Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

920 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)18%—Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+411/6/201417/6/2026
The TCP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to cause a denial of service (non-paged pool memory consumption and system hang) via malformed data in…
AnalizadaAlta (8.8)65%⚠ Explotación activa💥 PoCMicrosoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows Server 2008+214/5/201417/6/2026
The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not properly handle distribution of passwords, which allows remote authenticated users to obtain sensitive credential information and…
ModificadaAlta (7.2)1.8%—Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+514/5/201417/6/2026
The ShellExecute API in Windows Shell in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly implement file associations, which allows local users to gain…
ModificadaMedia (6.9)15%—Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+68/4/201417/6/2026
Untrusted search path vulnerability in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a Trojan horse cmd.exe…
ModificadaMedia (6.6)2.9%—Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+612/3/201417/6/2026
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to obtain sensitive information from kernel…
ModificadaMedia (5.4)10%—Microsoft Windows Server 2003Microsoft Windows Server 2008Microsoft Windows Server 2012Microsoft Windows Vista+112/3/201417/6/2026
The Security Account Manager Remote (SAMR) protocol implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows Server 2012 Gold and R2 does not properly determine the user-lockout state, which makes it easier for remote attackers to…
ModificadaAlta (9.3)14%—Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows Server 2003+412/3/201417/6/2026
Double free vulnerability in qedit.dll in DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via a crafted JPEG…
ModificadaAlta (7.2)1.6%—Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+612/3/201417/6/2026
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application,…
ModificadaMedia (4.3)1.8%—Blackboard Vista/ce22/2/201417/6/2026
Cross-site scripting (XSS) vulnerability in Blackboard Vista/CE 8.0 SP6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.1)19%—Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+612/2/201417/6/2026
The XMLHTTP ActiveX controls in XML Core Services 3.0 in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to bypass the Same Origin…
ModificadaMedia (6.9)2.8%💥 ExploitMicrosoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+611/12/201316/6/2026
Integer overflow in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows local users to gain privileges via a crafted application, aka "Win32k…
ModificadaAlta (9.3)20%—Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+611/12/201316/6/2026
Use-after-free vulnerability in the Scripting Runtime Object Library in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to…
ModificadaAlta (7.2)1.8%—Microsoft Windows 7Microsoft Windows 8Microsoft Windows RTMicrosoft Windows Server 2008+211/12/201316/6/2026
portcls.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application, aka "Port-Class Driver Double Fetch Vulnerability."
ModificadaAlta (7.5)1.4%—Osehra Vista4/12/201317/6/2026
The M2M Broker in OSEHRA VistA, as distributed before September 30, 2013, allows attackers to bypass authentication and authorization to perform doctor-only actions and read or modify patient records via unspecified vectors related to a "logic flaw."
ModificadaAlta (7.1)4.8%—Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+618/11/201316/6/2026
DirectAccess in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly verify server X.509 certificates, which allows…
ModificadaAlta (9.3)34%—Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+613/11/201316/6/2026
Integer overflow in the Graphics Device Interface (GDI) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary…
ModificadaMedia (4.9)2.6%—Microsoft Windows 7Microsoft Windows 8Microsoft Windows Server 2003Microsoft Windows Server 2008+313/11/201316/6/2026
The Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 allows local users to obtain sensitive information from kernel memory by leveraging…
ModificadaMedia (5)17%—Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+613/11/201316/6/2026
Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to cause a denial of service (daemon hang) via a web-service request containing a…
AnalizadaAlta (8.8)74%⚠ Explotación activa💥 ExploitMicrosoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+612/11/201316/6/2026
The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to…
AnalizadaAlta (7.8)85%⚠ Explotación activa💥 ExploitMicrosoft Excel ViewerMicrosoft LyncMicrosoft OfficeMicrosoft Office Compatibility Pack+46/11/201316/6/2026
GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync 2010, 2010 Attendee, 2013, and Basic 2013 allows remote attackers to execute arbitrary code via a crafted TIFF image, as demonstrated by an image in a Word document, and…
ModificadaAlta (8.1)43%—Microsoft Windows 7Microsoft Windows 8Microsoft Windows RTMicrosoft Windows Server 2003+49/10/201316/6/2026
The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allow remote attackers to execute arbitrary code via a crafted CMAP table in a TrueType font (TTF) file, aka…
ModificadaAlta (8.4)1.0%—Microsoft Windows 7Microsoft Windows Server 2008Microsoft Windows Vista9/10/201316/6/2026
dxgkrnl.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "DirectX Graphics Kernel Subsystem Double Fetch Vulnerability."
ModificadaAlta (7.2)1.8%—Microsoft Windows 7Microsoft Windows 8Microsoft Windows RTMicrosoft Windows Server 2003+49/10/201316/6/2026
Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application, aka…
ModificadaAlta (7.2)5.4%—Microsoft Windows 7Microsoft Windows 8Microsoft Windows RTMicrosoft Windows Server 2003+49/10/201316/6/2026
The USB drivers in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allow physically proximate attackers to execute arbitrary code by connecting a crafted USB…
ModificadaAlta (10)38%—Microsoft Windows 7Microsoft Windows 8Microsoft Windows RTMicrosoft Windows Server 2003+49/10/201316/6/2026
The DSA_InsertItem function in Comctl32.dll in the Windows common control library in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly allocate memory, which allows remote attackers…
Orbitaley — Vulnerabilidades