Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 29 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.3) | 0.75% | — | Microsoft SQL Server Management StudioMicrosoft Visual Studio Tools FOR Applications 2019Microsoft Visual Studio Tools FOR Applications 2019 SDKMicrosoft Visual Studio Tools FOR Applications 2022+1 | 12/4/2025 | 17/6/2026 | Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally. | |
| Modificada | Media (5.5) | 1.2% | — | Microsoft SQL Server Management Studio | 17/8/2020 | 17/6/2026 | A denial of service vulnerability exists when Microsoft SQL Server Management Studio (SSMS) improperly handles files. An attacker could exploit the vulnerability to trigger a denial of service. To exploit the vulnerability, an attacker would first require execution on the victim system. The security update addresses… | |
| Modificada | Media (6.5) | 5.4% | — | Microsoft SQL Server Management Studio | 10/10/2019 | 17/6/2026 | An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when it improperly enforces permissions, aka 'SQL Server Management Studio Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1313. | |
| Modificada | Media (6.5) | 5.3% | — | Microsoft SQL Server Management Studio | 10/10/2019 | 17/6/2026 | An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when it improperly enforces permissions, aka 'SQL Server Management Studio Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1376. | |
| Modificada | Media (5.5) | 23% | — | Microsoft SQL Server Management Studio | 10/10/2018 | 17/6/2026 | An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing malicious XML content containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This affects SQL Server Management Studio 17.9, SQL Server Management… | |
| Modificada | Media (5.5) | 23% | — | Microsoft SQL Server Management Studio | 10/10/2018 | 17/6/2026 | An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XMLA file containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This affects SQL Server Management Studio 17.9, SQL Server Management… | |
| Modificada | Media (5.5) | 23% | — | Microsoft SQL Server Management Studio | 10/10/2018 | 17/6/2026 | An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XEL file containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This affects SQL Server Management Studio 17.9, SQL Server Management… | |
| Modificada | Media (4.3) | 15% | — | Microsoft Office InfopathMicrosoft SQL ServerMicrosoft SQL Server Management Studio ExpressMicrosoft Visual Studio | 16/6/2011 | 16/6/2026 | The XML Editor in Microsoft InfoPath 2007 SP2 and 2010; SQL Server 2005 SP3 and SP4 and 2008 SP1, SP2, and R2; SQL Server Management Studio Express (SSMSE) 2005; and Visual Studio 2005 SP1, 2008 SP1, and 2010 does not properly handle external entities, which allows remote attackers to read arbitrary files via a… |