Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
2286 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.2) | 0.81% | — | Oracle MysqlCanonical Ubuntu LinuxRedhat Software CollectionsRedhat Enterprise Linux+3 | 23/7/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.7.26 and prior and 8.0.16 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware… | |
| Modificada | Media (4.9) | 2.0% | — | Oracle MysqlRedhat Software CollectionsRedhat Enterprise LinuxRedhat Enterprise Linux EUS+2 | 23/7/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (6.5) | 2.7% | — | Oracle MysqlRedhat Software CollectionsRedhat Enterprise LinuxRedhat Enterprise Linux EUS+2 | 23/7/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Charsets). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Baja (2.7) | 1.9% | — | Oracle MysqlFedoraproject FedoraRedhat Software CollectionsRedhat Enterprise Linux+3 | 23/7/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks… | |
| Modificada | Baja (3.4) | 2.6% | — | Oracle JDKOracle JREOpensuse LeapHP XP7 Command View+7 | 23/7/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Media (4.9) | 2.5% | — | Oracle MysqlFedoraproject FedoraRedhat Software CollectionsRedhat Enterprise Linux+3 | 23/7/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability… | |
| Modificada | Media (4.9) | 2.1% | — | Oracle MysqlFedoraproject FedoraRedhat Software CollectionsRedhat Enterprise Linux+3 | 23/7/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (4.9) | 2.1% | — | Oracle MysqlFedoraproject FedoraRedhat Software CollectionsRedhat Enterprise Linux+3 | 23/7/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Components / Services). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful… | |
| Modificada | Media (5.4) | 1.8% | — | Oracle MysqlCanonical Ubuntu LinuxFedoraproject FedoraRedhat Software Collections+4 | 23/7/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL… | |
| Modificada | Media (4.9) | 2.3% | — | Oracle MysqlCanonical Ubuntu LinuxFedoraproject FedoraRedhat Software Collections+4 | 23/7/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.… | |
| Modificada | Media (5.3) | 4.4% | — | Oracle JDKOracle JREDebian LinuxCanonical Ubuntu Linux+9 | 23/7/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols… | |
| Modificada | Media (5.3) | 4.4% | — | Oracle JDKOracle JRECanonical Ubuntu LinuxOpensuse Leap+9 | 23/7/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Utilities). Supported versions that are affected are Java SE: 7u221, 8u212, 11.0.3 and 12.0.1; Java SE Embedded: 8u211. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols… | |
| Modificada | Media (4.9) | 2.2% | — | Oracle MysqlCanonical Ubuntu LinuxFedoraproject FedoraRedhat Software Collections+4 | 23/7/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.… | |
| Modificada | Media (4.9) | 2.2% | — | Oracle MysqlFedoraproject FedoraRedhat Software CollectionsRedhat Enterprise Linux+3 | 23/7/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.7.25 and prior and 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.… | |
| Modificada | Media (4.9) | 2.1% | — | Oracle MysqlFedoraproject FedoraRedhat Software CollectionsRedhat Enterprise Linux+3 | 23/7/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Options). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (6.5) | 4.0% | — | Oracle MysqlCanonical Ubuntu LinuxMariadbRedhat Enterprise Linux Desktop+7 | 23/7/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: XML). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL… | |
| Modificada | Media (5.1) | 0.79% | — | Oracle MysqlCanonical Ubuntu LinuxFedoraproject FedoraRedhat Enterprise Linux EUS+3 | 23/7/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where MySQL… | |
| Modificada | Baja (3.1) | 1.6% | — | Oracle MysqlCanonical Ubuntu LinuxFedoraproject FedoraRedhat Software Collections+4 | 23/7/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Compiling). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise… | |
| Modificada | Media (6.5) | 1.9% | — | Freedesktop PopplerDebian LinuxFedoraproject FedoraRedhat Enterprise Linux+3 | 22/7/2019 | 17/6/2026 | The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory chunk on the heap, with a size controlled by an attacker, as demonstrated by pdftocairo. | |
| Modificada | Crítica (9.8) | 6.3% | — | Gnome PangoOracle Sd-wan EdgeFedoraproject FedoraDebian Linux+9 | 19/7/2019 | 17/6/2026 | Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The heap based buffer overflow can be used to get code execution. The component is: function name: pango_log2vis_get_embedding_levels, assignment of nchars and the loop condition. The attack vector is: Bug can be used when application pass… | |
| Modificada | Alta (8.1) | 3.7% | — | Libsdl Simple Directmedia LayerDebian LinuxOpensuse Backports SLEOpensuse Leap+9 | 16/7/2019 | 17/6/2026 | SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in BlitNtoN in video/SDL_blit_N.c when called from SDL_SoftBlit in video/SDL_blit.c. | |
| Modificada | Alta (8.8) | 49% | — | Squid-cache SquidFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+4 | 11/7/2019 | 17/6/2026 | An issue was discovered in Squid 4.0.23 through 4.7. When checking Basic Authentication with HttpHeader::getAuth, Squid uses a global buffer to store the decoded data. Squid does not check that the decoded length isn't greater than the buffer, leading to a heap-based buffer overflow with user controlled data. | |
| Modificada | Alta (7.2) | 24% | — | Redislabs RedisRedhat OpenstackRedhat Enterprise LinuxRedhat Enterprise Linux EUS+5 | 11/7/2019 | 17/6/2026 | A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By corrupting a hyperloglog using the SETRANGE command, an attacker could cause Redis to perform controlled increments of up to 12 bytes past the end of a… | |
| Modificada | Alta (7.2) | 26% | — | Redislabs RedisRedhat OpenstackRedhat Software CollectionsRedhat Enterprise Linux+6 | 11/7/2019 | 17/6/2026 | A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By carefully corrupting a hyperloglog using the SETRANGE command, an attacker could trick Redis interpretation of dense HLL encoding to write up to 3 bytes beyond… | |
| Modificada | Alta (7.8) | 0.43% | — | LibosinfoFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux EUS+2 | 5/7/2019 | 17/6/2026 | libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the command line. |