Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

276 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.9)3.6%—Microsoft Exchange Server11/11/202017/6/2026
Microsoft Exchange Server Denial of Service Vulnerability
ModificadaAlta (8.8)3.9%—Microsoft Exchange Server11/11/202017/6/2026
Microsoft Exchange Server Remote Code Execution Vulnerability
ModificadaMedia (5.4)12%—Microsoft Exchange Server11/11/202017/6/2026
Microsoft Exchange Server Remote Code Execution Vulnerability
ModificadaMedia (6.5)2.7%—Microsoft Exchange Server16/10/202017/6/2026
<p>An information disclosure vulnerability exists in how Microsoft Exchange validates tokens when handling certain messages. An attacker who successfully exploited the vulnerability could use this to gain further information from a user.</p> <p>To exploit the vulnerability, an attacker could include specially crafted…
ModificadaAlta (7.2)47%💥 ExploitMicrosoft Exchange Server11/9/202017/6/2026
<p>A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.</p> <p>An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the System user. Exploitation of the vulnerability requires an authenticated user in a…
ModificadaMedia (5.5)0.54%—Intel Celeron 1000mIntel Celeron 1005mIntel Celeron 1007uIntel Celeron 1017u+69015/6/202017/6/2026
Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaMedia (5.3)4.9%—Oracle JDKOracle JREOracle OpenjdkNetapp 7-mode Transition Tool+1715/4/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to…
ModificadaMedia (5.3)4.9%—Oracle JDKOracle JREOracle OpenjdkDebian Linux+1715/4/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE, Java…
ModificadaMedia (5.4)1.6%—Microsoft Exchange Server12/3/202017/6/2026
A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted web request to an affected Exchange server, aka 'Microsoft Exchange Server Spoofing Vulnerability'.
ModificadaAlta (8.1)3.3%—Microsoft Exchange Server11/2/202017/6/2026
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'.
AnalizadaAlta (8.8)100%⚠ Explotación activa💥 ExploitMicrosoft Exchange Server11/2/202017/6/2026
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.
ModificadaMedia (4.5)0.75%—Mcafee Threat Intelligence Exchange Server13/11/201917/6/2026
Abuse of Authorization vulnerability in APIs exposed by TIE server in McAfee Threat Intelligence Exchange Server (TIE Server) 3.0.0 allows remote authenticated users to modify stored reputation data via specially crafted messages.
ModificadaCrítica (9.8)22%—Microsoft Exchange Server12/11/201917/6/2026
A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Microsoft Exchange Remote Code Execution Vulnerability'.
ModificadaMedia (6.5)1.7%—Dell Bsafe Cert-jDell Bsafe Crypto-jDell Bsafe Ssl-jMcafee Threat Intelligence Exchange Server+1218/9/201917/6/2026
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A malicious remote attacker could potentially exploit this vulnerability to coerce two parties into computing the same predictable shared key.
ModificadaMedia (6.1)2.0%—Microsoft Exchange Server11/9/201917/6/2026
A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web App (OWA) fails to properly handle web requests, aka 'Microsoft Exchange Spoofing Vulnerability'.
ModificadaAlta (7.5)6.2%—Microsoft Exchange Server11/9/201917/6/2026
A denial of service vulnerability exists in Microsoft Exchange Server software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Denial of Service Vulnerability'.
ModificadaMedia (5.4)1.6%—Microsoft Exchange Server15/7/201917/6/2026
A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted web request to an affected Exchange server, aka 'Microsoft Exchange Server Spoofing Vulnerability'.
ModificadaAlta (8.1)3.4%—Microsoft Exchange Server15/7/201917/6/2026
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'.
ModificadaMedia (6.5)5.3%—Microsoft Exchange ServerMicrosoft LyncMicrosoft Lync BasicMicrosoft Mail AND Calendar+515/7/201917/6/2026
An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security…
ModificadaMedia (6.1)2.1%—Microsoft Exchange Server9/4/201917/6/2026
A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests, aka 'Microsoft Exchange Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0817.
ModificadaMedia (5.4)2.3%—Microsoft Exchange Server9/4/201917/6/2026
A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests, aka 'Microsoft Exchange Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0858.
ModificadaAlta (8.1)24%—Microsoft Exchange Server5/3/201917/6/2026
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0686.
ModificadaAlta (7.4)5.0%—Microsoft Exchange Server5/3/201917/6/2026
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0724.
ModificadaMedia (5.9)17%—OpensslCanonical Ubuntu LinuxDebian LinuxNetapp Active IQ Unified Manager+7827/2/201917/6/2026
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid…
ModificadaMedia (6.5)4.6%—Microsoft Exchange Server8/1/201917/6/2026
An information disclosure vulnerability exists when the Microsoft Exchange PowerShell API grants calendar contributors more view permissions than intended, aka "Microsoft Exchange Information Disclosure Vulnerability." This affects Microsoft Exchange Server.