Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1243 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.5) | 0.73% | — | Oracle Database | 21/7/2021 | 17/6/2026 | Vulnerability in the Oracle Database - Enterprise Edition Data Redaction component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to… | |
| Modificada | Media (4.9) | 0.90% | — | Oracle XML Database | 21/7/2021 | 17/6/2026 | Vulnerability in the Oracle XML DB component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows high privileged attacker having Alter User privilege with network access via Oracle Net to compromise Oracle XML DB. Successful attacks of… | |
| Modificada | Alta (7.2) | 1.0% | — | Oracle XML Database | 21/7/2021 | 17/6/2026 | Vulnerability in the Oracle XML DB component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows high privileged attacker having Create Any Procedure, Create Public Synonym privilege with network access via Oracle Net to compromise… | |
| Modificada | Baja (2.7) | 0.76% | — | Oracle Database Vault | 21/7/2021 | 17/6/2026 | Vulnerability in the Database Vault component of Oracle Database Server. Supported versions that are affected are 12.2.0.1 and 19c. Easily exploitable vulnerability allows high privileged attacker having DBA privilege with network access via Oracle Net to compromise Database Vault. Successful attacks of this… | |
| Modificada | Media (6.5) | 7.0% | 💥 PoC | Golang GOFedoraproject FedoraNetapp Cloud Insights TelegrafNetapp Storagegrid+2 | 15/7/2021 | 17/6/2026 | The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange, allowing a malicious TLS server to cause a TLS client to panic. | |
| Modificada | Media (5.5) | 2.6% | — | Apache ANTOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Banking Trade Finance+32 | 14/7/2021 | 25/8/2026 | When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR… | |
| Modificada | Media (5.5) | 2.5% | — | Apache ANTOracle Agile Product Lifecycle ManagementOracle Banking Trade FinanceOracle Banking Treasury Management+28 | 14/7/2021 | 25/8/2026 | When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected. | |
| Modificada | Media (4.8) | 0.50% | — | Mcafee Database Security | 3/6/2021 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows an administrator to embed JavaScript code when configuring the name of a database to be monitored. This would be triggered when any authorized user logs into the… | |
| Modificada | Media (5.5) | 0.64% | — | Mcafee Database Security | 3/6/2021 | 17/6/2026 | Incorrect access to deleted scripts vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote authenticated attacker to gain access to signed SQL scripts which have been marked as deleted or expired within the administrative console. This access was only available through the REST API. | |
| Modificada | Media (4.5) | 0.20% | — | Mcafee Database Security | 2/6/2021 | 17/6/2026 | Cleartext Transmission of Sensitive Information vulnerability in the administrator interface of McAfee Database Security (DBSec) prior to 4.8.2 allows an administrator to view the unencrypted password of the McAfee Insights Server used to pass data to the Insights Server. This user is restricted to only have access to… | |
| Modificada | Alta (8) | 1.9% | — | Mcafee Database Security | 2/6/2021 | 17/6/2026 | Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote authenticated attacker to create a reverse shell with administrator privileges on the DBSec server via carefully constructed Java serialized object sent to the DBSec server. | |
| Modificada | Alta (8.8) | 2.2% | — | Mcafee Database Security | 2/6/2021 | 17/6/2026 | Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote unauthenticated attacker to create a reverse shell with administrator privileges on the DBSec server via carefully constructed Java serialized object sent to the DBSec server. | |
| Modificada | Media (5.4) | 0.70% | — | Deliciousbrains Database Backup | 1/6/2021 | 17/6/2026 | The Database Backup for WordPress plugin before 2.4 did not escape the backup_recipient POST parameter in before output it back in the attribute of an HTML tag, leading to a Stored Cross-Site Scripting issue. | |
| Modificada | Media (4.3) | 0.72% | — | Mendix Database Replication | 12/5/2021 | 17/6/2026 | Uploading a table mapping using a manipulated XML file results in an exception that could expose information about the application-server and the used XML-framework on the Mendix Database Replication Module (All versions prior to v7.0.1). | |
| Modificada | Baja (2.7) | 0.71% | — | Oracle Database | 22/4/2021 | 17/6/2026 | Vulnerability in the Oracle Database - Enterprise Edition Unified Audit component of Oracle Database Server. Supported versions that are affected are 18c and 19c. Easily exploitable vulnerability allows high privileged attacker having Create Audit Policy privilege with network access via Oracle Net to compromise… | |
| Modificada | Media (5.3) | 0.79% | — | Oracle Database Server | 22/4/2021 | 17/6/2026 | Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Java VM. Successful attacks of… | |
| Modificada | Baja (2.3) | 0.60% | — | Oracle Database | 22/4/2021 | 17/6/2026 | Vulnerability in the Oracle Database - Enterprise Edition component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows high privileged attacker having RMAN executable privilege with logon to the infrastructure where Oracle… | |
| Modificada | Baja (2.7) | 1.7% | 💥 PoC | Oracle Database Server | 22/4/2021 | 17/6/2026 | Vulnerability in the Database Vault component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows high privileged attacker having Create Any View, Select Any View privilege with network access via Oracle Net to compromise Database… | |
| Modificada | Media (4.1) | 1.4% | 💥 PoC | Oracle Database Server | 22/4/2021 | 17/6/2026 | Vulnerability in the Recovery component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows high privileged attacker having DBA Level Account privilege with network access via Oracle Net to compromise Recovery. While the… | |
| Modificada | Media (6.5) | 0.74% | — | Mongodb Database ToolsMongodb Mongomirror | 12/4/2021 | 17/6/2026 | Usage of specific command line parameter in MongoDB Tools which was originally intended to just skip hostname checks, may result in MongoDB skipping all certificate validation. This may result in accepting invalid certificates.This issue affects: MongoDB Inc. MongoDB Database Tools 3.6 versions later than 3.6.5; 3.6… | |
| Modificada | Alta (8.1) | 3.2% | 💥 Exploit | Database-backups Project Database-backups | 5/4/2021 | 17/6/2026 | The Database Backups WordPress plugin through 1.2.2.6 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as generate backups of the database, change the plugin's settings and delete backups. | |
| Modificada | Media (5.9) | 4.9% | — | NettyDebian LinuxNetapp Oncommand API ServicesNetapp Oncommand Workflow Automation+14 | 30/3/2021 | 17/6/2026 | Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerability that enables request smuggling. The content-length header is not… | |
| Modificada | Media (5.5) | 0.50% | — | SqliteOracle Communications Network Charging AND ControlEnterprise Manager FOR Oracle DatabaseOracle JD Edwards Enterpriseone Tools+3 | 23/3/2021 | 17/6/2026 | A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code execution by triggering a use-after-free. The highest threat from this vulnerability is to system… | |
| Modificada | Alta (7.8) | 1.2% | — | Ciphercoin Contact Form 7 Database Addon | 18/3/2021 | 17/6/2026 | Unvalidated input in the Contact Form 7 Database Addon plugin, versions before 1.2.5.6, was prone to a vulnerability that lets remote attackers inject arbitrary formulas into CSV files. | |
| Modificada | Alta (7.2) | 1.2% | — | Sigmaplugin Advanced Database Cleaner | 18/3/2021 | 17/6/2026 | Unvaludated input in the Advanced Database Cleaner plugin, versions before 3.0.2, lead to SQL injection allowing high privilege users (admin+) to perform SQL attacks. |