Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

467 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitMicrosoft Exchange Server3/3/202119/8/2026
Microsoft Exchange Server Remote Code Execution Vulnerability
ModificadaAlta (7.2)25%—Microsoft Exchange Server3/3/202119/8/2026
Microsoft Exchange Server Remote Code Execution Vulnerability
ModificadaAlta (7.2)34%—Microsoft Exchange Server3/3/202119/8/2026
Microsoft Exchange Server Remote Code Execution Vulnerability
AnalizadaAlta (7.8)100%⚠ Explotación activa💥 ExploitMicrosoft Exchange Server2/3/20211/10/2026
Microsoft Exchange Server Remote Code Execution Vulnerability
AnalizadaAlta (7.8)94%⚠ Explotación activaMicrosoft Exchange Server2/3/20211/10/2026
Microsoft Exchange Server Remote Code Execution Vulnerability
ModificadaMedia (5.5)4.6%💥 PoCMicrosoft Exchange Server25/2/202117/6/2026
Microsoft Exchange Server Spoofing Vulnerability
ModificadaMedia (5.4)1.8%—Microsoft Exchange Server25/2/202117/6/2026
<p>A spoofing vulnerability exists in Microsoft Exchange Server which could result in an attack that would allow a malicious actor to impersonate the user.</p> <p>This update addresses this vulnerability.</p> <p>To prevent these types of attacks, Microsoft recommends customers to download inline images from different…
AnalizadaAlta (8.8)37%⚠ Explotación activa💥 PoCMicrosoft Exchange Server10/12/202017/6/2026
Microsoft Exchange Remote Code Execution Vulnerability
ModificadaAlta (8.8)71%—Microsoft Exchange Server10/12/202017/6/2026
Microsoft Exchange Server Information Disclosure Vulnerability
ModificadaCrítica (9.1)3.4%—Microsoft Exchange Server10/12/202017/6/2026
Microsoft Exchange Remote Code Execution Vulnerability
ModificadaAlta (8.4)6.6%—Microsoft Exchange Server10/12/202017/6/2026
Microsoft Exchange Remote Code Execution Vulnerability
ModificadaCrítica (9.1)90%💥 ExploitMicrosoft Exchange Server10/12/202017/6/2026
Microsoft Exchange Remote Code Execution Vulnerability
ModificadaAlta (7.2)49%—Microsoft Exchange Server10/12/202017/6/2026
Microsoft Exchange Remote Code Execution Vulnerability
ModificadaMedia (4.9)3.6%—Microsoft Exchange Server11/11/202017/6/2026
Microsoft Exchange Server Denial of Service Vulnerability
ModificadaAlta (8.8)3.9%—Microsoft Exchange Server11/11/202017/6/2026
Microsoft Exchange Server Remote Code Execution Vulnerability
ModificadaMedia (5.4)12%—Microsoft Exchange Server11/11/202017/6/2026
Microsoft Exchange Server Remote Code Execution Vulnerability
ModificadaAlta (7.5)1.3%—Arista Cloudvision Exchange26/10/202017/6/2026
Arista’s CloudVision eXchange (CVX) server before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause a denial of service (crash and restart) in the ControllerOob agent via a malformed control-plane packet.
ModificadaMedia (6.5)2.7%—Microsoft Exchange Server16/10/202017/6/2026
<p>An information disclosure vulnerability exists in how Microsoft Exchange validates tokens when handling certain messages. An attacker who successfully exploited the vulnerability could use this to gain further information from a user.</p> <p>To exploit the vulnerability, an attacker could include specially crafted…
ModificadaAlta (7.2)47%💥 ExploitMicrosoft Exchange Server11/9/202017/6/2026
<p>A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.</p> <p>An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the System user. Exploitation of the vulnerability requires an authenticated user in a…
ModificadaCrítica (9.8)13%—Zohocorp Manageengine Adselfservice PlusZohocorp Manageengine Exchange Reporter PlusZohocorp Manageengine Ad360Zohocorp Manageengine Datasecurity Plus+731/8/202017/6/2026
An issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus before build number 5817, DataSecurity Plus before build number 6033, RecoverManager Plus before build number 6017, EventLog Analyzer before build number 12136, ADAudit Plus…
ModificadaMedia (5.5)0.54%—Intel Celeron 1000mIntel Celeron 1005mIntel Celeron 1007uIntel Celeron 1017u+69015/6/202017/6/2026
Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaMedia (5.3)4.9%—Oracle JDKOracle JREOracle OpenjdkNetapp 7-mode Transition Tool+1715/4/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to…
ModificadaMedia (5.3)4.9%—Oracle JDKOracle JREOracle OpenjdkDebian Linux+1715/4/202017/6/2026
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE, Java…
ModificadaMedia (5.4)1.6%—Microsoft Exchange Server12/3/202017/6/2026
A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted web request to an affected Exchange server, aka 'Microsoft Exchange Server Spoofing Vulnerability'.
ModificadaMedia (5.5)2.9%—Avira Anti-malware SDKAvira Antivirus ServerAvira Antivirus FOR EndpointAvira Antivirus FOR Small Business+420/2/202017/6/2026
Avira AV Engine before 8.3.54.138 allows virus-detection bypass via a crafted ISO archive. This affects versions before 8.3.54.138 of Antivirus for Endpoint, Antivirus for Small Business, Exchange Security (Gateway), Internet Security Suite for Windows, Prime, Free Security Suite for Windows, and Cross Platform…
Orbitaley — Vulnerabilidades