Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

455 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)1.6%—Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+514/4/201517/6/2026
Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka…
ModificadaAlta (7.2)2.7%—Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+514/4/201517/6/2026
Microsoft Windows Server 2003 R2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka…
ModificadaAlta (9.3)71%💥 ExploitMicrosoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+511/3/201517/6/2026
Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a Trojan horse DLL in the current working…
ModificadaMedia (5.6)2.7%—Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+511/3/201517/6/2026
The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to cause a denial of service (NULL pointer dereference and blue screen), or obtain…
ModificadaBaja (2.1)2.6%—Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+511/3/201517/6/2026
The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly restrict the availability of address information during a function call, which makes…
ModificadaAlta (9.3)21%—Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+511/3/201517/6/2026
Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font…
ModificadaAlta (9.3)17%—Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+511/3/201517/6/2026
Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font…
ModificadaAlta (9.3)20%—Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+511/3/201517/6/2026
Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font…
ModificadaAlta (9.3)20%—Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+511/3/201517/6/2026
Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font…
ModificadaMedia (5)21%—Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+511/3/201517/6/2026
Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to obtain sensitive information from kernel memory, and possibly bypass the KASLR…
ModificadaAlta (9.3)20%—Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+511/3/201517/6/2026
Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font…
ModificadaMedia (5)23%—Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+511/3/201517/6/2026
Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to obtain sensitive information from kernel memory, and possibly bypass the KASLR…
ModificadaAlta (9.3)24%💥 ExploitMicrosoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+511/3/201517/6/2026
Windows Text Services (WTS) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "WTS…
ModificadaMedia (4.3)15%—Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+511/3/201517/6/2026
Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly initialize memory for rendering of malformed PNG images, which allows remote attackers to obtain sensitive…
ModificadaBaja (2.1)2.4%—Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+511/3/201517/6/2026
The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly initialize function buffers, which allows local users to obtain sensitive information…
ModificadaMedia (4.3)15%—Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+511/3/201517/6/2026
Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly allocate memory, which allows remote attackers to cause a denial of service via a crafted…
ModificadaAlta (7.2)1.8%—Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+511/3/201517/6/2026
The Windows Registry Virtualization feature in the kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly restrict changes to virtual stores, which allows local users to gain…
ModificadaMedia (4.3)13%—Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+56/3/201517/6/2026
Schannel (aka Secure Channel) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly restrict TLS state transitions, which makes it easier for remote attackers to…
ModificadaMedia (4.3)19%—Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+511/2/201517/6/2026
Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly initialize memory for TIFF images, which allows remote attackers to obtain sensitive information from process…
ModificadaMedia (4.7)3.8%💥 ExploitMicrosoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+511/2/201517/6/2026
The font mapper in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly scale fonts, which allows local users to cause a…
ModificadaAlta (7.2)13%💥 ExploitMicrosoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+511/2/201517/6/2026
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Elevation…
ModificadaBaja (1.9)2.5%💥 ExploitMicrosoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+511/2/201517/6/2026
The CryptProtectMemory function in cng.sys (aka the Cryptography Next Generation driver) in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1, when the…
ModificadaBaja (3.3)8.1%💥 ExploitMicrosoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+511/2/201517/6/2026
The Group Policy Security Configuration policy implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows man-in-the-middle attackers to disable a signing…
ModificadaAlta (8.3)29%💥 ExploitMicrosoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+511/2/201517/6/2026
The UNC implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not include authentication from the server to the client, which allows remote attackers to execute…
ModificadaMedia (6.9)4.5%💥 ExploitMicrosoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+511/2/201517/6/2026
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges or cause a denial of service (NULL pointer…
Orbitaley — Vulnerabilidades