Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

1895 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)8.2%—Microsoft Internet Explorer10/12/201917/6/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'.
AnalizadaAlta (7.5)77%⚠ Explotación activa💥 ExploitMicrosoft Internet Explorer12/11/201917/6/2026
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1426, CVE-2019-1427, CVE-2019-1428.
ModificadaAlta (7.5)7.8%—Microsoft Internet Explorer12/11/201917/6/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'.
ModificadaAlta (7.8)0.23%—Cobham Explorer 710 Firmware10/10/201917/6/2026
The Cobham EXPLORER 710, firmware version 1.07, does not validate its firmware image. Development scripts left in the firmware can be used to upload a custom firmware image that the device runs. This could allow an unauthenticated, local attacker to upload their own firmware that could be used to intercept or modify…
ModificadaCrítica (9.8)1.5%—Cobham Explorer 710 Firmware10/10/201917/6/2026
The root password of the Cobham EXPLORER 710 is the same for all versions of firmware up to and including v1.08. This could allow an attacker to reverse-engineer the password from available versions to gain authenticated access to the device.
ModificadaAlta (7.8)0.21%—Cobham Explorer 710 Firmware10/10/201917/6/2026
The web application portal of the Cobham EXPLORER 710, firmware version 1.07, sends the login password in cleartext. This could allow an unauthenticated, local attacker to intercept the password and gain access to the portal.
ModificadaCrítica (9.8)2.5%—Cobham Explorer 710 Firmware10/10/201917/6/2026
The web application portal of the Cobham EXPLORER 710, firmware version 1.07, allows unauthenticated access to port 5454. This could allow an unauthenticated, remote attacker to connect to this port via Telnet and execute 86 Attention (AT) commands, including some that provide unauthenticated, shell-like access to the…
ModificadaMedia (5.5)0.36%—Cobham Explorer 710 Firmware10/10/201917/6/2026
The web root directory of the Cobham EXPLORER 710, firmware version 1.07, has no access restrictions on downloading and reading all files. This could allow an unauthenticated, local attacker connected to the device to access and download any file found in the web root directory.
ModificadaMedia (5.5)0.28%—Cobham Explorer 710 Firmware10/10/201917/6/2026
The web application portal of the Cobham EXPLORER 710, firmware version 1.07, has no authentication by default. This could allow an unauthenticated, local attacker connected to the device to access the portal and to make any change to the device.
ModificadaAlta (7.5)7.4%—Microsoft Internet Explorer10/10/201917/6/2026
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'.
ModificadaMedia (4.3)2.3%—Microsoft Internet ExplorerMicrosoft Edge10/10/201917/6/2026
A spoofing vulnerability exists when Microsoft Browsers improperly handle browser cookies, aka 'Microsoft Browser Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0608.
ModificadaAlta (7.5)7.5%—Microsoft Internet Explorer10/10/201917/6/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1238.
ModificadaMedia (6.4)5.9%—Microsoft Internet Explorer10/10/201917/6/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1239.
ModificadaMedia (4.3)2.4%—Microsoft Internet ExplorerMicrosoft Edge10/10/201917/6/2026
A spoofing vulnerability exists when Microsoft Browsers does not properly parse HTTP content, aka 'Microsoft Browser Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1357.
AnalizadaAlta (7.5)52%⚠ Explotación activa💥 PoCMicrosoft Internet Explorer23/9/201917/6/2026
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1221.
ModificadaAlta (7.5)19%💥 PoCMicrosoft Internet Explorer11/9/201917/6/2026
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'.
ModificadaMedia (4.3)3.8%—Microsoft Internet ExplorerMicrosoft Edge11/9/201917/6/2026
A security feature bypass vulnerability exists when Microsoft Browsers fail to validate the correct Security Zone of requests for specific URLs, aka 'Microsoft Browser Security Feature Bypass Vulnerability'.
ModificadaAlta (7.5)13%—Microsoft Internet Explorer11/9/201917/6/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1236.
ModificadaAlta (7.5)1.6%—Estrongs ES File Explorer File Manager5/9/201917/6/2026
The master-password feature in the ES File Explorer File Manager application 4.2.0.1.3 for Android can be bypassed via a com.estrongs.android.pop.ftp.ESFtpShortcut intent, leading to remote FTP access to the entirety of local storage.
ModificadaAlta (7.5)1.0%—Naver Cloud Explorer3/9/201917/6/2026
NDrive(1.2.2).sys in Naver Cloud Explorer has a stack-based buffer overflow, which allows attackers to cause a denial of service when reading data from IOCTL handle.
ModificadaAlta (7.5)3.4%—Microsoft Internet Explorer14/8/201917/6/2026
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the…
ModificadaMedia (6.4)3.1%—Microsoft Internet ExplorerMicrosoft Edge14/8/201917/6/2026
A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the…
ModificadaMedia (4.3)3.7%—Microsoft Internet ExplorerMicrosoft Edge14/8/201917/6/2026
A security feature bypass vulnerability exists when Microsoft browsers improperly handle requests of different origins. The vulnerability allows Microsoft browsers to bypass Same-Origin Policy (SOP) restrictions, and to allow requests that should otherwise be ignored. An attacker who successfully exploited the…
ModificadaAlta (7.5)3.3%—Microsoft Internet Explorer14/8/201917/6/2026
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the…
ModificadaAlta (8.1)4.2%—Zohocorp Manageengine Assetexplorer8/8/201917/6/2026
Zoho ManageEngine AssetExplorer 6.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing license XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.