Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1970 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 14% | — | Microsoft EdgeMicrosoft Internet Explorer | 9/8/2016 | 17/6/2026 | Microsoft Internet Explorer 9 through 11 and Edge allow remote attackers to obtain sensitive information via a crafted web page, aka "Microsoft Browser Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3326. | |
| Modificada | Media (5.3) | 16% | — | Microsoft EdgeMicrosoft Internet Explorer | 9/8/2016 | 17/6/2026 | Microsoft Internet Explorer 9 through 11 and Edge allow remote attackers to obtain sensitive information via a crafted web page, aka "Microsoft Browser Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3327. | |
| Modificada | Alta (7.5) | 14% | — | Microsoft EdgeMicrosoft Internet Explorer | 9/8/2016 | 17/6/2026 | Microsoft Internet Explorer 11 and Edge allow remote attackers to execute arbitrary code via a crafted web page, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3289. | |
| Modificada | Baja (2.5) | 36% | — | Microsoft Internet Explorer | 9/8/2016 | 17/6/2026 | Microsoft Internet Explorer 10 and 11 load different files for attempts to open a file:// URL depending on whether the file exists, which allows local users to enumerate files via vectors involving a file:// URL and an HTML5 sandbox iframe, aka "Internet Explorer Information Disclosure Vulnerability." | |
| Modificada | Alta (7.5) | 15% | — | Microsoft EdgeMicrosoft Internet Explorer | 9/8/2016 | 17/6/2026 | Microsoft Internet Explorer 9 through 11 and Edge allow remote attackers to execute arbitrary code via a crafted web page, aka "Microsoft Browser Memory Corruption Vulnerability." | |
| Modificada | Alta (7.5) | 16% | — | Microsoft Internet Explorer | 9/8/2016 | 17/6/2026 | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code via a crafted web page, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3288. | |
| Modificada | Alta (7.5) | 18% | — | Microsoft EdgeMicrosoft Internet Explorer | 9/8/2016 | 17/6/2026 | Microsoft Internet Explorer 11 and Edge allow remote attackers to execute arbitrary code via a crafted web page, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3322. | |
| Modificada | Alta (7.5) | 52% | 💥 Exploit | Microsoft Internet Explorer | 9/8/2016 | 17/6/2026 | Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code via a crafted web page, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3290. | |
| Modificada | Media (5.3) | 32% | — | Microsoft EdgeMicrosoft Internet Explorer | 13/7/2016 | 17/6/2026 | Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability." | |
| Modificada | Baja (3.1) | 7.2% | — | Microsoft Internet Explorer | 13/7/2016 | 17/6/2026 | Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to conduct content-spoofing attacks via a crafted URL, aka "Microsoft Browser Spoofing Vulnerability." | |
| Modificada | Baja (3.1) | 8.3% | — | Microsoft EdgeMicrosoft Internet Explorer | 13/7/2016 | 17/6/2026 | Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to conduct content-spoofing attacks via a crafted URL, aka "Microsoft Browser Spoofing Vulnerability." | |
| Modificada | Media (5.3) | 14% | — | Microsoft EdgeMicrosoft Internet Explorer | 13/7/2016 | 17/6/2026 | The XSS Filter in Microsoft Internet Explorer 9 through 11 and Microsoft Edge does not properly restrict JavaScript code, which allows remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability." | |
| Modificada | Alta (7.5) | 14% | — | Microsoft EdgeMicrosoft Internet Explorer | 13/7/2016 | 17/6/2026 | Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability." | |
| Modificada | Media (5.3) | 13% | — | Microsoft Internet Explorer | 13/7/2016 | 17/6/2026 | Microsoft Internet Explorer 11 allows remote attackers to obtain sensitive information via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." | |
| Modificada | Alta (8.8) | 23% | — | Microsoft EdgeMicrosoft Internet Explorer | 13/7/2016 | 17/6/2026 | The Microsoft (1) JScript 9, (2) VBScript, and (3) Chakra JavaScript engines, as used in Microsoft Internet Explorer 11, Microsoft Edge, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption… | |
| Modificada | Alta (8.8) | 36% | — | Microsoft EdgeMicrosoft Internet Explorer | 13/7/2016 | 17/6/2026 | The Microsoft (1) JScript 9, (2) VBScript, and (3) Chakra JavaScript engines, as used in Microsoft Internet Explorer 9 through 11, Microsoft Edge, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory… | |
| Modificada | Alta (8.8) | 23% | — | Microsoft EdgeMicrosoft Internet Explorer | 13/7/2016 | 17/6/2026 | The Microsoft (1) JScript 9, (2) VBScript, and (3) Chakra JavaScript engines, as used in Microsoft Internet Explorer 9 through 11, Microsoft Edge, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory… | |
| Modificada | Media (6.5) | 15% | — | Microsoft Internet Explorer | 13/7/2016 | 17/6/2026 | Microsoft Internet Explorer 9 through 11 allows remote attackers to trick users into making TCP connections to a restricted port via a crafted web site, aka "Internet Explorer Security Feature Bypass Vulnerability." | |
| Modificada | Alta (7.5) | 13% | — | Microsoft Internet Explorer | 13/7/2016 | 17/6/2026 | Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." | |
| Modificada | Alta (7.5) | 14% | — | Microsoft Internet Explorer | 13/7/2016 | 17/6/2026 | Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3240 and CVE-2016-3241. | |
| Modificada | Alta (7.5) | 13% | — | Microsoft Internet Explorer | 13/7/2016 | 17/6/2026 | Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3240 and CVE-2016-3242. | |
| Modificada | Alta (7.5) | 14% | — | Microsoft Internet Explorer | 13/7/2016 | 17/6/2026 | Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3241 and CVE-2016-3242. | |
| Modificada | Alta (8.8) | 19% | — | Microsoft Internet Explorer | 13/7/2016 | 17/6/2026 | The Microsoft (1) JScript 5.8 and 9 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability." | |
| Modificada | Alta (8.8) | 67% | — | Microsoft Internet ExplorerMicrosoft Windows 10Microsoft Windows 7Microsoft Windows 8.1+4 | 16/6/2016 | 17/6/2026 | The Web Proxy Auto Discovery (WPAD) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold and 1511, and Internet Explorer 9 through 11 has an improper fallback mechanism, which allows… | |
| Modificada | Media (6.1) | 10% | — | Microsoft Internet Explorer | 16/6/2016 | 17/6/2026 | The XSS Filter in Microsoft Internet Explorer 9 through 11 does not properly identify JavaScript, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site, aka "Internet Explorer XSS Filter Vulnerability." |