Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
–

1645 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.26%—SketchupAIMicrosoft Internet ExplorerAI22/5/202623/7/2026
A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration through maliciously crafted SKP files. The vulnerability stems from improper input sanitization in the component options window, enabling attackers to execute arbitrary…
AplazadaMedia (6.9)0.13%—Spotie Internet Explorer Password RecoveryAI11/3/202617/6/2026
SpotIE Internet Explorer Password Recovery 2.9.5 contains a denial of service vulnerability in the registration key input field that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a 256-character payload into the Key field during registration to trigger a…
AplazadaMedia (5)0.18%—Plain Craft LauncherAIMicrosoft Internet ExplorerAIMicrosoft WPFAI6/4/202517/6/2026
Plain Craft Launcher (PCL) is a launcher for Minecraft. PCL allows users to use homepages provided by third parties. If controls such as WebBrowser are used in the homepage, WPF will use Internet Explorer to load the specified webpage. If the user uses a malicious homepage, the attacker can use IE background to access…
ModificadaAlta (7.5)23%—Microsoft Internet Explorer11/5/202117/6/2026
Scripting Engine Memory Corruption Vulnerability
AnalizadaAlta (8.8)5.4%⚠ Explotación activaMicrosoft Internet Explorer11/3/202119/8/2026
Internet Explorer Remote Code Execution Vulnerability
AnalizadaAlta (8.8)81%⚠ Explotación activaMicrosoft EdgeMicrosoft Internet Explorer11/3/20211/10/2026
Internet Explorer Memory Corruption Vulnerability
ModificadaAlta (7.5)3.1%—Microsoft EdgeMicrosoft Internet Explorer11/11/202017/6/2026
Microsoft Browser Memory Corruption Vulnerability
ModificadaAlta (7.5)3.2%—Microsoft Internet Explorer11/11/202017/6/2026
Internet Explorer Memory Corruption Vulnerability
ModificadaAlta (8.1)2.7%—Microsoft Internet ExplorerMicrosoft Edge11/11/202017/6/2026
Scripting Engine Memory Corruption Vulnerability
ModificadaAlta (8.8)2.1%—Microsoft Internet Explorer11/9/202017/6/2026
<p>An elevation of privilege vulnerability exists in the way that the Wininit.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.</p> <p>There are multiple ways an attacker could exploit the vulnerability:</p> <ul> <li><p>In a web-based…
ModificadaAlta (8.8)3.7%—Microsoft Internet Explorer11/9/202017/6/2026
<p>An elevation of privilege vulnerability exists in the way that the Wininit.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.</p> <p>There are multiple ways an attacker could exploit the vulnerability:</p> <ul> <li><p>In a web-based…
AnalizadaAlta (7.5)2.7%⚠ Explotación activaMicrosoft Internet ExplorerMicrosoft EdgeMicrosoft Chakracore11/9/202017/6/2026
<p>A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the…
ModificadaAlta (7.5)8.8%—Microsoft Internet Explorer17/8/202017/6/2026
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the…
ModificadaAlta (7.5)3.7%—Microsoft Internet Explorer17/8/202017/6/2026
A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input. An attacker could execute arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take…
AnalizadaAlta (8.8)24%⚠ Explotación activaMicrosoft Internet Explorer17/8/202017/6/2026
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the…
ModificadaMedia (4.3)4.5%—Microsoft Internet Explorer14/7/202017/6/2026
An information disclosure vulnerability exists when Skype for Business is accessed via Internet Explorer, aka 'Skype for Business via Internet Explorer Information Disclosure Vulnerability'.
ModificadaAlta (7.5)10%—Microsoft Internet Explorer14/7/202017/6/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'.
ModificadaMedia (5.3)3.8%—Microsoft Internet Explorer9/6/202017/6/2026
An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory, aka 'Internet Explorer Information Disclosure Vulnerability'.
ModificadaAlta (7.5)7.2%—Microsoft Internet Explorer9/6/202017/6/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1214, CVE-2020-1215, CVE-2020-1216, CVE-2020-1230.
ModificadaAlta (7.5)7.1%—Microsoft Internet Explorer9/6/202017/6/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1214, CVE-2020-1215, CVE-2020-1216, CVE-2020-1260.
ModificadaAlta (7.5)19%—Microsoft Internet ExplorerMicrosoft EdgeMicrosoft Chakracore9/6/202017/6/2026
A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory Corruption Vulnerability'.
ModificadaAlta (7.5)7.2%—Microsoft Internet Explorer9/6/202017/6/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1214, CVE-2020-1215, CVE-2020-1230, CVE-2020-1260.
ModificadaAlta (7.5)8.0%—Microsoft Internet Explorer9/6/202017/6/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1214, CVE-2020-1216, CVE-2020-1230, CVE-2020-1260.
ModificadaAlta (7.5)8.0%—Microsoft Internet Explorer9/6/202017/6/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1213, CVE-2020-1215, CVE-2020-1216, CVE-2020-1230, CVE-2020-1260.
ModificadaAlta (7.5)7.2%—Microsoft Internet Explorer9/6/202017/6/2026
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1214, CVE-2020-1215, CVE-2020-1216, CVE-2020-1230, CVE-2020-1260.