Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
2192 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 2.7% | — | Icedtea-web Project Icedtea-webRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+2 | 31/7/2019 | 17/6/2026 | It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to upload arbitrary files to arbitrary locations in the context of the user. | |
| Modificada | Media (5) | 2.2% | — | Clusterlabs Fence-agentsRedhat Enterprise LinuxRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 30/7/2019 | 17/6/2026 | A flaw was discovered in fence-agents, prior to version 4.3.4, where using non-ASCII characters in a guest VM's comment or other fields would cause fence_rhevm to exit with an exception. In cluster environments, this could lead to preventing automated recovery or otherwise denying service to clusters of which that VM… | |
| Modificada | Alta (7.5) | 2.7% | — | Linux KernelRedhat Developer ToolsRedhat MRG RealtimeRedhat Enterprise Linux+16 | 30/7/2019 | 17/6/2026 | A flaw was found in the Linux kernel's NFS implementation, all versions 3.x and all versions 4.x up to 4.20. An attacker, who is able to mount an exported NFS filesystem, is able to trigger a null pointer dereference by using an invalid NFS sequence. This can panic the machine and deny access to the NFS server. Any… | |
| Modificada | Alta (7.4) | 1.5% | — | Eclipse Openj9Redhat SatelliteRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 30/7/2019 | 17/6/2026 | All builds of Eclipse OpenJ9 prior to 0.15 contain a bug where the loop versioner may fail to privatize a value that is pulled out of the loop by versioning - for example if there is a condition that is moved out of the loop that reads a field we may not privatize the value of that field in the modified copy of the… | |
| Modificada | Media (4.9) | 1.9% | — | Oracle MysqlRedhat Software CollectionsRedhat Enterprise LinuxRedhat Enterprise Linux EUS+2 | 23/7/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability… | |
| Modificada | Media (6.5) | 2.3% | — | Oracle MysqlRedhat Software CollectionsRedhat Enterprise LinuxRedhat Enterprise Linux EUS+2 | 23/7/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (4.9) | 2.2% | — | Oracle MysqlRedhat Software CollectionsRedhat Enterprise LinuxRedhat Enterprise Linux EUS+2 | 23/7/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (4.9) | 2.0% | — | Oracle MysqlRedhat Software CollectionsRedhat Enterprise LinuxRedhat Enterprise Linux EUS+2 | 23/7/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Roles). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of… | |
| Modificada | Media (5.5) | 1.9% | — | Oracle MysqlCanonical Ubuntu LinuxRedhat Software CollectionsRedhat Enterprise Linux+3 | 23/7/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Audit). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to… | |
| Modificada | Media (4.8) | 2.3% | — | Oracle JDKOracle JREDebian LinuxOpensuse Leap+9 | 23/7/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple… | |
| Modificada | Media (4.9) | 2.0% | — | Oracle MysqlRedhat Software CollectionsRedhat Enterprise LinuxRedhat Enterprise Linux EUS+2 | 23/7/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Baja (2.2) | 1.3% | — | Oracle MysqlRedhat Software CollectionsRedhat Enterprise LinuxRedhat Enterprise Linux EUS+2 | 23/7/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 8.0.16 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (6.5) | 2.1% | — | Oracle MysqlRedhat Software CollectionsRedhat Enterprise LinuxRedhat Enterprise Linux EUS+2 | 23/7/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (4.9) | 2.0% | — | Oracle MysqlRedhat Software CollectionsRedhat Enterprise LinuxRedhat Enterprise Linux EUS+2 | 23/7/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks… | |
| Modificada | Media (4.9) | 2.0% | — | Oracle MysqlRedhat Software CollectionsRedhat Enterprise LinuxRedhat Enterprise Linux EUS+2 | 23/7/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (4.9) | 2.0% | — | Oracle MysqlRedhat Software CollectionsRedhat Enterprise LinuxRedhat Enterprise Linux EUS+2 | 23/7/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (6.5) | 3.7% | — | Oracle MysqlMariadbCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+7 | 23/7/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL… | |
| Modificada | Media (4.9) | 2.0% | — | Oracle MysqlRedhat Software CollectionsRedhat Enterprise LinuxRedhat Enterprise Linux EUS+2 | 23/7/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (4.9) | 2.0% | — | Oracle MysqlRedhat Software CollectionsRedhat Enterprise LinuxRedhat Enterprise Linux EUS+2 | 23/7/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (4.9) | 2.0% | — | Oracle MysqlRedhat Software CollectionsRedhat Enterprise LinuxRedhat Enterprise Linux EUS+2 | 23/7/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: FTS). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Alta (7.1) | 2.3% | — | Oracle MysqlRedhat Software CollectionsRedhat Enterprise LinuxRedhat Enterprise Linux EUS+2 | 23/7/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (4.9) | 2.0% | — | Oracle MysqlRedhat Software CollectionsRedhat Enterprise LinuxRedhat Enterprise Linux EUS+2 | 23/7/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability… | |
| Modificada | Media (4.2) | 0.81% | — | Oracle MysqlCanonical Ubuntu LinuxRedhat Software CollectionsRedhat Enterprise Linux+3 | 23/7/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.7.26 and prior and 8.0.16 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware… | |
| Modificada | Media (4.9) | 2.0% | — | Oracle MysqlRedhat Software CollectionsRedhat Enterprise LinuxRedhat Enterprise Linux EUS+2 | 23/7/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (6.5) | 2.7% | — | Oracle MysqlRedhat Software CollectionsRedhat Enterprise LinuxRedhat Enterprise Linux EUS+2 | 23/7/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Charsets). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… |