Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1970 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 1.1% | — | Fujitsu Fence-explorer | 15/9/2017 | 17/6/2026 | Untrusted search path vulnerability in FENCE-Explorer for Windows V8.4.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (7.5) | 9.0% | — | Microsoft Internet ExplorerMicrosoft Edge | 13/9/2017 | 17/6/2026 | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user due to… | |
| Modificada | Alta (7.5) | 11% | — | Microsoft Internet Explorer | 13/9/2017 | 17/6/2026 | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Internet Explorer… | |
| Modificada | Alta (7.5) | 12% | — | Microsoft EdgeMicrosoft Internet Explorer | 13/9/2017 | 17/6/2026 | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user, due to… | |
| Modificada | Alta (7.5) | 11% | — | Microsoft Internet Explorer | 13/9/2017 | 17/6/2026 | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Internet Explorer… | |
| Modificada | Alta (7.5) | 12% | — | Microsoft EdgeMicrosoft Internet Explorer | 13/9/2017 | 17/6/2026 | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Internet Explorer and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current… | |
| Modificada | Media (4.3) | 8.4% | — | Microsoft Internet ExplorerMicrosoft Edge | 13/9/2017 | 17/6/2026 | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to obtain specific information used in the parent domain, due to… | |
| Modificada | Media (4.3) | 5.2% | — | Microsoft Internet Explorer | 13/9/2017 | 17/6/2026 | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to trick a user into believing that the user was visiting a legitimate website, due to the way that… | |
| Modificada | Alta (7.5) | 3.1% | — | Estrongs ES File Explorer | 28/8/2017 | 17/6/2026 | Directory traversal vulnerability in ES File Explorer 3.2.4.1. | |
| Modificada | Alta (8.8) | 11% | — | Manageengine Servicedesk PlusManageengine AssetexplorerManageengine SupportcenterManageengine It360 | 28/8/2017 | 17/6/2026 | Directory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4 allows remote authenticated users to execute arbitrary code. | |
| Modificada | Alta (8.8) | 78% | 💥 Exploit | Manageengine Servicedesk PlusManageengine AssetexplorerManageengine SupportcenterManageengine It360 | 28/8/2017 | 17/6/2026 | Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4. | |
| Modificada | Alta (7.2) | 1.2% | — | Extplorer | 9/8/2017 | 17/6/2026 | Command inject in transfer from another server in extplorer 2.1.9 and prior allows attacker to inject command via the userfile[0] parameter. | |
| Modificada | Alta (7.5) | 8.5% | — | Microsoft EdgeMicrosoft Internet Explorer | 8/8/2017 | 17/6/2026 | Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user due to Microsoft browsers improperly handling… | |
| Modificada | Alta (7.5) | 9.2% | — | Microsoft EdgeMicrosoft Internet Explorer | 8/8/2017 | 17/6/2026 | Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user due to Microsoft browsers improperly… | |
| Modificada | Alta (7.5) | 5.7% | — | Microsoft Internet Explorer | 8/8/2017 | 17/6/2026 | Internet Explorer in Microsoft Windows Server 2008 SP2 and Windows Server 2012 allows an attacker to execute arbitrary code in the context of the current user due to Internet Explorer improperly accessing objects in memory, aka "Internet Explorer Memory Corruption Vulnerability". | |
| Modificada | Alta (7.5) | 72% | 💥 Exploit | Microsoft EdgeMicrosoft Internet Explorer | 8/8/2017 | 17/6/2026 | Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser… | |
| Modificada | Alta (7.5) | 72% | 💥 Exploit | Microsoft Internet ExplorerMicrosoft Edge | 8/8/2017 | 17/6/2026 | Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser… | |
| Modificada | Alta (7.5) | 56% | 💥 Exploit | Microsoft Internet ExplorerMicrosoft Edge | 8/8/2017 | 17/6/2026 | Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user due to the way that JavaScript engines render… | |
| Modificada | Alta (8.8) | 15% | 💥 PoC | Microsoft Internet Explorer | 8/8/2017 | 17/6/2026 | Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to bypass Device Guard User Mode Code Integrity (UMCI) policies due to Internet Explorer failing to validate UMCI policies, aka "Internet Explorer Security Feature Bypass Vulnerability". | |
| Modificada | Alta (8.8) | 0.70% | — | SMA Sunny BOY 3600 FirmwareSMA Sunny BOY 5000 FirmwareSMA Sunny Tripower Core1 FirmwareSMA Sunny Tripower 15000tl Firmware+36 | 5/8/2017 | 17/6/2026 | An issue was discovered in SMA Solar Technology products. If a user simultaneously has Sunny Explorer running and visits a malicious host, cross-site request forgery can be used to change settings in the inverters (for example, issuing a POST request to change the user password). All Sunny Explorer settings available… | |
| Modificada | Alta (7.5) | 1.7% | — | SMA Sunny Explorer | 5/8/2017 | 17/6/2026 | An issue was discovered in SMA Solar Technology products. When signed into Sunny Explorer with a wrong password, it is possible to create a debug report, disclosing information regarding the application and allowing the attacker to create and save a .txt file with contents to his liking. An attacker may use this for… | |
| Modificada | Alta (7.5) | 1.9% | — | SMA Sunny Explorer | 5/8/2017 | 17/6/2026 | An issue was discovered in SMA Solar Technology products. By sending nonsense data or setting up a TELNET session to the database port of Sunny Explorer, the application can be crashed. NOTE: the vendor reports that the maximum possible damage is a communication failure. Also, only Sunny Boy TLST-21 and TL-21 and… | |
| Modificada | Alta (7.5) | 58% | 💥 Exploit | Microsoft Internet Explorer | 11/7/2017 | 17/6/2026 | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 Internet Explorer in the way affected Microsoft scripting engines render when handling objects in memory, aka "Scripting… | |
| Modificada | Alta (7.5) | 9.4% | — | Microsoft EdgeMicrosoft Internet Explorer | 11/7/2017 | 17/6/2026 | Microsoft browsers in Microsoft Windows Server 2008 and R2, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user when the JavaScript engines fail to render when handling… | |
| Modificada | Alta (7.5) | 9.4% | — | Microsoft EdgeMicrosoft Internet Explorer | 11/7/2017 | 17/6/2026 | Microsoft browsers in Microsoft Windows 7, Windows Server 2008 and R2, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user when the JavaScript engines fail to render… |