Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
467 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Microsoft Exchange Server | 3/3/2021 | 19/8/2026 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| Modificada | Alta (7.2) | 25% | — | Microsoft Exchange Server | 3/3/2021 | 19/8/2026 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| Modificada | Alta (7.2) | 34% | — | Microsoft Exchange Server | 3/3/2021 | 19/8/2026 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| Analizada | Alta (7.8) | 100% | ⚠ Explotación activa💥 Exploit | Microsoft Exchange Server | 2/3/2021 | 1/10/2026 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| Analizada | Alta (7.8) | 94% | ⚠ Explotación activa | Microsoft Exchange Server | 2/3/2021 | 1/10/2026 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| Modificada | Media (5.5) | 4.6% | 💥 PoC | Microsoft Exchange Server | 25/2/2021 | 17/6/2026 | Microsoft Exchange Server Spoofing Vulnerability | |
| Modificada | Media (5.4) | 1.8% | — | Microsoft Exchange Server | 25/2/2021 | 17/6/2026 | <p>A spoofing vulnerability exists in Microsoft Exchange Server which could result in an attack that would allow a malicious actor to impersonate the user.</p> <p>This update addresses this vulnerability.</p> <p>To prevent these types of attacks, Microsoft recommends customers to download inline images from different… | |
| Analizada | Alta (8.8) | 37% | ⚠ Explotación activa💥 PoC | Microsoft Exchange Server | 10/12/2020 | 17/6/2026 | Microsoft Exchange Remote Code Execution Vulnerability | |
| Modificada | Alta (8.8) | 71% | — | Microsoft Exchange Server | 10/12/2020 | 17/6/2026 | Microsoft Exchange Server Information Disclosure Vulnerability | |
| Modificada | Crítica (9.1) | 3.4% | — | Microsoft Exchange Server | 10/12/2020 | 17/6/2026 | Microsoft Exchange Remote Code Execution Vulnerability | |
| Modificada | Alta (8.4) | 6.6% | — | Microsoft Exchange Server | 10/12/2020 | 17/6/2026 | Microsoft Exchange Remote Code Execution Vulnerability | |
| Modificada | Crítica (9.1) | 90% | 💥 Exploit | Microsoft Exchange Server | 10/12/2020 | 17/6/2026 | Microsoft Exchange Remote Code Execution Vulnerability | |
| Modificada | Alta (7.2) | 49% | — | Microsoft Exchange Server | 10/12/2020 | 17/6/2026 | Microsoft Exchange Remote Code Execution Vulnerability | |
| Modificada | Media (4.9) | 3.6% | — | Microsoft Exchange Server | 11/11/2020 | 17/6/2026 | Microsoft Exchange Server Denial of Service Vulnerability | |
| Modificada | Alta (8.8) | 3.9% | — | Microsoft Exchange Server | 11/11/2020 | 17/6/2026 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| Modificada | Media (5.4) | 12% | — | Microsoft Exchange Server | 11/11/2020 | 17/6/2026 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| Modificada | Alta (7.5) | 1.3% | — | Arista Cloudvision Exchange | 26/10/2020 | 17/6/2026 | Arista’s CloudVision eXchange (CVX) server before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause a denial of service (crash and restart) in the ControllerOob agent via a malformed control-plane packet. | |
| Modificada | Media (6.5) | 2.7% | — | Microsoft Exchange Server | 16/10/2020 | 17/6/2026 | <p>An information disclosure vulnerability exists in how Microsoft Exchange validates tokens when handling certain messages. An attacker who successfully exploited the vulnerability could use this to gain further information from a user.</p> <p>To exploit the vulnerability, an attacker could include specially crafted… | |
| Modificada | Alta (7.2) | 47% | 💥 Exploit | Microsoft Exchange Server | 11/9/2020 | 17/6/2026 | <p>A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.</p> <p>An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the System user. Exploitation of the vulnerability requires an authenticated user in a… | |
| Modificada | Crítica (9.8) | 13% | — | Zohocorp Manageengine Adselfservice PlusZohocorp Manageengine Exchange Reporter PlusZohocorp Manageengine Ad360Zohocorp Manageengine Datasecurity Plus+7 | 31/8/2020 | 17/6/2026 | An issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus before build number 5817, DataSecurity Plus before build number 6033, RecoverManager Plus before build number 6017, EventLog Analyzer before build number 12136, ADAudit Plus… | |
| Modificada | Media (5.5) | 0.54% | — | Intel Celeron 1000mIntel Celeron 1005mIntel Celeron 1007uIntel Celeron 1017u+690 | 15/6/2020 | 17/6/2026 | Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Media (5.3) | 4.9% | — | Oracle JDKOracle JREOracle OpenjdkNetapp 7-mode Transition Tool+17 | 15/4/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Media (5.3) | 4.9% | — | Oracle JDKOracle JREOracle OpenjdkDebian Linux+17 | 15/4/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE, Java… | |
| Modificada | Media (5.4) | 1.6% | — | Microsoft Exchange Server | 12/3/2020 | 17/6/2026 | A cross-site-scripting (XSS) vulnerability exists when Microsoft Exchange Server does not properly sanitize a specially crafted web request to an affected Exchange server, aka 'Microsoft Exchange Server Spoofing Vulnerability'. | |
| Modificada | Media (5.5) | 2.9% | — | Avira Anti-malware SDKAvira Antivirus ServerAvira Antivirus FOR EndpointAvira Antivirus FOR Small Business+4 | 20/2/2020 | 17/6/2026 | Avira AV Engine before 8.3.54.138 allows virus-detection bypass via a crafted ISO archive. This affects versions before 8.3.54.138 of Antivirus for Endpoint, Antivirus for Small Business, Exchange Security (Gateway), Internet Security Suite for Windows, Prime, Free Security Suite for Windows, and Cross Platform… |