabar JICS (aka Internet Campus Solution) before 9 allows remote attackers to upload and execute arbitrary .aspx code by placing it in a ZIP archive and using the MoxieManager (for .NET) plugin before 2.1.4 in the moxiemanager directory within the installation folder ICS\ICS.NET\ICSFileServer. | |
| Modificada | Crítica (9.8) | 2.1% | — | Jenzabar Internet Campus Solution | 25/3/2019 | 17/6/2026 | ICS/StaticPages/AddTestUsers.aspx in Jenzabar JICS (aka Internet Campus Solution) before 2019-02-06 allows remote attackers to create an arbitrary number of accounts with a password of 1234. | |
| Analizada | Media (6.5) | 8.1% | ⚠ Explotación activa | Microsoft Internet Explorer | 5/3/2019 | 17/6/2026 | An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited this vulnerability could test for the presence of files on disk, aka 'Internet Explorer Information Disclosure Vulnerability'. | |
| Modificada | Media (4.3) | 2.8% | — | Microsoft Internet ExplorerMicrosoft Edge | 5/3/2019 | 17/6/2026 | A spoofing vulnerability exists when Microsoft browsers improperly handles specific redirects, aka 'Microsoft Browser Spoofing Vulnerability'. | |
| Modificada | Alta (7.5) | 11% | — | Microsoft Internet Explorer | 5/3/2019 | 17/6/2026 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'. | |
| Modificada | Alta (7.1) | 0.21% | — | Qualcomm Snapdragon Auto FirmwareQualcomm Snapdragon Compute FirmwareQualcomm Snapdragon Consumer Internet OF Things FirmwareQualcomm Snapdragon Industrial Internet OF Things Firmware+26 | 25/2/2019 | 17/6/2026 | Improperly configured memory protection allows read/write access to modem image from HLOS kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in versions MDM9150, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9650, MDM9655, MSM8996AU, QCS605, SD 636, SD 675,… | |
| Modificada | Alta (7.8) | 0.21% | — | Qualcomm Snapdragon Auto FirmwareQualcomm Snapdragon Consumer Internet OF Things FirmwareQualcomm Snapdragon Industrial Internet OF Things FirmwareQualcomm Mdm9150 Firmware+14 | 25/2/2019 | 17/6/2026 | Lack of input validation for data received from user space can lead to an out of bound array issue in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in version MDM9150, MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 636, SD 820A,… | |
| Modificada | Alta (7.8) | 0.22% | — | Qualcomm Snapdragon Auto FirmwareQualcomm Snapdragon Consumer Internet OF Things FirmwareQualcomm Snapdragon Industrial Internet OF Things FirmwareQualcomm Snapdragon Internet OF Things Firmware+37 | 25/2/2019 | 17/6/2026 | Improper validation of array index can lead to unauthorized access while processing debugFS in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in version MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W,… | |
| Modificada | Media (5.5) | 0.20% | — | Qualcomm Snapdragon Auto FirmwareQualcomm Snapdragon Connectivity FirmwareQualcomm Snapdragon Consumer Internet OF Things FirmwareQualcomm Snapdragon Industrial Internet OF Things Firmware+32 | 25/2/2019 | 17/6/2026 | Arbitrary write issue can occur when user provides kernel address in compat mode in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU,… | |
| Modificada | Alta (7.8) | 1.8% | 💥 PoC | Trendmicro Antivirus + SecurityTrendmicro Internet SecurityTrendmicro Maximum SecurityTrendmicro Premium Security | 5/2/2019 | 17/6/2026 | A DLL hijacking vulnerability in Trend Micro Security 2019 (Consumer) versions below 15.0.0.1163 and below could allow an attacker to manipulate a specific DLL and escalate privileges on vulnerable installations. | |
| Analizada | Alta (8.8) | 53% | ⚠ Explotación activa💥 Exploit | Microsoft Internet ExplorerMicrosoft Excel ViewerMicrosoft OfficeMicrosoft Office 365 Proplus+1 | 8/1/2019 | 17/6/2026 | A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10,… | |
| Analizada | Alta (7.5) | 30% | ⚠ Explotación activa | Microsoft Internet Explorer | 20/12/2018 | 17/6/2026 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8643. | |
| Modificada | Alta (7.5) | 0.70% | — | Swisscom Internet-box Standard FirmwareSwisscom Internet-box Light FirmwareSwisscom Internet-box Plus FirmwareSwisscom Internet-box 2 Firmware | 17/12/2018 | 17/6/2026 | A stack-based buffer overflow in the LAN UPnP service running on UDP port 1900 of Swisscom Internet-Box (2, Standard, and Plus) prior to v09.04.00 and Internet-Box light prior to v08.05.02 allows remote code execution. No authentication is required to exploit this vulnerability. Sending a simple UDP packet to port… |