Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

1895 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)6.2%—Microsoft Internet Explorer21/5/202019/8/2026
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same…
ModificadaAlta (7.5)3.2%—Microsoft Internet Explorer21/5/202019/8/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same…
ModificadaAlta (7.5)3.2%—Microsoft Internet Explorer21/5/202019/8/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same…
ModificadaAlta (7.5)3.2%—Microsoft Internet Explorer21/5/202019/8/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same…
AnalizadaAlta (7.5)31%⚠ Explotación activaMicrosoft Internet Explorer15/4/202017/6/2026
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0970.
ModificadaAlta (8.8)12%—Microsoft Internet Explorer15/4/202017/6/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0966.
ModificadaAlta (8.8)12%—Microsoft Internet Explorer15/4/202017/6/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0967.
ModificadaAlta (7.5)7.9%—Microsoft Internet Explorer15/4/202017/6/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'.
ModificadaMedia (6.4)1.6%—Zohocorp Manageengine Assetexplorer23/3/202017/6/2026
An issue was discovered in Zoho ManageEngine AssetExplorer 6.5. During an upgrade of the Windows agent, it does not validate the source and binary downloaded. This allows an attacker on an adjacent network to execute code with NT AUTHORITY/SYSTEM privileges on the agent machines by providing an arbitrary executable…
ModificadaAlta (7.2)6.0%—Zohocorp Manageengine Assetexplorer23/3/202017/6/2026
Zoho ManageEngine Asset Explorer 6.5 does not validate the System Center Configuration Manager (SCCM) database username when dynamically generating a command to schedule scans for SCCM. This allows an attacker to execute arbitrary commands on the AssetExplorer Server with NT AUTHORITY/SYSTEM privileges.
ModificadaCrítica (9.8)1.1%—Naver Cloud Explorer23/3/202017/6/2026
Naver Cloud Explorer before 2.2.2.11 allows the attacker can move a local file in any path on the filesystem as a system privilege through its named pipe.
ModificadaMedia (6.1)3.5%—Invisioncommunity Invision Power BoardMicrosoft Internet Explorer13/3/202016/6/2026
Invision Power Board (aka IPB or IP.Board) 2.x through 3.0.4, when Internet Explorer 5 is used, allows XSS via a .txt attachment.
ModificadaAlta (7.5)7.9%—Microsoft Internet Explorer12/3/202017/6/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'.
ModificadaAlta (7.5)8.7%—Microsoft Internet Explorer12/3/202017/6/2026
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-2020-0825, CVE-2020-0826, CVE-2020-0827, CVE-2020-0828, CVE-2020-0829,…
ModificadaAlta (7.5)8.7%—Microsoft Internet Explorer12/3/202017/6/2026
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-2020-0825, CVE-2020-0826, CVE-2020-0827, CVE-2020-0828, CVE-2020-0829,…
ModificadaAlta (7.5)8.7%—Microsoft Internet ExplorerMicrosoft ChakracoreMicrosoft Edge12/3/202017/6/2026
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-2020-0825, CVE-2020-0826, CVE-2020-0827, CVE-2020-0828, CVE-2020-0829,…
ModificadaAlta (7.5)7.2%—Microsoft Internet Explorer12/3/202017/6/2026
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'.
ModificadaAlta (7.5)8.7%—Microsoft ChakracoreMicrosoft Internet ExplorerMicrosoft Edge12/3/202017/6/2026
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0823, CVE-2020-0825, CVE-2020-0826, CVE-2020-0827, CVE-2020-0828, CVE-2020-0829, CVE-2020-0830,…
ModificadaCrítica (9.1)0.48%—Naver Cloud Explorer3/3/202017/6/2026
Naver Cloud Explorer before 2.2.2.11 allows the system to download an arbitrary file from the attacker's server and execute it during the upgrade.
ModificadaMedia (6.1)1.0%—Amazon AWS Javascript S3 Explorer13/2/202017/6/2026
explorer.js in Amazon AWS JavaScript S3 Explorer (aka aws-js-s3-explorer) v2 alpha before 2019-08-02 allows XSS in certain circumstances.
ModificadaMedia (4.3)5.1%—Microsoft Internet ExplorerMicrosoft Edge11/2/202017/6/2026
An information disclosure vulnerability exists in the way that affected Microsoft browsers handle cross-origin requests, aka 'Microsoft Browser Information Disclosure Vulnerability'.
AnalizadaAlta (7.5)87%⚠ Explotación activa💥 ExploitMicrosoft Internet Explorer11/2/202017/6/2026
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0710, CVE-2020-0711, CVE-2020-0712, CVE-2020-0713, CVE-2020-0767.
ModificadaAlta (7.5)9.9%—Microsoft Internet Explorer11/2/202017/6/2026
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0674, CVE-2020-0710, CVE-2020-0711, CVE-2020-0712, CVE-2020-0713, CVE-2020-0767.
ModificadaAlta (8.8)1.5%—Super File Explorer Project Super File Explorer28/1/202017/6/2026
An arbitrary file upload vulnerability has been discovered in the Super File Explorer app 1.0.1 for iOS. The vulnerability is located in the developer path that is accessible and hidden next to the root path. By default, there is no password set for the FTP or Web UI service.
ModificadaAlta (7.5)8.6%—Microsoft Internet Explorer14/1/202017/6/2026
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'.