Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
729 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.4) | 2.2% | — | RIM Blackberry Enterprise ServerRIM Blackberry Enterprise Server Express | 14/7/2011 | 16/6/2026 | Unspecified vulnerability in the BlackBerry Administration API in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software 5.0.1 through 5.0.3, and BlackBerry Enterprise Server Express software 5.0.1 through 5.0.3, allows remote attackers to read text files or cause a denial of service via unknown vectors. | |
| Modificada | Media (4.3) | 15% | — | Microsoft Office InfopathMicrosoft SQL ServerMicrosoft SQL Server Management Studio ExpressMicrosoft Visual Studio | 16/6/2011 | 16/6/2026 | The XML Editor in Microsoft InfoPath 2007 SP2 and 2010; SQL Server 2005 SP3 and SP4 and 2008 SP1, SP2, and R2; SQL Server Management Studio Express (SSMSE) 2005; and Visual Studio 2005 SP1, 2008 SP1, and 2010 does not properly handle external entities, which allows remote attackers to read arbitrary files via a… | |
| Modificada | Media (4.3) | 1.9% | — | RIM Blackberry Enterprise ServerRIM Blackberry Enterprise Server Express | 18/4/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in webdesktop/app in the BlackBerry Web Desktop Manager component in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software before 5.0.2 MR5 and 5.0.3 before MR1, and BlackBerry Enterprise Server Express software 5.0.1 and 5.0.2, allows remote attackers to inject… | |
| Modificada | Alta (7.2) | 1.5% | — | Microsoft Windows 2003 ServerMicrosoft Windows 7Microsoft Windows Server 2003Microsoft Windows Server 2008+31 | 13/4/2011 | 16/6/2026 | win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, a different… | |
| Modificada | Media (4.3) | 1.9% | — | SUN Java System Communications Express | 19/1/2011 | 16/6/2026 | Unspecified vulnerability in Oracle Sun Java System Communications Express 6.2 and 6.3 allows remote attackers to affect integrity via unknown vectors related to Web Mail. | |
| Modificada | Alta (9.3) | 5.7% | — | RIM Blackberry Enterprise ServerRIM Blackberry Enterprise Server Express | 13/1/2011 | 16/6/2026 | Multiple buffer overflows in the PDF Distiller in the BlackBerry Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server 4.1.3 through 5.0.2, and Enterprise Server Express 5.0.1 and 5.0.2, allow remote attackers to execute arbitrary code via a crafted PDF file. | |
| Modificada | Alta (7.1) | 1.4% | — | Apple Airport Express Base Station FirmwareApple Airport Extreme Base Station FirmwareApple Airport ExpressApple Airport Extreme+1 | 22/12/2010 | 16/6/2026 | Unspecified vulnerability in the network bridge functionality on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Station with firmware before 7.5.2 allows remote attackers to cause a denial of service (networking outage) via a crafted DHCP reply. | |
| Modificada | Baja (2.6) | 1.7% | — | Apple Airport Express Base Station FirmwareApple Airport Extreme Base Station FirmwareApple Airport ExpressApple Airport Extreme+1 | 22/12/2010 | 16/6/2026 | The Application-Level Gateway (ALG) on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Station with firmware before 7.5.2 modifies PORT commands in incoming FTP traffic, which allows remote attackers to use the device's IP address for arbitrary intranet TCP traffic by leveraging write… | |
| Modificada | Media (6.1) | 0.82% | — | Apple Airport Express Base Station FirmwareApple Airport Extreme Base Station FirmwareApple Airport ExpressApple Airport Extreme+1 | 22/12/2010 | 16/6/2026 | The ICMPv6 implementation on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Station with firmware before 7.5.2 does not limit the rate of (1) Router Advertisement and (2) Neighbor Discovery packets, which allows remote attackers to cause a denial of service (resource consumption and… | |
| Modificada | Alta (7.2) | 0.61% | — | HP Data Protector Express | 13/9/2010 | 16/6/2026 | Unspecified vulnerability in HP Data Protector Express, and Data Protector Express Single Server Edition (SSE), 3.x before build 56936 and 4.x before build 56906 on Windows allows local users to gain privileges or cause a denial of service via unknown vectors, a different vulnerability than CVE-2010-3007. | |
| Modificada | Alta (7.2) | 5.5% | 💥 Exploit | HP Data Protector Express | 9/9/2010 | 16/6/2026 | Unspecified vulnerability in HP Data Protector Express, and Data Protector Express Single Server Edition (SSE), 3.x before build 56936 and 4.x before build 56906 allows local users to gain privileges or cause a denial of service via unknown vectors. | |
| Modificada | Alta (9.3) | 19% | 💥 Exploit | Microsoft Outlook ExpressMicrosoft Windows 2003 ServerMicrosoft Windows 7Microsoft Windows Server 2003+3 | 27/8/2010 | 16/6/2026 | Untrusted search path vulnerability in wab.exe 6.00.2900.5512 in Windows Address Book in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a Trojan horse wab32res.dll file in the current… | |
| Modificada | Alta (7.8) | 2.9% | — | Cisco Unified Contact Center ExpressCisco Customer Response SolutionCisco Unified IP Interactive Voice Response | 10/6/2010 | 16/6/2026 | Directory traversal vulnerability in the bootstrap service in Cisco Unified Contact Center Express (UCCX) 7.0 before 7.0(1)SR4 and 7.0(2), unspecified 6.0 versions, and 5.0 before 5.0(2)SR3 allows remote attackers to read arbitrary files via a crafted bootstrap message to TCP port 6295. | |
| Modificada | Alta (7.8) | 2.5% | — | Cisco Unified Contact Center ExpressCisco Customer Response SolutionCisco Unified IP Interactive Voice Response | 10/6/2010 | 16/6/2026 | The computer telephony integration (CTI) server component in Cisco Unified Contact Center Express (UCCX) 7.0 before 7.0(1)SR4 and 7.0(2), 6.0 before 6.0(1)SR1, and 5.0 before 5.0(2)SR3 allows remote attackers to cause a denial of service (CTI server and Node Manager failure) via a malformed CTI message. | |
| Modificada | Alta (7.8) | 2.7% | — | NEC BladesystemcenterNEC ExpresssystemcenterNEC SigmasystemcenterNEC Virtualpccenter+1 | 19/5/2010 | 16/6/2026 | Unspecified vulnerability in NEC WebSAM DeploymentManager 5.13 and earlier, as used in SigmaSystemCenter 2.1 Update2 and earlier, BladeSystemCenter, ExpressSystemCenter, and VirtualPCCenter 2.2 and earlier, allows remote attackers to cause a denial of service (OS shutdown or restart) via unknown vectors related to… | |
| Modificada | Alta (9.3) | 20% | 💥 Exploit | Microsoft Outlook ExpressMicrosoft Windows Live MailMicrosoft Windows Mail | 12/5/2010 | 16/6/2026 | Integer overflow in inetcomm.dll in Microsoft Outlook Express 5.5 SP2, 6, and 6 SP1; Windows Live Mail on Windows XP SP2 and SP3, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7; and Windows Mail on Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows… | |
| Modificada | Media (4.3) | 1.7% | — | SUN Java System Communications Express | 1/4/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Sun Java System Communications Express 6.2 and 6.3 allows remote attackers to inject arbitrary web script or HTML via the subject field of a message, as demonstrated by a subject containing an IMG element with a SRC attribute that performs a cross-site request forgery (CSRF)… | |
| Modificada | Media (5) | 1.2% | — | Apple Airport ExpressApple Airport ExtremeApple Time Capsule | 10/3/2010 | 16/6/2026 | The FTP proxy server in Apple AirPort Express, AirPort Extreme, and Time Capsule with firmware 7.5 does not restrict the IP address and port specified in a PORT command from a client, which allows remote attackers to leverage intranet FTP servers for arbitrary TCP forwarding via a crafted PORT command. | |
| Modificada | Alta (7.5) | 52% | 💥 Exploit | IBM Cognos Express | 5/2/2010 | 16/6/2026 | IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial of service, by leveraging hardcoded credentials. | |
| Modificada | Alta (7.2) | 0.43% | — | Intel Gm45 ChipsetIntel Pm45 Express ChipsetIntel Q35 ChipsetIntel Q43 Express Chipset+1 | 24/12/2009 | 16/6/2026 | Intel Q35, GM45, PM45 Express, Q45, and Q43 Express chipsets in the SINIT Authenticated Code Module (ACM), which allows local users to bypass the Trusted Execution Technology protection mechanism and gain privileges by modifying the MCHBAR register to point to an attacker-controlled region, which prevents the SENTER… | |
| Modificada | Media (4.3) | 1.3% | — | Symantec Securityexpressions Audit AND Compliance Server | 15/10/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Symantec SecurityExpressions Audit and Compliance Server 4.1.1, 4.1, and earlier allows remote attackers to inject arbitrary web script or HTML via vectors that trigger an error message in a response, related to an "HTML Injection issue." | |
| Modificada | Baja (3.5) | 1.0% | — | Symantec Securityexpressions Audit AND Compliance Server | 15/10/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the console in Symantec SecurityExpressions Audit and Compliance Server 4.1.1, 4.1, and earlier allows remote authenticated users to inject arbitrary web script or HTML via "external client input" that triggers crafted error messages. | |
| Modificada | Alta (9.3) | 23% | — | Microsoft Windows 2003 ServerMicrosoft Windows Server 2008Microsoft Windows VistaMicrosoft Windows XP+22 | 14/10/2009 | 16/6/2026 | Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office… | |
| Modificada | Alta (9.3) | 20% | — | Microsoft Windows 2003 ServerMicrosoft Windows Server 2008Microsoft Windows VistaMicrosoft Windows XP+22 | 14/10/2009 | 16/6/2026 | GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "Memory Corruption Vulnerability." | |
| Modificada | Alta (9.3) | 21% | — | Microsoft Windows 2003 ServerMicrosoft Windows Server 2008Microsoft Windows VistaMicrosoft Windows XP+22 | 14/10/2009 | 16/6/2026 | Multiple integer overflows in unspecified APIs in GDI+ in Microsoft .NET Framework 1.1 SP1, .NET Framework 2.0 SP1 and SP2, Windows XP SP2 and SP3, Windows Server 2003 SP2, Vista Gold and SP1, Server 2008 Gold, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio… |