Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
87 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.82% | — | Redhat Openshift Serverless | 26/8/2022 | 17/6/2026 | It was found that the CVE-2021-27918, CVE-2021-31525 and CVE-2021-33196 have been incorrectly mentioned as fixed in RHSA for Serverless 1.16.0 and Serverless client kn 1.16.0. These have been fixed with Serverless 1.17.0. | |
| Modificada | Alta (8.8) | 0.82% | — | Matrix DendriteGomatrixserverlib | 19/8/2022 | 17/6/2026 | gomatrixserverlib is a Go library for matrix protocol federation. Dendrite is a Matrix homeserver written in Go, an alternative to Synapse. The power level parsing within gomatrixserverlib was failing to parse the `"events_default"` key of the `m.room.power_levels` event, defaulting the event default power level to… | |
| Modificada | Media (6.5) | 1.2% | — | Goverlan Client AgentGoverlan Reach ConsoleGoverlan Reach Server | 20/5/2022 | 17/6/2026 | In certain Goverlan products, the Windows Firewall is temporarily turned off upon a Goverlan agent update operation. This allows remote attackers to bypass firewall blocking rules for a time period of up to 30 seconds. This affects Goverlan Reach Console before 10.5.1, Reach Server before 3.70.1, and Reach Client… | |
| Modificada | Crítica (9.8) | 1.5% | — | Serverless Offline Project Serverless Offline | 10/8/2021 | 17/6/2026 | Serverless Offline 8.0.0 returns a 403 HTTP status code for a route that has a trailing / character, which might cause a developer to implement incorrect access control, because the actual behavior within the Amazon AWS environment is a 200 HTTP status code (i.e., possibly greater than expected permissions). | |
| Modificada | Media (6.1) | 0.95% | — | Hapifhir Testpage Overlay | 8/10/2020 | 17/6/2026 | Users of the HAPI FHIR Testpage Overlay 5.0.0 and below can use a specially crafted URL to exploit an XSS vulnerability in this module, allowing arbitrary JavaScript to be executed in the user's browser. The impact of this vulnerability is believed to be low, as this module is intended for testing and not believed to… | |
| Modificada | Alta (8.8) | 2.3% | — | Jenkins Amazon WEB Services Serverless Application Model | 16/4/2020 | 17/6/2026 | Jenkins AWS SAM Plugin 1.2.2 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability. | |
| Modificada | Alta (7.5) | 1.2% | — | Telerik UI FOR Silverlight | 31/3/2020 | 17/6/2026 | An issue was discovered in Progress Telerik UI for Silverlight before 2020.1.330. The RadUploadHandler class in RadUpload for Silverlight expects a web request that provides the file location of the uploading file along with a few other parameters. The uploading file location should be inside the directory where the… | |
| Modificada | Alta (7.8) | 0.72% | — | Goverlan Client AgentGoverlan Reach ConsoleGoverlan Reach Server | 16/2/2020 | 17/6/2026 | Goverlan Reach Console before 9.50, Goverlan Reach Server before 3.50, and Goverlan Client Agent before 9.20.50 have an Untrusted Search Path that leads to Command Injection and Local Privilege Escalation via DLL hijacking. | |
| Modificada | Baja (3.1) | 0.59% | — | Jenkins Aqua Security Severless Scanner | 12/9/2019 | 17/6/2026 | Jenkins Aqua Security Serverless Scanner Plugin 1.0.4 and earlier transmitted configured passwords in plain text as part of job configuration forms, potentially resulting in their exposure. | |
| Modificada | Alta (7.5) | 2.0% | — | Serverliujiayi1 Project Serverliujiayi1 | 7/6/2018 | 17/6/2026 | serverliujiayi1 is a simple http server. serverliujiayi1 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL. | |
| Modificada | Alta (7.5) | 2.0% | — | Serverlyr Project Serverlyr | 7/6/2018 | 17/6/2026 | serverlyr is a simple http server. serverlyr is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL. | |
| Modificada | Alta (8.8) | 19% | — | Microsoft LyncMicrosoft OfficeMicrosoft SilverlightMicrosoft Skype FOR Business+7 | 15/6/2017 | 17/6/2026 | Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to the way it handles objects in memory, aka "Windows Graphics Remote Code Execution… | |
| Modificada | Alta (8.8) | 39% | — | Microsoft LyncMicrosoft OfficeMicrosoft Office Word ViewerMicrosoft Silverlight+7 | 15/6/2017 | 17/6/2026 | Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, Windows Server 2016, Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office Word Viewer, Microsoft Lync 2013 SP1, Skype for Business 2016, Microsoft… | |
| Modificada | Alta (7.8) | 50% | — | Microsoft Live MeetingMicrosoft LyncMicrosoft OfficeMicrosoft Silverlight+5 | 17/3/2017 | 17/6/2026 | The Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Live Meeting 2007; Silverlight 5; Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site,… | |
| Modificada | Media (5.5) | 54% | — | Microsoft .net FrameworkMicrosoft Live MeetingMicrosoft LyncMicrosoft Office+10 | 14/10/2016 | 17/6/2026 | Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010;… | |
| Modificada | Alta (8.8) | 18% | — | Microsoft Silverlight | 14/9/2016 | 17/6/2026 | StringBuilder in Microsoft Silverlight 5 before 5.1.50709.0 does not properly allocate memory for string-insert and string-append operations, which allows remote attackers to execute arbitrary code via a crafted web site, aka "Microsoft Silverlight Memory Corruption Vulnerability." | |
| Analizada | Alta (8.8) | 69% | ⚠ Explotación activa | Microsoft Silverlight | 13/1/2016 | 14/8/2026 | Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) via a crafted web site, aka "Silverlight Runtime Remote Code Execution Vulnerability." | |
| Modificada | Alta (9.3) | 14% | — | Microsoft Silverlight | 9/12/2015 | 17/6/2026 | Microsoft Silverlight 5 before 5.1.41105.00 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read or write access) via unspecified open and close requests, aka "Microsoft Silverlight RCE Vulnerability." | |
| Modificada | Media (4.3) | 16% | — | Microsoft Silverlight | 9/12/2015 | 17/6/2026 | Microsoft Silverlight 5 before 5.1.41105.00 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Silverlight Information Disclosure Vulnerability," a different vulnerability than CVE-2015-6114. | |
| Modificada | Media (4.3) | 19% | — | Microsoft Silverlight | 9/12/2015 | 17/6/2026 | Microsoft Silverlight 5 before 5.1.41105.00 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Silverlight Information Disclosure Vulnerability," a different vulnerability than CVE-2015-6165. | |
| Modificada | Alta (9.3) | 26% | — | Microsoft Live MeetingMicrosoft LyncMicrosoft OfficeMicrosoft Silverlight+11 | 9/12/2015 | 17/6/2026 | The Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT Gold and 8.1; Office 2007 SP3; Office 2010 SP2; Word Viewer; .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6; Skype for… | |
| Modificada | Alta (9.3) | 36% | — | Microsoft .net FrameworkMicrosoft Live MeetingMicrosoft LyncMicrosoft Lync Basic+10 | 15/8/2015 | 17/6/2026 | Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, Lync Basic 2013 SP1, Silverlight before 5.1.40728, and… | |
| Modificada | Alta (9.3) | 34% | — | Microsoft .net FrameworkMicrosoft Live MeetingMicrosoft LyncMicrosoft Lync Basic+10 | 15/8/2015 | 17/6/2026 | Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, Lync Basic 2013 SP1, Silverlight before 5.1.40728, and… | |
| Modificada | Alta (9.3) | 36% | — | Microsoft .net FrameworkMicrosoft Live MeetingMicrosoft LyncMicrosoft Lync Basic+11 | 15/8/2015 | 17/6/2026 | Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10, Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, Lync Basic 2013 SP1, Silverlight before… | |
| Modificada | Alta (9.3) | 37% | — | Microsoft .net FrameworkMicrosoft Live MeetingMicrosoft LyncMicrosoft Lync Basic+11 | 15/8/2015 | 17/6/2026 | Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10, Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, Lync Basic 2013 SP1, Silverlight before… |