Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

1785 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.9)0.87%—Oracle MysqlNetapp Oncommand Insight17/10/202317/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.34 and prior and 8.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of…
ModificadaMedia (4.9)0.94%—Oracle MysqlNetapp Oncommand Insight17/10/202317/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.34 and prior and 8.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this…
ModificadaMedia (5.3)0.89%—Oracle JDKOracle JRENetapp Cloud Insights Acquisition UnitNetapp Cloud Insights Storage Workload Security Agent17/10/202317/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: CORBA). Supported versions that are affected are Oracle Java SE: 8u381, 8u381-perf; Oracle GraalVM Enterprise Edition: 20.3.11 and 21.3.7. Easily exploitable vulnerability allows unauthenticated attacker with…
ModificadaMedia (4.9)0.94%—Oracle MysqlNetapp Oncommand Insight17/10/202317/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.34 and prior and 8.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this…
ModificadaMedia (4.9)0.93%—Oracle MysqlNetapp Oncommand Insight17/10/202317/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.33 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this…
ModificadaMedia (4.9)0.88%—Oracle MysqlNetapp Oncommand Insight17/10/202317/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.34 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this…
ModificadaMedia (6.5)0.98%—Oracle MysqlNetapp Oncommand Insight17/10/202317/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.34 and prior and 8.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of…
ModificadaMedia (4.9)0.94%—Oracle MysqlNetapp Oncommand Insight17/10/202317/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.34 and prior and 8.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of…
ModificadaMedia (4.9)0.89%—Oracle MysqlNetapp Oncommand Insight17/10/202317/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.7.43 and prior and 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful…
ModificadaMedia (4.9)0.88%—Oracle MysqlNetapp Oncommand Insight17/10/202317/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.7.42 and prior and 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful…
ModificadaBaja (3.7)0.89%—Oracle Graalvm FOR JDKOracle JDKOracle JRENetapp Cloud Insights Acquisition Unit+117/10/202317/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u381-perf, 17.0.8, 21; Oracle GraalVM for JDK: 17.0.8, 21; Oracle GraalVM Enterprise Edition: 21.3.7 and 22.3.3.…
ModificadaMedia (4.9)0.89%—Oracle MysqlNetapp Oncommand Insight17/10/202317/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.7.42 and prior and 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful…
ModificadaMedia (5.3)0.34%—Hcltech Bigfix Insights FOR Vulnerability Remediation11/10/202317/6/2026
BigFix Insights/IVR fixlet uses improper credential handling within certain fixlet content. An attacker can gain access to information that is not explicitly authorized.
ModificadaAlta (8.2)0.33%—Hcltech Bigfix Insights FOR Vulnerability Remediation11/10/202317/6/2026
BigFix Insights for Vulnerability Remediation (IVR) uses weak cryptography that can lead to credential exposure. An attacker could gain access to sensitive information, modify data in unexpected ways, etc.
ModificadaCrítica (9.8)1.7%—Microsoft Azure Hdinsight10/10/202317/6/2026
Azure HDInsight Apache Oozie Workflow Scheduler XXE Elevation of Privilege Vulnerability
AnalizadaAlta (7.5)100%⚠ Explotación activa💥 ExploitSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/202311/8/2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
ModificadaMedia (6.1)0.42%—Milesight Ur51 FirmwareMilesight Ur52 FirmwareMilesight Ur55 FirmwareMilesight Ur32l Firmware+35/10/202317/6/2026
Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the admin panel.
ModificadaAlta (7.5)64%💥 ExploitMilesight Ur5x FirmwareMilesight Ur32l FirmwareMilesight Ur32 FirmwareMilesight Ur35 Firmware+14/10/20239/7/2026
An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.
AnalizadaMedia (6.1)0.56%—Monsterinsights Userfeedback29/9/202317/6/2026
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in UserFeedback Team User Feedback plugin <= 1.0.7 versions.
AnalizadaAlta (8.8)24%⚠ Explotación activa💥 PoCApple IpadosApple Iphone OSApple MacosFedoraproject Fedora+1021/9/202317/6/2026
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.
ModificadaAlta (7.2)2.0%—Microsoft Azure Hdinsight12/9/202317/6/2026
Azure HDInsight Apache Ambari JDBC Injection Elevation of Privilege Vulnerability
ModificadaMedia (5.4)0.44%—I-pro Video Insight5/9/202317/6/2026
Stored cross-site scripting vulnerability in Map setting page of VI Web Client prior to 7.9.6 allows a remote authenticated attacker to inject an arbitrary script.
ModificadaMedia (5.4)0.44%—I-pro Video Insight5/9/202317/6/2026
Stored cross-site scripting vulnerability in View setting page of VI Web Client prior to 7.9.6 allows a remote authenticated attacker to inject an arbitrary script.
ModificadaMedia (6.1)0.51%—I-pro Video Insight5/9/202317/6/2026
Reflected cross-site scripting vulnerability in VI Web Client prior to 7.9.6 allows a remote unauthenticated attacker to inject an arbitrary script.
ModificadaMedia (6.1)0.50%—I-pro Video Insight5/9/202317/6/2026
Open redirect vulnerability in VI Web Client prior to 7.9.6 allows a remote unauthenticated attacker to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL.