Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

154 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)7.2%—HP Converged Infrastructure Solution Sizer SuiteHP Insight Management SizerHP Power AdvisorHP SAP Sizing Tool+1122/8/201617/6/2026
HPE Smart Update in Storage Sizing Tool before 13.0, Converged Infrastructure Solution Sizer Suite (CISSS) before 2.13.1, Power Advisor before 7.8.2, Insight Management Sizer before 16.12.1, Synergy Planning Tool before 3.3, SAP Sizing Tool before 16.12.1, Sizing Tool for SAP Business Suite powered by HANA before…
ModificadaAlta (7.5)2.3%—Hancom Hanword Viewer 2007Hancom Hanword Viewer 2010Hancom HWP 2014Hancom Hwpviewer 201415/5/201517/6/2026
Integer overflow in the HwpApp::CHncSDS_Manager function in Hancom Office HanWord processor, as used in Hwp 2014 VP before 9.1.0.2342, HanWord Viewer 2007 and Viewer 2010 8.5.6.1158, and HwpViewer 2014 VP 9.1.0.2186, allows remote attackers to cause a denial of service (crash) and possibly "influence the program's…
ModificadaAlta (7.5)7.0%💥 ExploitHancom Office 2010 SE12/1/201517/6/2026
Buffer overflow in Hancom Office 2010 SE allows remote attackers to execute arbitrary via a long string in the Text attribute in a TEXTART XML element in an HML file.
ModificadaAlta (10)21%—Microsoft Forefront Protection 201012/2/201417/6/2026
Microsoft Forefront Protection 2010 for Exchange Server does not properly parse e-mail content, which might allow remote attackers to execute arbitrary code via a crafted message, aka "RCE Vulnerability."
ModificadaMedia (5)2.1%—Schneider-electric Modicon M340 BMX NOC 0401 FirmwareSchneider-electric Modicon M340 BMX NOE 0100 FirmwareSchneider-electric Modicon M340 BMX NOE 0100h FirmwareSchneider-electric Modicon M340 BMX NOE 0110 Firmware+84/4/201316/6/2026
The Schneider Electric M340 PLC modules allow remote attackers to cause a denial of service (resource consumption) via unspecified vectors. NOTE: the vendor reportedly disputes this issue because it "could not be duplicated" and "an attacker could not remotely exploit this observed behavior to deny PLC control…
ModificadaAlta (7.5)1.5%—Siteminder Agent FOR Sharepoint 2010Siteminder Federation 12.0Siteminder Federation 12.1Siteminder Federation 12.5+421/3/201316/6/2026
CA SiteMinder Federation (FSS) 12.5, 12.0, and r6; Federation (Standalone) 12.1 and 12.0; Agent for SharePoint 2010; and SiteMinder for Secure Proxy Server 6.0, 12.0, and 12.5 does not properly verify XML signatures for SAML statements, which allows remote attackers to spoof other users and gain privileges.
ModificadaAlta (9.3)4.3%—Kingsoft Writer 2007Kingsoft Writer 20105/3/201316/6/2026
Buffer overflow in Kingsoft Writer 2007 and 2010 before 2724 allows remote attackers to execute arbitrary code via a crafted RTF document.
ModificadaMedia (6.9)0.42%—Tuneup Utilities 2009Tuneup Utilities 20106/9/201216/6/2026
Multiple untrusted search path vulnerabilities in TuneUp Utilities 2009 8.0.3310 and 2010 9.0.4600 allow local users to gain privileges via a Trojan horse (1) wscapi.dll or (2) vclib32.dll file in the current working directory, as demonstrated by a directory that contains a .tvs file. NOTE: the provenance of this…
ModificadaMedia (6.9)0.35%—Ksoffice Office 20106/9/201216/6/2026
Multiple untrusted search path vulnerabilities in the (1) Presentation, (2) Writer, and (3) Spreadsheets components in Kingsoft Office 2010 6.6.0.2477 allow local users to gain privileges via a Trojan horse plgpf.dll file in the current working directory, as demonstrated by a directory that contains a .xls, .ppt,…
ModificadaMedia (6.2)0.33%—Trendmicro Internet Security 201025/8/201216/6/2026
Race condition in Trend Micro Internet Security Pro 2010 17.50.1647.0000 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during…
ModificadaMedia (6.2)0.29%—Pcsecurityshield Security Shield 201025/8/201216/6/2026
Race condition in Security Shield 2010 13.0.16.313 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka…
ModificadaMedia (6.2)0.29%—Pandasecurity Panda Internet Security 201025/8/201216/6/2026
Race condition in Panda Internet Security 2010 15.01.00 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler…
ModificadaMedia (6.2)0.32%—Symantec Norton Internet Security 201025/8/201216/6/2026
Race condition in Symantec Norton Internet Security 2010 17.5.0.127 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during…
ModificadaMedia (6.2)0.30%—Mcafee Total Protection 201025/8/201216/6/2026
Race condition in McAfee Total Protection 2010 10.0.580 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler…
ModificadaMedia (6.2)0.32%—Kaspersky Internet Security 201025/8/201216/6/2026
Race condition in Kaspersky Internet Security 2010 9.0.0.736 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler…
ModificadaMedia (6.2)0.32%—Gdata Totalcare 201025/8/201216/6/2026
Race condition in G DATA TotalCare 2010 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an…
ModificadaMedia (6.2)0.30%—F-secure Internet Security 201025/8/201216/6/2026
Race condition in F-Secure Internet Security 2010 10.00 build 246 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler…
ModificadaMedia (6.2)0.30%—CA Internet Security Suite 201025/8/201216/6/2026
Race condition in CA Internet Security Suite Plus 2010 6.0.0.272 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler…
ModificadaMedia (6.2)0.30%—Bitdefender Total Security 201025/8/201216/6/2026
Race condition in BitDefender Total Security 2010 13.0.20.347 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler…
ModificadaMedia (4.3)1.6%💥 ExploitYandex.server 201027/5/201216/6/2026
Cross-site scripting (XSS) vulnerability in search/ in Yandex.Server 2010 9.0 Enterprise allows remote attackers to inject arbitrary web script or HTML via the text parameter.
ModificadaAlta (9.3)4.8%—Hancom Office 2010 SE24/2/201216/6/2026
Multiple integer overflows in Hancom Office 2010 SE 8.5.5 allow remote attackers to execute arbitrary code via large dimension values in a (1) JPG image to the ImportGR in the JPG image filter module (HncJpeg10.flt) or (2) PNG image to the PNG image filter module (HncPng10.flt), which triggers a heap-based buffer…
ModificadaAlta (7.5)0.91%💥 ExploitOlykit Swoopo Clone 20102/11/201116/6/2026
SQL injection vulnerability in index.php in OlyKit Swoopo Clone 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter in a product action.
ModificadaAlta (8.8)2.5%—CA Host-based Intrusion Prevention SystemCA Internet Security Suite 2010CA Internet Security Suite 201125/2/201116/6/2026
The XML Security Database Parser class in the XMLSecDB ActiveX control in the HIPSEngine component in the Management Server before 8.1.0.88, and the client before 1.6.450, in CA Host-Based Intrusion Prevention System (HIPS) 8.1, as used in CA Internet Security Suite (ISS) 2010, allows remote attackers to download an…
ModificadaAlta (7.2)1.8%—Microsoft Forefront Client SecurityMicrosoft Forefront Endpoint Protection 2010Microsoft Malicious Software Removal ToolMicrosoft Malware Protection Engine+325/2/201116/6/2026
Microsoft Malware Protection Engine before 1.1.6603.0, as used in Microsoft Malicious Software Removal Tool (MSRT), Windows Defender, Security Essentials, Forefront Client Security, Forefront Endpoint Protection 2010, and Windows Live OneCare, allows local users to gain privileges via a crafted value of an unspecified…
ModificadaAlta (7.2)1.1%💥 ExploitCA Internet Security Suite Plus 20108/12/201016/6/2026
Integer overflow in KmxSbx.sys 6.2.0.22 in CA Internet Security Suite Plus 2010 allows local users to cause a denial of service (pool corruption) and execute arbitrary code via crafted arguments to the 0x88000080 IOCTL, which triggers a buffer overflow.
Orbitaley — Vulnerabilidades