Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
2526 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 12% | — | Microsoft EdgeMicrosoft Internet Explorer | 13/9/2017 | 17/6/2026 | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user, due to… | |
| Modificada | Alta (7.5) | 11% | — | Microsoft Internet Explorer | 13/9/2017 | 17/6/2026 | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Internet Explorer… | |
| Modificada | Alta (7.5) | 12% | — | Microsoft EdgeMicrosoft Internet Explorer | 13/9/2017 | 17/6/2026 | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Internet Explorer and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current… | |
| Modificada | Media (4.3) | 8.4% | — | Microsoft Internet ExplorerMicrosoft Edge | 13/9/2017 | 17/6/2026 | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to obtain specific information used in the parent domain, due to… | |
| Modificada | Media (4.3) | 5.2% | — | Microsoft Internet Explorer | 13/9/2017 | 17/6/2026 | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to trick a user into believing that the user was visiting a legitimate website, due to the way that… | |
| Modificada | Alta (7.5) | 0.86% | — | Kaspersky Internet Security | 25/8/2017 | 17/6/2026 | In Kaspersky Internet Security for Android 11.12.4.1622, some of the application trace files were not encrypted. | |
| Modificada | Crítica (9.8) | 1.5% | — | Kaspersky Internet Security | 25/8/2017 | 17/6/2026 | In Kaspersky Internet Security for Android 11.12.4.1622, some of application exports activities have weak permissions, which might be used by a malware application to get unauthorized access to the product functionality by using Android IPC. | |
| Modificada | Alta (7.5) | 8.5% | — | Microsoft EdgeMicrosoft Internet Explorer | 8/8/2017 | 17/6/2026 | Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user due to Microsoft browsers improperly handling… | |
| Modificada | Alta (7.5) | 9.2% | — | Microsoft EdgeMicrosoft Internet Explorer | 8/8/2017 | 17/6/2026 | Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user due to Microsoft browsers improperly… | |
| Modificada | Alta (7.5) | 5.7% | — | Microsoft Internet Explorer | 8/8/2017 | 17/6/2026 | Internet Explorer in Microsoft Windows Server 2008 SP2 and Windows Server 2012 allows an attacker to execute arbitrary code in the context of the current user due to Internet Explorer improperly accessing objects in memory, aka "Internet Explorer Memory Corruption Vulnerability". | |
| Modificada | Alta (7.5) | 72% | 💥 Exploit | Microsoft EdgeMicrosoft Internet Explorer | 8/8/2017 | 17/6/2026 | Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser… | |
| Modificada | Alta (7.5) | 72% | 💥 Exploit | Microsoft Internet ExplorerMicrosoft Edge | 8/8/2017 | 17/6/2026 | Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser… | |
| Modificada | Alta (7.5) | 56% | 💥 Exploit | Microsoft Internet ExplorerMicrosoft Edge | 8/8/2017 | 17/6/2026 | Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user due to the way that JavaScript engines render… | |
| Modificada | Alta (8.8) | 15% | 💥 PoC | Microsoft Internet Explorer | 8/8/2017 | 17/6/2026 | Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to bypass Device Guard User Mode Code Integrity (UMCI) policies due to Internet Explorer failing to validate UMCI policies, aka "Internet Explorer Security Feature Bypass Vulnerability". | |
| Modificada | Alta (7.5) | 1.9% | — | IBM Websphere MQ Internet Pass-thru | 2/8/2017 | 17/6/2026 | IBM WebSphere MQ Internet Pass-Thru 2.0 and 2.1 could allow n attacker to cause the MQIPT to stop responding due to an incorrectly configured security policy. IBM X-Force ID: 121156. | |
| Modificada | Alta (7.8) | 0.79% | — | Internet-soft FTP Commander | 30/7/2017 | 17/6/2026 | InternetSoft FTP Commander 8.02 and prior has an untrusted search path, allowing DLL hijacking via a Trojan horse dwmapi.dll file. | |
| Modificada | Alta (7.8) | 0.74% | — | Panda Security Panda Antivirus PRO 2015Panda Security Panda Global Protection 2015Panda Security Panda Gold Protection 2015Panda Security Panda Internet Security 2015 | 25/7/2017 | 17/6/2026 | Heap-based buffer overflow in Panda Security Kernel Memory Access Driver 1.0.0.13 allows attackers to execute arbitrary code with kernel privileges via a crafted size input for allocated kernel paged pool and allocated non-paged pool buffers. | |
| Modificada | Alta (7.5) | 58% | 💥 Exploit | Microsoft Internet Explorer | 11/7/2017 | 17/6/2026 | Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 Internet Explorer in the way affected Microsoft scripting engines render when handling objects in memory, aka "Scripting… | |
| Modificada | Alta (7.5) | 9.4% | — | Microsoft EdgeMicrosoft Internet Explorer | 11/7/2017 | 17/6/2026 | Microsoft browsers in Microsoft Windows Server 2008 and R2, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user when the JavaScript engines fail to render when handling… | |
| Modificada | Alta (7.5) | 9.4% | — | Microsoft EdgeMicrosoft Internet Explorer | 11/7/2017 | 17/6/2026 | Microsoft browsers in Microsoft Windows 7, Windows Server 2008 and R2, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user when the JavaScript engines fail to render… | |
| Modificada | Alta (7.5) | 9.4% | — | Microsoft EdgeMicrosoft Internet Explorer | 11/7/2017 | 17/6/2026 | Microsoft browsers in Microsoft Windows 7, Windows Server 2008 and R2, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user when the JavaScript engines fail to render… | |
| Modificada | Media (6.5) | 5.3% | — | Microsoft EdgeMicrosoft Internet Explorer | 11/7/2017 | 17/6/2026 | Microsoft browsers on Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow a spoofing vulnerability in the way they parse HTTP content, aka "Microsoft Browser Spoofing Vulnerability." | |
| Modificada | Alta (7.5) | 50% | 💥 Exploit | Microsoft Internet Explorer | 11/7/2017 | 17/6/2026 | Internet Explorer on Microsoft Windows 8.1 and Windows RT 8.1, and Windows Server 2012 R2 allows an attacker to execute arbitrary code in the context of the current user when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability". | |
| Modificada | Media (6.5) | 8.0% | — | Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8.1Microsoft Windows RT 8.1+5 | 11/7/2017 | 17/6/2026 | Microsoft browsers on when Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1, Windows RT 8.1, and Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow a security feature bypass vulnerability when they improperly handle redirect requests, aka "Microsoft Browser… | |
| Modificada | Alta (7.5) | 1.0% | — | Arcadyan Swisscom Internet-box Firmware | 29/6/2017 | 17/6/2026 | Authorization Bypass in the Web interface of Arcadyan SLT-00 Star* (aka Swisscom Internet-Box) devices before R7.7 allows unauthorized reconfiguration of the static routing table via an unauthenticated HTTP request, leading to denial of service and information disclosure. |