Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

920 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)1.1%—Infovista Vistaportal17/12/201817/6/2026
Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "/VPortal/mgtconsole/Subscribers.jsp" has reflected XSS via the ConnPoolName or GroupId parameter.
ModificadaMedia (6.1)1.1%—Infovista Vistaportal17/12/201817/6/2026
Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "/VPortal/mgtconsole/SubFolderPackages.jsp" has reflected XSS via the GroupId parameter.
ModificadaMedia (6.1)1.1%—Infovista Vistaportal17/12/201817/6/2026
Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "/VPortal/mgtconsole/Import.jsp" has reflected XSS via the ConnPoolName parameter.
ModificadaMedia (6.1)1.1%—Infovista Vistaportal17/12/201817/6/2026
Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "/VPortal/mgtconsole/GroupMove.jsp" has reflected XSS via the ConnPoolName, GroupId, or type parameter.
ModificadaMedia (6.1)1.1%—Infovista Vistaportal17/12/201817/6/2026
Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "/VPortal/mgtconsole/GroupCopy.jsp" has reflected XSS via the ConnPoolName, GroupId, or type parameter.
ModificadaMedia (6.1)1.1%—Infovista Vistaportal17/12/201817/6/2026
Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "Variables.jsp" has reflected XSS via the ConnPoolName and GroupId parameters.
ModificadaMedia (6.1)1.1%—Infovista Vistaportal17/12/201817/6/2026
Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "PresentSpace.jsp" has reflected XSS via the GroupId and ConnPoolName parameters.
ModificadaMedia (6.1)1.1%—Infovista Vistaportal17/12/201817/6/2026
Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "EditCurrentUser.jsp" has reflected XSS via the GroupId and ConnPoolName parameters.
ModificadaMedia (6.1)1.1%—Infovista Vistaportal17/12/201817/6/2026
Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "EditCurrentPresentSpace.jsp" has reflected XSS via the ConnPoolName, GroupId, and ParentId parameters.
ModificadaMedia (6.1)1.1%—Infovista Vistaportal17/12/201817/6/2026
Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "EditCurrentPool.jsp" has reflected XSS via the PropName parameter.
ModificadaMedia (6.1)1.1%—Infovista Vistaportal17/12/201817/6/2026
Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "Users.jsp" has reflected XSS via the ConnPoolName parameter.
ModificadaMedia (6.1)1.1%—Infovista Vistaportal17/12/201817/6/2026
Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "UserProperties.jsp" has reflected XSS via the ConnPoolName parameter.
ModificadaMedia (6.1)1.1%—Infovista Vistaportal17/12/201817/6/2026
Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "SubPagePackages.jsp" has reflected XSS via the ConnPoolName and GroupId parameters.
ModificadaMedia (6.1)1.1%—Infovista Vistaportal17/12/201817/6/2026
Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "PresentSpace.jsp" has reflected XSS via the ConnPoolName and GroupId parameters.
ModificadaMedia (6.1)1.1%—Infovista Vistaportal17/12/201817/6/2026
Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "GroupRessourceAdmin.jsp" has reflected XSS via the ConnPoolName parameter.
ModificadaMedia (6.1)1.1%—Infovista Vistaportal17/12/201817/6/2026
Cross Site Scripting exists in InfoVista VistaPortal SE Version 5.1 (build 51029). The page "EditCurrentPresentSpace.jsp" has reflected XSS via the ConnPoolName, GroupId, and ParentId parameters.
ModificadaMedia (6.1)1.1%—Infovista Vistaportal17/12/201817/6/2026
XSS exists in InfoVista VistaPortal SE Version 5.1 (build 51029). VPortal/mgtconsole/RolePermissions.jsp has reflected XSS via the ConnPoolName parameter.
ModificadaAlta (7.5)2.0%—Chatbyvista Project Chatbyvista7/6/201817/6/2026
chatbyvista is a file server. chatbyvista is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
ModificadaMedia (5.5)2.9%💥 PoCMicrosoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows Vista+126/2/201817/6/2026
An issue was discovered in secdrv.sys as shipped in Microsoft Windows Vista, Windows 7, Windows 8, and Windows 8.1 before KB3086255, and as shipped in Macrovision SafeDisc. An uninitialized kernel pool allocation in IOCTL 0xCA002813 allows a local unprivileged attacker to leak 16 bits of uninitialized kernel PagedPool…
ModificadaAlta (7)1.5%💥 PoCMicrosoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows Vista+126/2/201817/6/2026
An issue was discovered in secdrv.sys as shipped in Microsoft Windows Vista, Windows 7, Windows 8, and Windows 8.1 before KB3086255, and as shipped in Macrovision SafeDisc. Two carefully timed calls to IOCTL 0xCA002813 can cause a race condition that leads to a use-after-free. When exploited, an unprivileged attacker…
ModificadaAlta (7.8)1.8%—Jpki THE Public Certification Service FOR IndividualsJpki THE Public Certification Service FOR Individuals FOR Windows 7Jpki THE Public Certification Service FOR Individuals FOR Windows Vista9/6/201717/6/2026
Untrusted search path vulnerability in The Public Certification Service for Individuals "The JPKI user's software (for Windows 7 and later)" Ver3.0.1 and earlier, The Public Certification Service for Individuals "The JPKI user's software (for Windows Vista)" Ver3.0.1 and earlier and The Public Certification Service…
AnalizadaAlta (7.8)99%⚠ Explotación activa💥 ExploitMicrosoft OfficeMicrosoft Windows 7Microsoft Windows Server 2008Microsoft Windows Server 2012+212/4/201717/6/2026
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office/WordPad Remote Code Execution…
ModificadaMedia (4.3)6.0%—Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8.1Microsoft Windows RT 8.1+412/4/201717/6/2026
The Adobe Type Manager Font Driver (ATMFD.dll) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold , 1511, 1607, and 1703 allows an attacker to gain sensitive information via a specially crafted document or…
ModificadaAlta (8.1)6.4%—Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8.1Microsoft Windows RT 8.1+412/4/201717/6/2026
An elevation of privilege vulnerability exists in Windows when LDAP request buffer lengths are improperly calculated. In a remote attack scenario, an attacker could exploit this vulnerability by running a specially crafted application to send malicious traffic to a Domain Controller, aka "LDAP Elevation of Privilege…
ModificadaAlta (7.5)13%—Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8.1Microsoft Windows RT 8.1+412/4/201717/6/2026
An elevation of privilege vulnerability exists when Microsoft Windows running on Windows 10, Windows 10 1511, Windows 8.1 Windows RT 8.1, and Windows Server 2012 R2 fails to properly sanitize handles in memory, aka "Scripting Engine Memory Corruption Vulnerability."
Orbitaley — Vulnerabilidades