Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

1900 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)3.4%—Microsoft Internet Explorer14/8/201917/6/2026
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the…
ModificadaMedia (6.4)3.1%—Microsoft Internet ExplorerMicrosoft Edge14/8/201917/6/2026
A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the…
ModificadaMedia (4.3)3.7%—Microsoft Internet ExplorerMicrosoft Edge14/8/201917/6/2026
A security feature bypass vulnerability exists when Microsoft browsers improperly handle requests of different origins. The vulnerability allows Microsoft browsers to bypass Same-Origin Policy (SOP) restrictions, and to allow requests that should otherwise be ignored. An attacker who successfully exploited the…
ModificadaAlta (7.5)3.3%—Microsoft Internet Explorer14/8/201917/6/2026
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the…
ModificadaAlta (8.1)4.2%—Zohocorp Manageengine Assetexplorer8/8/201917/6/2026
Zoho ManageEngine AssetExplorer 6.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing license XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
ModificadaCrítica (9.1)4.4%—Zohocorp Manageengine Assetexplorer8/8/201917/6/2026
Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer version 6.2.0 for the AJaxServlet servlet via a parameter in a URL.
ModificadaAlta (8.8)3.1%—Zohocorp Manageengine Assetexplorer8/8/201917/6/2026
Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer 6.2.0 and before for the ClientUtilServlet servlet via a URL in a parameter.
ModificadaAlta (7.5)7.1%—Microsoft Internet ExplorerMicrosoft Edge15/7/201917/6/2026
A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory Corruption Vulnerability'.
ModificadaAlta (7.5)7.2%—Microsoft Internet Explorer15/7/201917/6/2026
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'.
ModificadaAlta (7.5)7.8%—Microsoft Internet Explorer15/7/201917/6/2026
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1001, CVE-2019-1004, CVE-2019-1056.
ModificadaAlta (7.5)7.8%—Microsoft Internet Explorer15/7/201917/6/2026
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1001, CVE-2019-1004, CVE-2019-1059.
ModificadaAlta (7.5)7.8%—Microsoft Internet Explorer15/7/201917/6/2026
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1001, CVE-2019-1056, CVE-2019-1059.
ModificadaAlta (7.5)8.1%—Microsoft ChakracoreMicrosoft Internet ExplorerMicrosoft Edge15/7/201917/6/2026
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1004, CVE-2019-1056, CVE-2019-1059.
ModificadaMedia (6.1)2.2%—Zohocorp Manageengine Assetexplorer11/7/201917/6/2026
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via ResourcesAttachments.jsp with the parameter pageName.
ModificadaMedia (6.1)2.2%—Zohocorp Manageengine Assetexplorer11/7/201917/6/2026
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via SoftwareListView.do with the parameter swType or swComplianceType.
ModificadaMedia (6.1)2.2%—Zohocorp Manageengine Assetexplorer11/7/201917/6/2026
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the RCSettings.do rdsName parameter.
ModificadaMedia (6.1)2.2%—Zohocorp Manageengine Assetexplorer11/7/201917/6/2026
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the SearchN.do search field.
ModificadaMedia (4.2)2.3%—Microsoft EdgeMicrosoft Internet Explorer12/6/201917/6/2026
An information disclosure vulnerability exists when affected Microsoft browsers improperly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit the vulnerability, in a web-based attack scenario, an attacker…
ModificadaAlta (7.5)3.3%—Microsoft Internet Explorer12/6/201917/6/2026
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability…
ModificadaAlta (7.5)3.3%—Microsoft Internet Explorer12/6/201917/6/2026
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability…
ModificadaAlta (7.5)3.3%—Microsoft Internet ExplorerMicrosoft Edge12/6/201917/6/2026
A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the…
ModificadaAlta (7.5)3.3%—Microsoft Internet Explorer12/6/201917/6/2026
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability…
ModificadaAlta (7.5)5.7%—Microsoft Internet Explorer12/6/201917/6/2026
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability…
ModificadaMedia (4.3)5.5%—Microsoft Internet Explorer12/6/201917/6/2026
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability…
ModificadaAlta (8.8)4.9%—Microsoft Internet Explorer16/5/201917/6/2026
A security feature bypass vulnerability exists when urlmon.dll improperly handles certain Mark of the Web queries, aka 'Internet Explorer Security Feature Bypass Vulnerability'.
Orbitaley — Vulnerabilidades