Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

1970 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.6)0.42%—File Explorer Project File Explorer22/10/202117/6/2026
An issue in the authentication mechanism in Nong Ge File Explorer v1.4 unauthenticated allows to access sensitive data.
ModificadaMedia (6.5)0.56%—Netexplorer MY Smtp Contact10/8/202117/6/2026
A cross-site request forgery (CSRF) vulnerability in the My SMTP Contact v1.1.1 plugin for GetSimple CMS allows remote attackers to change the SMTP settings of the contact forms for the webpages of the CMS after an authenticated admin visits a malicious third-party site.
ModificadaCrítica (9.8)7.4%—Zohocorp Manageengine Assetexplorer19/7/202117/6/2026
Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address. This will allow an attacker to send a NEWSCAN request to a listening agent on the network as well as receive the…
ModificadaAlta (7.5)1.4%—Zohocorp Manageengine Assetexplorer19/7/202117/6/2026
Due to the Asset Explorer agent not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address. This will allow an attacker to send a NEWSCAN request to a listening agent on the network as well as receive the agent's HTTP request…
ModificadaAlta (7.5)4.5%—Zohocorp Manageengine Assetexplorer19/7/202117/6/2026
Manage Engine Asset Explorer Agent 1.0.34 listens on port 9000 for incoming commands over HTTPS from Manage Engine Server. The HTTPS certificates are not verified which allows any arbitrary user on the network to send commands over port 9000. While these commands may not be executed (due to authtoken validation), the…
ModificadaAlta (7.5)23%—Microsoft Internet Explorer11/5/202117/6/2026
Scripting Engine Memory Corruption Vulnerability
AnalizadaAlta (8.8)5.4%⚠ Explotación activaMicrosoft Internet Explorer11/3/202119/8/2026
Internet Explorer Remote Code Execution Vulnerability
AnalizadaAlta (8.8)81%⚠ Explotación activa💥 PoCMicrosoft EdgeMicrosoft Internet Explorer11/3/20211/10/2026
Internet Explorer Memory Corruption Vulnerability
ModificadaCrítica (9.8)6.9%—Mitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+3719/2/202117/6/2026
Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all…
ModificadaCrítica (9.8)3.9%—Mitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+3719/2/202117/6/2026
Heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all versions, FR Configurator SW3…
ModificadaMedia (6.1)2.9%💥 ExploitQuixplorer Project Quixplorer7/1/202117/6/2026
Quixplorer <=2.4.1 is vulnerable to reflected cross-site scripting (XSS) caused by improper validation of user supplied input. A remote attacker could exploit this vulnerability using a specially crafted URL to execute a script in a victim's Web browser within the security context of the hosting Web site, once the URL…
ModificadaAlta (7.5)3.1%—Microsoft EdgeMicrosoft Internet Explorer11/11/202017/6/2026
Microsoft Browser Memory Corruption Vulnerability
ModificadaAlta (7.5)3.2%—Microsoft Internet Explorer11/11/202017/6/2026
Internet Explorer Memory Corruption Vulnerability
ModificadaAlta (8.1)2.7%—Microsoft Internet ExplorerMicrosoft Edge11/11/202017/6/2026
Scripting Engine Memory Corruption Vulnerability
ModificadaAlta (8.8)2.1%—Microsoft Internet Explorer11/9/202017/6/2026
<p>An elevation of privilege vulnerability exists in the way that the Wininit.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.</p> <p>There are multiple ways an attacker could exploit the vulnerability:</p> <ul> <li><p>In a web-based…
ModificadaAlta (8.8)3.7%—Microsoft Internet Explorer11/9/202017/6/2026
<p>An elevation of privilege vulnerability exists in the way that the Wininit.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.</p> <p>There are multiple ways an attacker could exploit the vulnerability:</p> <ul> <li><p>In a web-based…
AnalizadaAlta (7.5)2.7%⚠ Explotación activaMicrosoft Internet ExplorerMicrosoft EdgeMicrosoft Chakracore11/9/202017/6/2026
<p>A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the…
ModificadaAlta (7.5)8.8%—Microsoft Internet Explorer17/8/202017/6/2026
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the…
ModificadaAlta (7.5)3.7%—Microsoft Internet Explorer17/8/202017/6/2026
A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input. An attacker could execute arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take…
AnalizadaAlta (8.8)24%⚠ Explotación activaMicrosoft Internet Explorer17/8/202017/6/2026
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the…
ModificadaMedia (4.3)4.5%—Microsoft Internet Explorer14/7/202017/6/2026
An information disclosure vulnerability exists when Skype for Business is accessed via Internet Explorer, aka 'Skype for Business via Internet Explorer Information Disclosure Vulnerability'.
ModificadaAlta (8.8)5.9%—Microsoft Azure Storage ExplorerMicrosoft TypescriptMicrosoft Visual Studio 2017Microsoft Visual Studio 2019+114/7/202017/6/2026
An elevation of privilege vulnerability exists in Visual Studio and Visual Studio Code when they load software dependencies, aka 'Visual Studio and Visual Studio Code Elevation of Privilege Vulnerability'.
ModificadaAlta (7.5)10%—Microsoft Internet Explorer14/7/202017/6/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'.
ModificadaMedia (5.3)3.8%—Microsoft Internet Explorer9/6/202017/6/2026
An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory, aka 'Internet Explorer Information Disclosure Vulnerability'.
ModificadaAlta (7.5)7.2%—Microsoft Internet Explorer9/6/202017/6/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1214, CVE-2020-1215, CVE-2020-1216, CVE-2020-1230.
Orbitaley — Vulnerabilidades