Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

2526 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)13%—Microsoft Internet Explorer27/6/201717/6/2026
Internet Explorer 6, Internet Explorer 7, Internet Explorer 8, Internet Explorer 9, Internet Explorer 10, and Internet Explorer 11 allows remote attackers to execute arbitrary code.
ModificadaAlta (7.5)6.1%—Microsoft Internet Explorer15/6/201717/6/2026
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, and Windows Server 2012 and R2 allow an attacker to execute arbitrary code in the context of the current user when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption…
ModificadaMedia (6.5)14%💥 PoCMicrosoft Internet ExplorerMicrosoft Edge15/6/201717/6/2026
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, and Windows Server 2012 and R2 allow an attacker to detect specific files on the user's computer when affected Microsoft scripting engines do not properly handle objects in memory, aka "Microsoft Browser…
ModificadaAlta (7.5)9.8%—Microsoft Internet ExplorerMicrosoft Edge15/6/201717/6/2026
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an allow an attacker to execute arbitrary code in the context of the current user when the JavaScript engines fail…
ModificadaAlta (7.5)8.2%—Microsoft Internet ExplorerMicrosoft Edge15/6/201717/6/2026
Microsoft browsers in Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an allow an attacker to execute arbitrary code in the context of the current user when the JavaScript engines fail to render when handling objects in memory…
ModificadaAlta (7.5)6.1%—Microsoft Internet Explorer15/6/201717/6/2026
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, and Windows Server 2012 and R2 allow an attacker to execute arbitrary code in the context of the current user when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory…
ModificadaAlta (7.5)8.2%—Microsoft Internet Explorer15/6/201717/6/2026
Microsoft browsers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an allow an attacker to execute arbitrary code in the context of the current user when the JavaScript engines fail to…
ModificadaAlta (7.5)18%—Microsoft EdgeMicrosoft Internet Explorer12/5/201717/6/2026
A remote code execution vulnerability exists in Microsoft browsers in the way JavaScript scripting engines handle objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0224, CVE-2017-0228, CVE-2017-0229, CVE-2017-0230, CVE-2017-0234, CVE-2017-0235, and…
ModificadaMedia (4.3)3.7%—Microsoft EdgeMicrosoft Internet Explorer12/5/201717/6/2026
A spoofing vulnerability exists when Microsoft browsers render SmartScreen Filter, aka "Microsoft Browser Spoofing Vulnerability."
ModificadaAlta (7.5)17%—Microsoft EdgeMicrosoft Internet Explorer12/5/201717/6/2026
A remote code execution vulnerability exists in Microsoft browsers in the way JavaScript engines render when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0224, CVE-2017-0229, CVE-2017-0230, CVE-2017-0234, CVE-2017-0235, CVE-2017-0236, and…
ModificadaAlta (7.5)9.8%—Microsoft Internet Explorer12/5/201717/6/2026
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0222.
AnalizadaAlta (8.8)30%⚠ Explotación activaMicrosoft Internet Explorer12/5/201717/6/2026
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0226.
ModificadaMedia (6.5)5.2%—Microsoft Internet Explorer12/5/201717/6/2026
A security feature bypass vulnerability exists in Internet Explorer that allows for bypassing Mixed Content warnings, aka "Internet Explorer Security Feature Bypass Vulnerability."
ModificadaAlta (7.5)0.93%—Quickheal Antivirus PROQuickheal Internet SecurityQuickheal Total Security4/5/201717/6/2026
Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 have approximately 165 PE files in the default installation that do not use ASLR/DEP protection mechanisms that provide sufficient defense against directed attacks against the product.
ModificadaCrítica (9.8)1.2%—Quickheal Antivirus PROQuickheal Internet SecurityQuickheal Total Security4/5/201717/6/2026
Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are vulnerable to Memory Corruption while parsing a malformed Mach-O file.
ModificadaCrítica (9.8)1.2%—Quickheal Antivirus PROQuickheal Internet SecurityQuickheal Total Security4/5/201717/6/2026
Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are vulnerable to Memory Corruption while parsing a malformed Mach-O file.
ModificadaCrítica (9.8)2.3%—Quickheal Antivirus PROQuickheal Internet SecurityQuickheal Total Security4/5/201717/6/2026
Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are vulnerable to Out of Bounds Write on a Heap Buffer due to improper validation of dwCompressionSize of Microsoft WIM Header WIMHEADER_V1_PACKED. This vulnerability can be exploited to gain Remote…
AnalizadaAlta (8.8)22%⚠ Explotación activaMicrosoft Internet Explorer12/4/201717/6/2026
An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain, aka "Internet Explorer Elevation of Privilege Vulnerability."
ModificadaAlta (7.5)46%💥 ExploitMicrosoft Internet Explorer12/4/201717/6/2026
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user, a.k.a. "Internet Explorer Memory Corruption Vulnerability."
ModificadaAlta (7.5)14%—Microsoft Internet Explorer12/4/201717/6/2026
A remote code execution vulnerability exists in Internet Explorer in the way that the JScript and VBScript engines render when handling objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user, aka "Scripting Engine Memory…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitMicrosoft Internet Information Services27/3/201717/6/2026
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with "If: <http://" in a PROPFIND request, as exploited in the wild in July or August…
ModificadaMedia (6.7)0.94%—Avira Free Security SuiteAvira Internet Security SuiteAvira Optimization SuiteAvira Total Security Suite21/3/201717/6/2026
Code injection vulnerability in Avira Total Security Suite 15.0 (and earlier), Optimization Suite 15.0 (and earlier), Internet Security Suite 15.0 (and earlier), and Free Security Suite 15.0 (and earlier) allows a local attacker to bypass a self-protection mechanism, inject arbitrary code, and take full control of any…
ModificadaMedia (6.7)0.75%—Bitdefender Antivirus PlusBitdefender Internet SecurityBitdefender Total Security21/3/201717/6/2026
Code injection vulnerability in Bitdefender Total Security 12.0 (and earlier), Internet Security 12.0 (and earlier), and Antivirus Plus 12.0 (and earlier) allows a local attacker to bypass a self-protection mechanism, inject arbitrary code, and take full control of any Bitdefender process via a "DoubleAgent" attack.…
ModificadaMedia (6.7)0.53%—Avast Free AntivirusAvast Internet SecurityAvast PremierAvast PRO Antivirus21/3/201717/6/2026
Code injection vulnerability in Avast Premier 12.3 (and earlier), Internet Security 12.3 (and earlier), Pro Antivirus 12.3 (and earlier), and Free Antivirus 12.3 (and earlier) allows a local attacker to bypass a self-protection mechanism, inject arbitrary code, and take full control of any Avast process via a…
ModificadaMedia (6.7)0.62%—AVG Anti-virusAVG Internet SecurityAVG Ultimate21/3/201717/6/2026
Code injection vulnerability in AVG Ultimate 17.1 (and earlier), AVG Internet Security 17.1 (and earlier), and AVG AntiVirus FREE 17.1 (and earlier) allows a local attacker to bypass a self-protection mechanism, inject arbitrary code, and take full control of any AVG process via a "DoubleAgent" attack. One perspective…