Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
644 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4) | 4.1% | — | Oracle MysqlSuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT+2 | 15/10/2014 | 17/6/2026 | Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier and 5.6.20 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:INNODB DML FOREIGN KEYS. | |
| Modificada | Baja (3.3) | 2.8% | — | Oracle SolarisOracle MysqlSuse Linux Enterprise DesktopSuse Linux Enterprise Server+3 | 15/10/2014 | 17/6/2026 | Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier and 5.6.19 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:REPLICATION ROW FORMAT BINARY LOG DML. | |
| Modificada | Media (4) | 2.7% | — | Oracle MysqlSuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT+2 | 15/10/2014 | 17/6/2026 | Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier and 5.6.19 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:CHARACTER SETS. | |
| Modificada | Alta (9.3) | 91% | 💥 Exploit | Adobe Flash PlayerAdobe Flash Player Desktop RuntimeAdobe AIR Desktop RuntimeAdobe AIR SDK+3 | 15/10/2014 | 17/6/2026 | Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allows attackers to execute arbitrary code via unspecified… | |
| Modificada | Alta (10) | 6.2% | — | Adobe Flash PlayerAdobe Flash Player Desktop RuntimeAdobe AIR Desktop RuntimeAdobe AIR SDK+3 | 15/10/2014 | 17/6/2026 | Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (memory… | |
| Modificada | Baja (3.4) | 100% | 💥 PoC | Redhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server+16 | 15/10/2014 | 17/6/2026 | The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | GNU BashArista EOSOracle LinuxQnap QTS+70 | 25/9/2014 | 17/6/2026 | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | GNU BashArista EOSOracle LinuxQnap QTS+70 | 24/9/2014 | 17/6/2026 | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the… | |
| Modificada | Alta (10) | 9.3% | — | Adobe AIR SDKOpensuseSuse Linux Enterprise DesktopAdobe Flash Player+1 | 10/9/2014 | 17/6/2026 | Use-after-free vulnerability in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before… | |
| Modificada | Alta (7.1) | 5.8% | — | Linux KernelSuse Linux Enterprise DesktopSuse Linux Enterprise Real Time ExtensionSuse Linux Enterprise Server+4 | 1/8/2014 | 17/6/2026 | The sctp_assoc_update function in net/sctp/associola.c in the Linux kernel through 3.15.8, when SCTP authentication is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by starting to establish an association between two endpoints immediately after an exchange of INIT… | |
| Modificada | Media (6.9) | 2.1% | 💥 Exploit | Linux KernelOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server+2 | 19/7/2014 | 17/6/2026 | The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to gain privileges by leveraging data-structure differences between an l2tp socket and an inet socket. | |
| Modificada | Media (5.5) | 3.5% | — | Oracle MysqlOracle SolarisDebian LinuxSuse Linux Enterprise Desktop+4 | 17/7/2014 | 17/6/2026 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier, and 5.6.17 and earlier, allows remote authenticated users to affect integrity and availability via vectors related to SRCHAR. | |
| Modificada | Media (6.5) | 3.5% | — | Oracle MysqlVmware Vcenter Server ApplianceOracle SolarisOpensuse Project Suse Linux Enterprise Desktop+8 | 17/7/2014 | 17/6/2026 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier and 5.6.17 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SRINFOSC. | |
| Modificada | Baja (2.8) | 3.4% | — | Oracle SolarisOracle MysqlMariadbSuse Linux Enterprise Desktop+2 | 17/7/2014 | 17/6/2026 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.35 and earlier and 5.6.15 and earlier allows remote authenticated users to affect availability via vectors related to ENFED. | |
| Modificada | Baja (3.3) | 3.0% | — | Suse Linux Enterprise DesktopSuse Linux Enterprise ServerOracle Mysql | 17/7/2014 | 17/6/2026 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.17 and earlier allows remote authenticated users to affect availability via vectors related to SRSP. | |
| Modificada | Media (4) | 3.9% | — | Suse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KITOracle Mysql+3 | 17/7/2014 | 17/6/2026 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier allows remote authenticated users to affect availability via vectors related to SROPTZR. | |
| Modificada | Media (4) | 3.5% | — | Oracle MysqlSuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT+3 | 17/7/2014 | 17/6/2026 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier allows remote authenticated users to affect availability via vectors related to ENARC. | |
| Modificada | Media (6.5) | 2.5% | — | Oracle MysqlSuse Linux Enterprise DesktopSuse Linux Enterprise Server | 17/7/2014 | 17/6/2026 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.17 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SRFTS. | |
| Modificada | Media (5) | 5.9% | — | Linux KernelSuse Linux Enterprise DesktopSuse Linux Enterprise Real Time ExtensionSuse Linux Enterprise Server+2 | 3/7/2014 | 17/6/2026 | The sctp_association_free function in net/sctp/associola.c in the Linux kernel before 3.15.2 does not properly manage a certain backlog value, which allows remote attackers to cause a denial of service (socket outage) via a crafted SCTP packet. | |
| Modificada | Baja (2.3) | 0.65% | — | Linux KernelRedhat Enterprise LinuxCanonical Ubuntu LinuxSuse Linux Enterprise Desktop+22 | 23/6/2014 | 17/6/2026 | The rd_build_device_space function in drivers/target/target_core_rd.c in the Linux kernel before 3.14 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from ramdisk_mcp memory by leveraging access to a SCSI initiator. | |
| Modificada | Baja (2.1) | 1.1% | 💥 Exploit | Linux KernelCanonical Ubuntu LinuxSuse Linux Enterprise High Availability ExtensionSuse Linux Enterprise Desktop+1 | 23/6/2014 | 17/6/2026 | The media_device_enum_entities function in drivers/media/media-device.c in the Linux kernel before 3.14.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory by leveraging /dev/media0 read access for a MEDIA_IOC_ENUM_ENTITIES ioctl call. | |
| Modificada | Alta (10) | 6.1% | — | DirectfbOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Software Development KIT+2 | 11/6/2014 | 17/6/2026 | The Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Voodoo interface, which triggers an out-of-bounds write. | |
| Modificada | Alta (10) | 6.8% | — | OpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Software Development KITSuse Linux Enterprise Workstation Extension+2 | 11/6/2014 | 17/6/2026 | Multiple integer signedness errors in the Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.13 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Voodoo interface, which triggers a stack-based buffer overflow. | |
| Analizada | Alta (7.8) | 37% | ⚠ Explotación activa💥 Exploit | Linux KernelRedhat Enterprise Linux Server AUSOpensuseSuse Linux Enterprise Desktop+5 | 7/6/2014 | 17/6/2026 | The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification. | |
| Modificada | Media (4.3) | 86% | — | OpensslRedhat StorageFedoraproject FedoraRedhat Enterprise Linux+7 | 5/6/2014 | 17/6/2026 | The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an anonymous ECDH cipher suite is used, allows remote attackers to cause a denial of service (NULL pointer dereference and client crash) by triggering a NULL certificate value. |