Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
123 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.33% | — | GFI Mailessentials | 28/4/2025 | 17/6/2026 | GFI MailEssentials prior to version 21.8 is vulnerable to a local privilege escalation issue. A local attacker can escalate to NT Authority/SYSTEM by sending a crafted serialized payload to a .NET Remoting Service. | |
| Aplazada | Media (6.4) | 0.35% | — | Monkee BOY EssentialsAI | 26/10/2024 | 17/6/2026 | The Monkee-Boy Essentials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject… | |
| Modificada | Crítica (9.8) | 1.2% | — | Jsgui-lang-essentials Project Jsgui-lang-essentials | 1/5/2022 | 17/6/2026 | All versions of package jsgui-lang-essentials are vulnerable to Prototype Pollution due to allowing all Object attributes to be altered, including their magical attributes such as proto, constructor and prototype. | |
| Modificada | Alta (7.8) | 0.61% | — | Microsoft Windows DefenderMicrosoft Endpoint ProtectionMicrosoft Security EssentialsMicrosoft System Center Endpoint Protection | 25/2/2021 | 17/6/2026 | Microsoft Defender Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.8) | 39% | ⚠ Explotación activa | Microsoft Windows DefenderMicrosoft Security EssentialsMicrosoft System Center Endpoint Protection | 12/1/2021 | 17/6/2026 | Microsoft Defender Remote Code Execution Vulnerability | |
| Modificada | Alta (7.1) | 0.72% | — | Microsoft Windows DefenderMicrosoft Forefront Endpoint Protection 2010Microsoft Security EssentialsMicrosoft System Center Endpoint Protection | 14/7/2020 | 17/6/2026 | An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'. | |
| Modificada | Alta (7.8) | 1.6% | — | Microsoft Windows DefenderMicrosoft Forefront Endpoint Protection 2010Microsoft Security EssentialsMicrosoft System Center Endpoint Protection | 9/6/2020 | 17/6/2026 | An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Defender Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1163. | |
| Modificada | Alta (7.8) | 0.89% | — | Microsoft Windows DefenderMicrosoft Forefront Endpoint Protection 2010Microsoft Security EssentialsMicrosoft System Center Endpoint Protection | 9/6/2020 | 17/6/2026 | An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Defender Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1170. | |
| Modificada | Alta (7.1) | 0.71% | — | Microsoft Windows DefenderMicrosoft Forefront Endpoint Protection 2010Microsoft Security EssentialsMicrosoft System Center Endpoint Protection | 15/4/2020 | 17/6/2026 | An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'. | |
| Modificada | Crítica (9.8) | 10% | — | HP Storage Essentials | 10/3/2020 | 17/6/2026 | In HPE Storage Essentials 9.5.0.142, there is Unauthenticated Java Deserialization with remote code execution via OS commands in a request to invoker/JMXInvokerServlet, aka PSRT110461. | |
| Modificada | Crítica (9.8) | 2.9% | — | IBM Change AND Configuration Management DatabaseIBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Maximo FOR Government+9 | 18/2/2020 | 16/6/2026 | A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to a failure to invalidate the authentication session, which could let a malicious user obtain unauthorized access. | |
| Modificada | Alta (7.5) | 4.1% | — | Microsoft Windows DefenderMicrosoft Forefront Endpoint Protection 2010Microsoft Security EssentialsMicrosoft System Center Endpoint Protection | 23/9/2019 | 17/6/2026 | A denial of service vulnerability exists when Microsoft Defender improperly handles files, aka 'Microsoft Defender Denial of Service Vulnerability'. | |
| Modificada | Alta (7.1) | 0.95% | — | Microsoft Windows DefenderMicrosoft Forefront Endpoint Protection 2010Microsoft Security EssentialsMicrosoft System Center Endpoint Protection | 14/8/2019 | 17/6/2026 | An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted command that could exploit the vulnerability and delete… | |
| Modificada | Alta (7.6) | 0.99% | — | Gigasoft ProessentialsGE Communicator | 2/10/2018 | 17/6/2026 | A heap-based buffer overflow exists in the third-party product Gigasoft, v5 and prior, included in GE Communicator 3.15 and prior. A malicious HTML file that loads the ActiveX controls can trigger the vulnerability via unchecked function calls. | |
| Modificada | Alta (8.8) | 63% | — | Microsoft Exchange ServerMicrosoft Security EssentialsMicrosoft Forefront Endpoint Protection 2010Microsoft Intune Endpoint Protection+2 | 4/4/2018 | 17/6/2026 | A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially crafted file, leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability." This affects Windows Defender, Windows Intune Endpoint Protection,… | |
| Modificada | Media (4.3) | 0.97% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Maximo FOR Energy OptimizationIBM Maximo FOR Aviation+10 | 27/3/2018 | 17/6/2026 | IBM Maximo Asset Management 7.1, 7.5, and 7.6; Maximo Asset Management Essentials 7.1 and 7.5; Control Desk 7.5 and 7.6; Tivoli Asset Management for IT 7.1 and 7.2; and certain other IBM products allow remote authenticated users to bypass intended access restrictions and read arbitrary ticket worklog entries via… | |
| Modificada | Alta (8.8) | 1.5% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management Essentials | 22/2/2018 | 17/6/2026 | IBM Maximo Asset Management 7.5 and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 138820. | |
| Modificada | Alta (8.8) | 2.2% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management Essentials | 14/2/2018 | 17/6/2026 | IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to include arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable Web server. IBM X-Force ID: 129106. | |
| Modificada | Media (6.1) | 0.99% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management Essentials | 13/12/2017 | 17/6/2026 | IBM Maximo Asset Management 7.5 and 7.6 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that… | |
| Modificada | Media (4.3) | 0.91% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management Essentials | 9/8/2017 | 17/6/2026 | IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to manipulate work orders to forge emails which could be used to conduct further advanced attacks. IBM X-Force ID: 126684. | |
| Modificada | Alta (7.8) | 44% | — | Microsoft Windows DefenderMicrosoft Endpoint ProtectionMicrosoft Forefront Endpoint ProtectionMicrosoft Security Essentials+1 | 29/6/2017 | 17/6/2026 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on 32-bit versions of Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703 does not properly scan a specially crafted… | |
| Modificada | Alta (8.8) | 1.8% | — | IBM Maximo Asset ManagementIBM Maximo Asset Management Essentials | 7/6/2017 | 17/6/2026 | IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier. An attacker could exploit this vulnerability to gain access to another user's session. IBM X-Force ID: 120253. | |
| Analizada | Alta (7.8) | 72% | ⚠ Explotación activa | Microsoft Malware Protection EngineMicrosoft Endpoint ProtectionMicrosoft Exchange ServerMicrosoft Forefront Endpoint Protection+5 | 26/5/2017 | 17/6/2026 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and… | |
| Modificada | Media (5.5) | 17% | — | Microsoft Windows DefenderMicrosoft Endpoint ProtectionMicrosoft Exchange ServerMicrosoft Forefront Endpoint Protection+3 | 26/5/2017 | 17/6/2026 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and… | |
| Modificada | Media (5.5) | 17% | — | Microsoft Windows DefenderMicrosoft Endpoint ProtectionMicrosoft Exchange ServerMicrosoft Forefront Endpoint Protection+3 | 26/5/2017 | 17/6/2026 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and… |