Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1785 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.9) | 0.87% | — | Oracle MysqlNetapp Oncommand Insight | 17/10/2023 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.34 and prior and 8.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of… | |
| Modificada | Media (4.9) | 0.94% | — | Oracle MysqlNetapp Oncommand Insight | 17/10/2023 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.34 and prior and 8.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (5.3) | 0.89% | — | Oracle JDKOracle JRENetapp Cloud Insights Acquisition UnitNetapp Cloud Insights Storage Workload Security Agent | 17/10/2023 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: CORBA). Supported versions that are affected are Oracle Java SE: 8u381, 8u381-perf; Oracle GraalVM Enterprise Edition: 20.3.11 and 21.3.7. Easily exploitable vulnerability allows unauthenticated attacker with… | |
| Modificada | Media (4.9) | 0.94% | — | Oracle MysqlNetapp Oncommand Insight | 17/10/2023 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.34 and prior and 8.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (4.9) | 0.93% | — | Oracle MysqlNetapp Oncommand Insight | 17/10/2023 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.33 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (4.9) | 0.88% | — | Oracle MysqlNetapp Oncommand Insight | 17/10/2023 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.34 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (6.5) | 0.98% | — | Oracle MysqlNetapp Oncommand Insight | 17/10/2023 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.34 and prior and 8.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of… | |
| Modificada | Media (4.9) | 0.94% | — | Oracle MysqlNetapp Oncommand Insight | 17/10/2023 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.34 and prior and 8.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of… | |
| Modificada | Media (4.9) | 0.89% | — | Oracle MysqlNetapp Oncommand Insight | 17/10/2023 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.7.43 and prior and 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful… | |
| Modificada | Media (4.9) | 0.88% | — | Oracle MysqlNetapp Oncommand Insight | 17/10/2023 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.7.42 and prior and 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful… | |
| Modificada | Baja (3.7) | 0.89% | — | Oracle Graalvm FOR JDKOracle JDKOracle JRENetapp Cloud Insights Acquisition Unit+1 | 17/10/2023 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u381-perf, 17.0.8, 21; Oracle GraalVM for JDK: 17.0.8, 21; Oracle GraalVM Enterprise Edition: 21.3.7 and 22.3.3.… | |
| Modificada | Media (4.9) | 0.89% | — | Oracle MysqlNetapp Oncommand Insight | 17/10/2023 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.7.42 and prior and 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful… | |
| Modificada | Media (5.3) | 0.34% | — | Hcltech Bigfix Insights FOR Vulnerability Remediation | 11/10/2023 | 17/6/2026 | BigFix Insights/IVR fixlet uses improper credential handling within certain fixlet content. An attacker can gain access to information that is not explicitly authorized. | |
| Modificada | Alta (8.2) | 0.33% | — | Hcltech Bigfix Insights FOR Vulnerability Remediation | 11/10/2023 | 17/6/2026 | BigFix Insights for Vulnerability Remediation (IVR) uses weak cryptography that can lead to credential exposure. An attacker could gain access to sensitive information, modify data in unexpected ways, etc. | |
| Modificada | Crítica (9.8) | 1.7% | — | Microsoft Azure Hdinsight | 10/10/2023 | 17/6/2026 | Azure HDInsight Apache Oozie Workflow Scheduler XXE Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Media (6.1) | 0.42% | — | Milesight Ur51 FirmwareMilesight Ur52 FirmwareMilesight Ur55 FirmwareMilesight Ur32l Firmware+3 | 5/10/2023 | 17/6/2026 | Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the admin panel. | |
| Modificada | Alta (7.5) | 64% | 💥 Exploit | Milesight Ur5x FirmwareMilesight Ur32l FirmwareMilesight Ur32 FirmwareMilesight Ur35 Firmware+1 | 4/10/2023 | 9/7/2026 | An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components. | |
| Analizada | Media (6.1) | 0.56% | — | Monsterinsights Userfeedback | 29/9/2023 | 17/6/2026 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in UserFeedback Team User Feedback plugin <= 1.0.7 versions. | |
| Analizada | Alta (8.8) | 24% | ⚠ Explotación activa💥 PoC | Apple IpadosApple Iphone OSApple MacosFedoraproject Fedora+10 | 21/9/2023 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7. | |
| Modificada | Alta (7.2) | 2.0% | — | Microsoft Azure Hdinsight | 12/9/2023 | 17/6/2026 | Azure HDInsight Apache Ambari JDBC Injection Elevation of Privilege Vulnerability | |
| Modificada | Media (5.4) | 0.44% | — | I-pro Video Insight | 5/9/2023 | 17/6/2026 | Stored cross-site scripting vulnerability in Map setting page of VI Web Client prior to 7.9.6 allows a remote authenticated attacker to inject an arbitrary script. | |
| Modificada | Media (5.4) | 0.44% | — | I-pro Video Insight | 5/9/2023 | 17/6/2026 | Stored cross-site scripting vulnerability in View setting page of VI Web Client prior to 7.9.6 allows a remote authenticated attacker to inject an arbitrary script. | |
| Modificada | Media (6.1) | 0.51% | — | I-pro Video Insight | 5/9/2023 | 17/6/2026 | Reflected cross-site scripting vulnerability in VI Web Client prior to 7.9.6 allows a remote unauthenticated attacker to inject an arbitrary script. | |
| Modificada | Media (6.1) | 0.50% | — | I-pro Video Insight | 5/9/2023 | 17/6/2026 | Open redirect vulnerability in VI Web Client prior to 7.9.6 allows a remote unauthenticated attacker to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL. |