Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2727▼ 513 respecto a la semana anterior
Críticas / altas1294▼ 200 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

828 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (9.3)31%💥 ExploitMicrosoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows Vista9/12/201517/6/2026
Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows remote attackers to execute arbitrary code via a crafted .mcl file, aka "Media Center Library Parsing RCE Vulnerability."
ModificadaAlta (7.2)82%💥 ExploitMicrosoft Windows 7Microsoft Windows Server 2008Microsoft Windows Vista9/12/201517/6/2026
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Windows Library Loading Remote Code Execution Vulnerability."
ModificadaMedia (4.3)46%💥 ExploitMicrosoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows Vista9/12/201517/6/2026
Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows remote attackers to read arbitrary files via a crafted .mcl file, aka "Windows Media Center Information Disclosure Vulnerability."
ModificadaAlta (7.2)1.6%—Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+59/12/201517/6/2026
Race condition in the Pragmatic General Multicast (PGM) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges or…
ModificadaAlta (9.3)26%—Microsoft Live MeetingMicrosoft LyncMicrosoft OfficeMicrosoft Silverlight+119/12/201517/6/2026
The Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT Gold and 8.1; Office 2007 SP3; Office 2010 SP2; Word Viewer; .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6; Skype for…
ModificadaAlta (9.3)18%—Microsoft Live MeetingMicrosoft LyncMicrosoft OfficeMicrosoft Skype FOR Business+109/12/201517/6/2026
The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10 Gold and 1511, Office 2007 SP3, Office 2010 SP2, Word Viewer, Skype for Business 2016, Lync 2010, Lync 2013 SP1, and…
ModificadaAlta (9.3)17%—Microsoft Live MeetingMicrosoft LyncMicrosoft OfficeMicrosoft Skype FOR Business+39/12/201517/6/2026
The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2, Office 2007 SP3, Office 2010 SP2, Word Viewer, Skype for Business 2016, Lync 2010, Lync 2013 SP1, and Live Meeting 2007 Console allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Graphics Memory…
ModificadaBaja (2.1)2.0%—Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+511/11/201517/6/2026
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to bypass intended filesystem permissions by leveraging Low Integrity access, aka "Windows…
ModificadaMedia (5.8)2.8%—Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+411/11/201517/6/2026
SChannel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 lacks the required extended master-secret binding support to ensure that a server's X.509 certificate is the same during renegotiation as it…
ModificadaAlta (9.3)35%💥 ExploitMicrosoft Windows 10Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+511/11/201517/6/2026
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Windows…
ModificadaAlta (9.3)35%💥 ExploitMicrosoft Windows 10Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+511/11/201517/6/2026
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Windows…
ModificadaBaja (2.1)4.1%💥 ExploitMicrosoft Windows 10Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+511/11/201517/6/2026
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to bypass the KASLR protection mechanism, and consequently discover a driver base address, via…
ModificadaMedia (6.9)3.1%💥 ExploitMicrosoft Windows 10Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+511/11/201517/6/2026
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Elevation of Privilege…
ModificadaMedia (6.9)3.2%💥 ExploitMicrosoft Windows 10Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+511/11/201517/6/2026
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Elevation of Privilege…
ModificadaAlta (7.2)4.0%💥 ExploitMicrosoft Windows 7Microsoft Windows Server 2008Microsoft Windows Vista11/11/201517/6/2026
Buffer overflow in the Network Driver Interface Standard (NDIS) implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "Windows NDIS Elevation of Privilege Vulnerability."
ModificadaAlta (9.3)21%—Microsoft Windows 7Microsoft Windows Server 2008Microsoft Windows Vista11/11/201517/6/2026
Heap-based buffer overflow in Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted Journal (.jnt) file, aka "Windows Journal Heap Overflow Vulnerability."
ModificadaMedia (4.9)4.0%💥 PoCMicrosoft Windows 10Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+311/11/201517/6/2026
Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandles password changes, which allows physically proximate attackers to bypass authentication, and conduct…
ModificadaAlta (7.2)1.9%—Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+511/11/201517/6/2026
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application that triggers a Winsock call referencing an invalid address, aka…
ModificadaAlta (7.2)3.6%💥 ExploitMicrosoft Windows 10Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+514/10/201517/6/2026
The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Windows Object Reference Elevation of Privilege Vulnerability."
ModificadaAlta (7.2)3.3%💥 ExploitMicrosoft Windows 10Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+514/10/201517/6/2026
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 mishandles junctions during mountpoint creation, which makes it easier for local users to gain privileges by leveraging certain…
ModificadaAlta (7.2)1.7%—Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+514/10/201517/6/2026
The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows physically proximate attackers to bypass the Trusted Boot protection mechanism, and consequently interfere with the integrity of code, BitLocker, Device Encryption, and Device Health…
ModificadaAlta (7.2)1.9%—Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+514/10/201517/6/2026
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Windows Elevation of Privilege Vulnerability."
ModificadaAlta (7.2)2.3%—Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+514/10/201517/6/2026
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Corruption Vulnerability."
ModificadaAlta (9.3)25%—Microsoft Windows 7Microsoft Windows Vista14/10/201517/6/2026
Use-after-free vulnerability in the Tablet Input Band in Windows Shell in Microsoft Windows Vista SP2 and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Microsoft Tablet Input Band Use After Free Vulnerability."
ModificadaAlta (9.3)29%—Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1+514/10/201517/6/2026
Use-after-free vulnerability in Windows Shell in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows remote attackers to execute arbitrary code via a crafted toolbar object, aka "Toolbar…