Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

617 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)1.6%—Siemens En100 Ethernet Module With Firmware Variant Dnp3 TCPSiemens En100 Ethernet Module With Firmware Variant IEC 61850Siemens En100 Ethernet Module With Firmware Variant Iec104Siemens En100 Ethernet Module With Firmware Variant Modbus TCP+112/12/201917/6/2026
A vulnerability has been identified in EN100 Ethernet module DNP3 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.37), EN100 Ethernet module IEC104 variant (All versions), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module PROFINET IO variant (All…
ModificadaMedia (6.1)0.89%—Siemens En100 Ethernet Module With Firmware Variant Dnp3 TCPSiemens En100 Ethernet Module With Firmware Variant IEC 61850Siemens En100 Ethernet Module With Firmware Variant Iec104Siemens En100 Ethernet Module With Firmware Variant Modbus TCP+112/12/201917/6/2026
A vulnerability has been identified in EN100 Ethernet module DNP3 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.37), EN100 Ethernet module IEC104 variant (All versions), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module PROFINET IO variant (All…
ModificadaAlta (7.5)1.9%—Siemens En100 Ethernet Module With Firmware Variant Dnp3 TCPSiemens En100 Ethernet Module With Firmware Variant IEC 61850Siemens En100 Ethernet Module With Firmware Variant Iec104Siemens En100 Ethernet Module With Firmware Variant Modbus TCP+112/12/201917/6/2026
A vulnerability has been identified in EN100 Ethernet module DNP3 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.37), EN100 Ethernet module IEC104 variant (All versions), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module PROFINET IO variant (All…
ModificadaMedia (4.3)0.95%—Yithemes Yith Woocommerce WishlistYithemes Yith Woocommerce CompareYithemes Yith Woocommerce Quick ViewYithemes Yith Woocommerce Zoom Magnifier+3431/10/201917/6/2026
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
ModificadaMedia (6.5)3.7%—Oracle MysqlMariadbCanonical Ubuntu LinuxFedoraproject Fedora+116/10/201917/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.6.45 and prior, 5.7.27 and prior and 8.0.17 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL…
ModificadaMedia (4.4)3.0%—Oracle MysqlMariadbFedoraproject FedoraCanonical Ubuntu Linux+516/10/201917/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.27 and prior and 8.0.17 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of…
ModificadaMedia (5.4)1.0%—Getwooplugins Additional Variation Images FOR Woocommerce29/8/201917/6/2026
The woo-variation-gallery plugin before 1.1.29 for WordPress has XSS.
ModificadaMedia (6.1)0.92%—Deepsoft Weblibrarian21/8/201917/6/2026
The weblibrarian plugin before 3.4.8.7 for WordPress has XSS via front-end short codes.
ModificadaMedia (6.1)0.89%—Deepsoft Weblibrarian21/8/201917/6/2026
The weblibrarian plugin before 3.4.8.6 for WordPress has XSS via front-end short codes.
ModificadaMedia (6.1)0.92%—Deepsoft Weblibrarian21/8/201917/6/2026
The weblibrarian plugin before 3.4.8.5 for WordPress has XSS via front-end short codes.
ModificadaMedia (6.1)1.0%—Getwooplugins Woo-variation-swatches8/8/201917/6/2026
The woo-variation-swatches (aka Variation Swatches for WooCommerce) plugin 1.0.61 for WordPress allows XSS via the wp-admin/admin.php?page=woo-variation-swatches-settings tab parameter.
ModificadaMedia (6.5)3.7%—Oracle MysqlMariadbCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+723/7/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL…
ModificadaMedia (5.5)3.1%—Oracle MysqlCanonical Ubuntu LinuxMariadb23/7/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks…
ModificadaMedia (6.5)4.0%—Oracle MysqlCanonical Ubuntu LinuxMariadbRedhat Enterprise Linux Desktop+723/7/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: XML). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL…
ModificadaMedia (5.1)0.79%—Oracle MysqlCanonical Ubuntu LinuxFedoraproject FedoraRedhat Enterprise Linux EUS+323/7/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where MySQL…
ModificadaMedia (4.9)3.9%—Oracle MysqlCanonical Ubuntu LinuxMariadbFedoraproject Fedora+123/7/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Pluggable Auth). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to…
ModificadaMedia (6.5)1.4%—Deepsoft Weblibrarian15/7/201917/6/2026
Deepwoods Software WebLibrarian 3.5.2 and earlier is affected by: SQL Injection. The impact is: Exposing the entire database. The component is: Function "AllBarCodes" (defined at database_code.php line 1018) is vulnerable to a boolean-based blind sql injection. This function call can be triggered by any user logged-in…
ModificadaMedia (4.9)2.8%—Oracle MysqlCanonical Ubuntu LinuxMariadbOpensuse Leap+423/4/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.25 and prior and 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks…
ModificadaMedia (4.9)3.0%—Oracle MysqlCanonical Ubuntu LinuxMariadbOpensuse Leap+623/4/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 5.6.43 and prior, 5.7.25 and prior and 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to…
ModificadaMedia (4.4)2.8%—Oracle MysqlCanonical Ubuntu LinuxMariadbRedhat Enterprise Linux Desktop+723/4/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.6.43 and prior, 5.7.25 and prior and 8.0.15 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise…
ModificadaMedia (6.1)0.86%—Scilico I, Librarian22/4/201917/6/2026
I, Librarian 4.10 has XSS via the notes.php notes parameter.
ModificadaMedia (6.1)0.87%—Scilico I, Librarian22/4/201917/6/2026
I, Librarian 4.10 has XSS via the export.php export_files parameter.
ModificadaMedia (6.1)1.1%—Scilico I, Librarian20/4/201917/6/2026
Cross-site scripting (XSS) vulnerability in display.php in I, Librarian 4.10 allows remote attackers to inject arbitrary web script or HTML via the project parameter.
ModificadaMedia (6.5)0.19%—Medtronic Mycarelink Monitor 24950 FirmwareMedtronic Mycarelink Monitor 24952 FirmwareMedtronic Carelink Monitor 2490c FirmwareMedtronic Carelink 2090 Firmware+1926/3/201917/6/2026
The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 Programmer, Amplia CRT-D, Claria CRT-D, Compia CRT-D, Concerto CRT-D, Concerto II CRT-D, Consulta CRT-D, Evera ICD, Maximo II CRT-D and ICD, Mirro ICD, Nayamed ND ICD,…
ModificadaMedia (6.5)0.90%—Medtronic Mycarelink Monitor FirmwareMedtronic Carelink Monitor FirmwareMedtronic Carelink 2090 FirmwareMedtronic Amplia Crt-d Firmware+1625/3/201917/6/2026
The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 Programmer, Amplia CRT-D, Claria CRT-D, Compia CRT-D, Concerto CRT-D, Concerto II CRT-D, Consulta CRT-D, Evera ICD, Maximo II CRT-D and ICD, Mirro ICD, Nayamed ND ICD,…
Orbitaley — Vulnerabilidades