Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
482 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 3.3% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux Desktop+25 | 19/10/2017 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Media (5.3) | 3.1% | — | Oracle JDKOracle JREDebian LinuxRedhat Satellite+25 | 19/10/2017 | 17/6/2026 | Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Crítica (9.6) | 3.0% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux Desktop+25 | 19/10/2017 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Baja (3.1) | 2.4% | — | Oracle JDKOracle JREOracle JrockitDebian Linux+26 | 19/10/2017 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit: R28.3.15. Difficult to exploit vulnerability allows unauthenticated attacker with network… | |
| Modificada | Media (4.9) | 1.9% | — | Oracle MysqlMariadbNetapp Active IQ Unified ManagerNetapp Oncommand Balance+5 | 19/10/2017 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: InnoDB). Supported versions that are affected are 5.7.19 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Alta (7.1) | 8.8% | 💥 Exploit | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux Desktop+22 | 19/10/2017 | 17/6/2026 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 8u144 and 9. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human… | |
| Modificada | Media (4) | 2.2% | — | Oracle JDKOracle JREOracle JrockitDebian Linux+26 | 19/10/2017 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit: R28.3.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access… | |
| Modificada | Media (6.1) | 1.5% | — | Oracle JDKOracle JRENetapp Active IQ Unified ManagerNetapp Cloud Backup+17 | 19/10/2017 | 17/6/2026 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Javadoc). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Java SE. Successful attacks require human… | |
| Modificada | Media (4.4) | 2.4% | — | Oracle MysqlNetapp Active IQ Unified ManagerNetapp Oncommand BalanceNetapp Oncommand Insight+5 | 19/10/2017 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: InnoDB). Supported versions that are affected are 5.6.37 and earlier and 5.7.19 and earlier. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.… | |
| Modificada | Crítica (9.6) | 3.1% | — | Oracle JDKOracle JREDebian LinuxRedhat Satellite+25 | 19/10/2017 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise… | |
| Modificada | Media (5.3) | 3.3% | — | Oracle JDKOracle JREOracle JrockitDebian Linux+26 | 19/10/2017 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit: R28.3.15. Easily exploitable vulnerability allows unauthenticated attacker with network… | |
| Modificada | Media (6.8) | 2.6% | — | Oracle JDKOracle JREDebian LinuxRedhat Enterprise Linux Desktop+24 | 19/10/2017 | 17/6/2026 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Smart Card IO). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks… | |
| Modificada | Media (4.1) | 0.70% | — | Oracle MysqlDebian LinuxRedhat OpenstackRedhat Enterprise Linux Desktop+13 | 19/10/2017 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.5.57 and earlier, 5.6.37 and earlier and 5.7.19 and earlier. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server… | |
| Modificada | Crítica (9.8) | 18% | — | HP LoadrunnerHP Performance Center | 11/10/2017 | 17/6/2026 | HPE LoadRunner before 12.53 Patch 4 and HPE Performance Center before 12.53 Patch 4 allow remote attackers to execute arbitrary code via unspecified vectors. At least in LoadRunner, this is a libxdrutil.dll mxdr_string heap-based buffer overflow. | |
| Modificada | Media (4.9) | 2.4% | — | Solarwinds Network Performance Monitor | 3/10/2017 | 17/6/2026 | The 'Upload logo from external path' function of SolarWinds Network Performance Monitor version 12.0.15300.90 allows remote attackers to cause a denial of service (permanent display of a "Cannot exit above the top directory" error message throughout the entire web application) via a ".." in the path field. In other… | |
| Modificada | Media (4.8) | 2.8% | — | Solarwinds Network Performance Monitor | 3/10/2017 | 17/6/2026 | Persistent cross-site scripting (XSS) in the Add Node function of SolarWinds Network Performance Monitor version 12.0.15300.90 allows remote attackers to introduce arbitrary JavaScript into various vulnerable parameters. | |
| Modificada | Crítica (9.8) | 7.0% | — | HP Application Performance Management | 30/9/2017 | 17/6/2026 | A potential security vulnerability has been identified in HPE Application Performance Management (BSM) Platform versions 9.26, 9.30, 9.40. The vulnerability could be remotely exploited to allow code execution. | |
| Modificada | Media (6.5) | 2.7% | — | HP BSM Platform Application Performance Management System Health | 30/9/2017 | 17/6/2026 | An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows remote users to traverse directory leading to disclosure of information. | |
| Modificada | Media (6.5) | 2.0% | — | HP BSM Platform Application Performance Management System Health | 30/9/2017 | 17/6/2026 | An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows remote users to delete arbitrary files via servlet directory traversal. | |
| Modificada | Crítica (9.8) | 6.1% | — | HP BSM Platform Application Performance Management System Health | 30/9/2017 | 17/6/2026 | An authentication vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows remote users to bypass authentication. | |
| Modificada | Alta (8.8) | 3.4% | — | HP BSM Platform Application Performance Management System Health | 30/9/2017 | 17/6/2026 | A directory traversal vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows users to upload unrestricted files. | |
| Analizada | Alta (8.1) | 99% | ⚠ Explotación activa💥 Exploit | Apache StrutsCisco Digital Media ManagerCisco Hosted Collaboration SolutionCisco Media Experience Engine+3 | 15/9/2017 | 17/6/2026 | The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads. | |
| Modificada | Media (6.5) | 2.9% | — | Oracle JDKOracle JREOracle JrockitDebian Linux+23 | 8/8/2017 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JAX-WS). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via… | |
| Modificada | Media (6.8) | 2.6% | — | Oracle JDKOracle JREOracle JrockitPhoenixcontact FL Mguard DM+23 | 8/8/2017 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via… | |
| Modificada | Baja (3.1) | 2.2% | — | Oracle JDKOracle JREDebian LinuxNetapp Active IQ Unified Manager+21 | 8/8/2017 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… |