Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
–

97 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)2.1%—Pivotal Cloud Foundry Command Line InterfacePivotal Cloud Foundry Command Line Interface ReleasePivotal Cloud Foundry DeploymentPivotal Cloud Foundry Deployment Concourse Tasks+515/8/201917/6/2026
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.
ModificadaCrítica (9.8)30%—Microsoft Forefront Unified Access Gateway5/7/201817/6/2026
uniquesig0/InternalSite/InitParams.aspx in Microsoft Forefront Unified Access Gateway 2010 allows remote attackers to trigger outbound DNS queries for arbitrary hosts via a comma-separated list of URLs in the orig_url parameter, possibly causing a traffic amplification and/or SSRF outcome.
ModificadaAlta (8.8)63%—Microsoft Exchange ServerMicrosoft Security EssentialsMicrosoft Forefront Endpoint Protection 2010Microsoft Intune Endpoint Protection+24/4/201817/6/2026
A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially crafted file, leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability." This affects Windows Defender, Windows Intune Endpoint Protection,…
ModificadaMedia (6.5)1.2%—Efrontlearning Efront5/2/201817/6/2026
Absolute path traversal vulnerability in eFront CMS 3.6.15.4 and earlier allows remote Professor users to obtain sensitive information via a full pathname in the other parameter.
ModificadaMedia (6.5)1.2%—Efrontlearning Efront25/7/201717/6/2026
The file_manager component in eFront CMS before 3.6.15.5 allows remote authenticated users to bypass intended file-upload restrictions by appending a crafted parameter to the file URL.
ModificadaMedia (6.5)1.1%—Efrontlearning Efront25/7/201717/6/2026
Absolute path traversal vulnerability in the file_manager component of eFront CMS before 3.6.15.5 allows remote authenticated users to read arbitrary files via a full pathname in the "Upload file from url" field in the file manager for professor.php.
ModificadaAlta (7.8)44%—Microsoft Windows DefenderMicrosoft Endpoint ProtectionMicrosoft Forefront Endpoint ProtectionMicrosoft Security Essentials+129/6/201717/6/2026
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on 32-bit versions of Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703 does not properly scan a specially crafted…
ModificadaMedia (5.5)6.0%—Microsoft Forefront SecurityMicrosoft Malware Protection EngineMicrosoft Windows Defender26/5/201717/6/2026
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and…
ModificadaAlta (7.8)48%—Microsoft Forefront SecurityMicrosoft Malware Protection EngineMicrosoft Windows Defender26/5/201717/6/2026
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and…
AnalizadaAlta (7.8)72%⚠ Explotación activaMicrosoft Malware Protection EngineMicrosoft Endpoint ProtectionMicrosoft Exchange ServerMicrosoft Forefront Endpoint Protection+526/5/201717/6/2026
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and…
ModificadaMedia (5.5)6.0%—Microsoft Forefront SecurityMicrosoft Malware Protection EngineMicrosoft Windows Defender26/5/201717/6/2026
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and…
ModificadaAlta (7.8)50%—Microsoft Forefront SecurityMicrosoft Malware Protection EngineMicrosoft Windows Defender26/5/201717/6/2026
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and…
ModificadaMedia (5.5)17%—Microsoft Windows DefenderMicrosoft Endpoint ProtectionMicrosoft Exchange ServerMicrosoft Forefront Endpoint Protection+326/5/201717/6/2026
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and…
ModificadaMedia (5.5)17%—Microsoft Windows DefenderMicrosoft Endpoint ProtectionMicrosoft Exchange ServerMicrosoft Forefront Endpoint Protection+326/5/201717/6/2026
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and…
ModificadaMedia (5.5)17%—Microsoft Windows DefenderMicrosoft Endpoint ProtectionMicrosoft Exchange ServerMicrosoft Forefront Endpoint Protection+326/5/201717/6/2026
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and…
ModificadaAlta (7.8)81%—Microsoft Forefront SecurityMicrosoft Malware Protection EngineMicrosoft Windows Defender9/5/201717/6/2026
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 does not properly scan a specially…
ModificadaMedia (6.8)0.78%—Epignosis Efront10/2/201517/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in administrator.php in Epignosis eFront Open Source Edition before 3.6.15.3 build 18022 allow remote attackers to hijack the authentication of administrators for requests that (1) delete modules via the delete_module parameter, (2) deactivate modules via the…
ModificadaMedia (4.3)3.3%—Efrontlearning Efront11/6/201417/6/2026
Cross-site scripting (XSS) vulnerability in libraries/includes/personal/profile.php in Epignosis eFront 3.6.14.4 allows remote attackers to inject arbitrary web script or HTML via the surname parameter to student.php.
ModificadaAlta (10)21%—Microsoft Forefront Protection 201012/2/201417/6/2026
Microsoft Forefront Protection 2010 for Exchange Server does not properly parse e-mail content, which might allow remote attackers to execute arbitrary code via a crafted message, aka "RCE Vulnerability."
ModificadaBaja (3.5)2.6%—Efrontlearning Efront21/12/201317/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in www/administrator.php in eFront 3.6.14 (build 18012) allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) Last name, (2) Lesson name, or (3) Course name field.
ModificadaMedia (5)1.5%—Efrontlearning Efront24/1/201316/6/2026
eFront 3.6.10, 3.6.11 build 15059, and earlier allows remote attackers to obtain sensitive information via invalid courses_ID parameter in the lesson_info module to index.php, which reveals the installation path in an error message.
ModificadaBaja (3.5)0.97%—Efrontlearning Efront13/8/201216/6/2026
Cross-site scripting (XSS) vulnerability in eFront 3.6.11 allows remote authenticated users to inject arbitrary web script or HTML via the subject box of a message.
ModificadaMedia (6)2.1%—Efrontlearning Efront13/8/201216/6/2026
Unrestricted file upload vulnerability in eFront 3.6.11 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension via an attachment in a message.
ModificadaMedia (5)36%—Microsoft Forefront Unified Access Gateway10/4/201216/6/2026
Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 does not properly configure the default web site, which allows remote attackers to obtain sensitive information via a crafted HTTPS request, aka "Unfiltered Access to UAG Default Website Vulnerability."
ModificadaMedia (5.8)11%—Microsoft Forefront Unified Access Gateway10/4/201216/6/2026
Open redirect vulnerability in Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka "UAG Blind HTTP Redirect Vulnerability."