Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

1970 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)8.7%—Microsoft Internet ExplorerMicrosoft ChakracoreMicrosoft Edge12/3/202017/6/2026
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-2020-0825, CVE-2020-0826, CVE-2020-0827, CVE-2020-0828, CVE-2020-0829,…
ModificadaAlta (7.5)7.2%—Microsoft Internet Explorer12/3/202017/6/2026
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'.
ModificadaAlta (7.5)8.7%—Microsoft ChakracoreMicrosoft Internet ExplorerMicrosoft Edge12/3/202017/6/2026
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0823, CVE-2020-0825, CVE-2020-0826, CVE-2020-0827, CVE-2020-0828, CVE-2020-0829, CVE-2020-0830,…
ModificadaCrítica (9.1)0.48%—Naver Cloud Explorer3/3/202017/6/2026
Naver Cloud Explorer before 2.2.2.11 allows the system to download an arbitrary file from the attacker's server and execute it during the upgrade.
ModificadaMedia (6.1)1.0%—Amazon AWS Javascript S3 Explorer13/2/202017/6/2026
explorer.js in Amazon AWS JavaScript S3 Explorer (aka aws-js-s3-explorer) v2 alpha before 2019-08-02 allows XSS in certain circumstances.
ModificadaMedia (4.3)5.1%—Microsoft Internet ExplorerMicrosoft Edge11/2/202017/6/2026
An information disclosure vulnerability exists in the way that affected Microsoft browsers handle cross-origin requests, aka 'Microsoft Browser Information Disclosure Vulnerability'.
AnalizadaAlta (7.5)87%⚠ Explotación activa💥 ExploitMicrosoft Internet Explorer11/2/202017/6/2026
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0710, CVE-2020-0711, CVE-2020-0712, CVE-2020-0713, CVE-2020-0767.
ModificadaAlta (7.5)9.9%—Microsoft Internet Explorer11/2/202017/6/2026
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0674, CVE-2020-0710, CVE-2020-0711, CVE-2020-0712, CVE-2020-0713, CVE-2020-0767.
ModificadaAlta (8.8)1.5%—Super File Explorer Project Super File Explorer28/1/202017/6/2026
An arbitrary file upload vulnerability has been discovered in the Super File Explorer app 1.0.1 for iOS. The vulnerability is located in the developer path that is accessible and hidden next to the root path. By default, there is no password set for the FTP or Web UI service.
ModificadaCrítica (9.8)2.6%—Lorextechnology Lnc116 FirmwareLorextechnology Lnc104 Firmware24/1/202016/6/2026
Lorex LNC116 and LNC104 IP Cameras have a Remote Authentication Bypass Vulnerability
ModificadaAlta (7.5)8.6%—Microsoft Internet Explorer14/1/202017/6/2026
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'.
ModificadaMedia (6.1)1.6%—Quixplorer Project Quixplorer2/1/202016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in QuiXplorer before 2.5.5 allow remote attackers to inject arbitrary web script or HTML via the (1) dir, (2) item, (3) order, (4) searchitem, (5) selitems[], or (6) srt parameter to index.php or (7) the QUERY_STRING to index.php.
ModificadaAlta (7.5)8.2%—Microsoft Internet Explorer10/12/201917/6/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'.
AnalizadaAlta (7.5)77%⚠ Explotación activa💥 ExploitMicrosoft Internet Explorer12/11/201917/6/2026
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1426, CVE-2019-1427, CVE-2019-1428.
ModificadaAlta (7.5)7.8%—Microsoft Internet Explorer12/11/201917/6/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'.
ModificadaAlta (7.8)0.23%—Cobham Explorer 710 Firmware10/10/201917/6/2026
The Cobham EXPLORER 710, firmware version 1.07, does not validate its firmware image. Development scripts left in the firmware can be used to upload a custom firmware image that the device runs. This could allow an unauthenticated, local attacker to upload their own firmware that could be used to intercept or modify…
ModificadaCrítica (9.8)1.5%—Cobham Explorer 710 Firmware10/10/201917/6/2026
The root password of the Cobham EXPLORER 710 is the same for all versions of firmware up to and including v1.08. This could allow an attacker to reverse-engineer the password from available versions to gain authenticated access to the device.
ModificadaAlta (7.8)0.21%—Cobham Explorer 710 Firmware10/10/201917/6/2026
The web application portal of the Cobham EXPLORER 710, firmware version 1.07, sends the login password in cleartext. This could allow an unauthenticated, local attacker to intercept the password and gain access to the portal.
ModificadaCrítica (9.8)2.5%—Cobham Explorer 710 Firmware10/10/201917/6/2026
The web application portal of the Cobham EXPLORER 710, firmware version 1.07, allows unauthenticated access to port 5454. This could allow an unauthenticated, remote attacker to connect to this port via Telnet and execute 86 Attention (AT) commands, including some that provide unauthenticated, shell-like access to the…
ModificadaMedia (5.5)0.36%—Cobham Explorer 710 Firmware10/10/201917/6/2026
The web root directory of the Cobham EXPLORER 710, firmware version 1.07, has no access restrictions on downloading and reading all files. This could allow an unauthenticated, local attacker connected to the device to access and download any file found in the web root directory.
ModificadaMedia (5.5)0.28%—Cobham Explorer 710 Firmware10/10/201917/6/2026
The web application portal of the Cobham EXPLORER 710, firmware version 1.07, has no authentication by default. This could allow an unauthenticated, local attacker connected to the device to access the portal and to make any change to the device.
ModificadaAlta (7.5)7.4%—Microsoft Internet Explorer10/10/201917/6/2026
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'.
ModificadaMedia (4.3)2.3%—Microsoft Internet ExplorerMicrosoft Edge10/10/201917/6/2026
A spoofing vulnerability exists when Microsoft Browsers improperly handle browser cookies, aka 'Microsoft Browser Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0608.
ModificadaAlta (7.5)7.5%—Microsoft Internet Explorer10/10/201917/6/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1238.
ModificadaMedia (6.4)5.9%—Microsoft Internet Explorer10/10/201917/6/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1239.
Orbitaley — Vulnerabilidades