Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
576 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 1.1% | — | Oracle Database Server | 22/10/2009 | 16/6/2026 | Unspecified vulnerability in the Net Foundation Layer component in Oracle Database 9.2.0.8 and 10.1.0.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. | |
| Modificada | Media (5.5) | 2.2% | — | Oracle Database Server | 22/10/2009 | 16/6/2026 | Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors. | |
| Modificada | Media (5.5) | 2.2% | — | Oracle Database Server | 22/10/2009 | 16/6/2026 | Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity, related to SYS.LTRIC (WMSYS.LTRIC). | |
| Modificada | Media (6.5) | 2.3% | — | Oracle Database Server | 22/10/2009 | 16/6/2026 | Unspecified vulnerability in the Data Mining component in Oracle Database 10.2.0.4 allows remote authenticated users to affect confidentiality, integrity, and availability, related to SYS.DMP_SYS. | |
| Modificada | Media (5.5) | 1.8% | — | Oracle Database Server | 14/7/2009 | 16/6/2026 | Unspecified vulnerability in the Virtual Private Database component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect confidentiality and integrity, related to VPD policies. | |
| Modificada | Media (5) | 12% | 💥 Exploit | Oracle Database Server | 14/7/2009 | 16/6/2026 | Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect availability via unknown vectors, a different vulnerability than CVE-2009-0991. | |
| Modificada | Baja (2.1) | 1.1% | — | Oracle Database Server | 14/7/2009 | 16/6/2026 | Unspecified vulnerability in the Auditing component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect confidentiality via unknown vectors. | |
| Modificada | Media (4.3) | 40% | 💥 Exploit | Oracle Database Server | 14/7/2009 | 16/6/2026 | Unspecified vulnerability in the Secure Enterprise Search component in Oracle Database 10.1.8.3 allows remote attackers to affect integrity via unknown vectors. NOTE: the previous information was obtained from the July 2009 CPU. Oracle has not commented on claims from an established researcher that this is cross-site… | |
| Modificada | Media (5.5) | 1.2% | — | Oracle Database ServerOracle Enterprise Manager | 14/7/2009 | 16/6/2026 | Unspecified vulnerability in the Config Management component in (1) Oracle Database 11.1.0.7 and (2) Oracle Enterprise Manager 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2009-1966. | |
| Modificada | Media (5.5) | 1.2% | — | Oracle Database ServerOracle Enterprise Manager | 14/7/2009 | 16/6/2026 | Unspecified vulnerability in the Config Management component in (1) Oracle Database 11.1.0.7 and (2) Oracle Enterprise Manager 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2009-1967. | |
| Modificada | Alta (7.5) | 8.7% | 💥 Exploit | Oracle Database Server | 14/7/2009 | 16/6/2026 | Unspecified vulnerability in the Network Foundation component in Oracle Database 11.1.0.6 allows remote authenticated users to affect integrity and availability via unknown vectors. | |
| Modificada | Media (5.5) | 1.8% | — | Oracle Database Server | 14/7/2009 | 16/6/2026 | Unspecified vulnerability in the Advanced Replication component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors. | |
| Modificada | Alta (9) | 10% | 💥 Exploit | Oracle Database Server | 14/7/2009 | 16/6/2026 | Unspecified vulnerability in the Network Foundation component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors. | |
| Modificada | Alta (7.5) | 10% | 💥 Exploit | Oracle Database Server | 14/7/2009 | 16/6/2026 | Unspecified vulnerability in the Network Authentication component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. | |
| Modificada | Media (4) | 1.2% | — | Oracle Database Server | 14/7/2009 | 16/6/2026 | Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.05, and 10.2.04 allows remote authenticated users to affect integrity via unknown vectors. | |
| Modificada | Media (5.5) | 1.8% | — | Oracle Database Server | 14/7/2009 | 16/6/2026 | Unspecified vulnerability in the Upgrade component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors. | |
| Modificada | Media (4) | 2.3% | — | Oracle Database Server | 15/4/2009 | 16/6/2026 | Unspecified vulnerability in the Database Vault component in Oracle Database 11.1.0.6 allows remote authenticated users to affect confidentiality, related to DBMS_SYS_SQL. | |
| Modificada | Media (6.5) | 1.4% | — | Oracle Database Server | 15/4/2009 | 16/6/2026 | Unspecified vulnerability in the Workspace Manager component in Oracle Database 11.1.0.6, 11.1.0.7, 10.2.0.3, 10.2.0.4, 10.1.0.5, 9.2.0.8, and 9.2.0.8DV allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors. | |
| Modificada | Media (5.1) | 2.2% | 💥 Exploit | Oracle Database Server | 5/2/2009 | 16/6/2026 | Oracle Database Server 10.1, 10.2, and 11g grants directory WRITE permissions for arbitrary pathnames that are aliased in a CREATE OR REPLACE DIRECTORY statement, which allows remote authenticated users with CREATE ANY DIRECTORY privileges to gain SYSDBA privileges by aliasing the pathname of the password directory,… | |
| Modificada | Media (6.5) | 1.4% | — | Oracle Database 9IOracle Database Server | 15/7/2008 | 16/6/2026 | Unspecified vulnerability in the Oracle Database Vault component in Oracle Database 9.2.0.8DV, 10.2.0.3, and 11.1.0.6 has unknown impact and remote authenticated attack vectors. | |
| Modificada | Media (4) | 1.3% | — | Oracle Authentication ComponentOracle Database Server | 15/7/2008 | 16/6/2026 | Unspecified vulnerability in the Authentication component in Oracle Database 11.1.0.6 has unknown impact and remote authenticated attack vectors, a different vulnerability than CVE-2008-2604. | |
| Modificada | Media (6.5) | 1.4% | — | Oracle Database ServerOracle DatabaseOracle Spatial Component | 15/7/2008 | 16/6/2026 | Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5, 10.2.0.3, and 11.1.0.6 has unknown impact and remote authenticated attack vectors related to MDSYS.SDO_TOPO_MAP. | |
| Modificada | Media (6.5) | 1.3% | — | Oracle Database SchedulerOracle Database Server | 15/7/2008 | 16/6/2026 | Unspecified vulnerability in the Database Scheduler component in Oracle Database 10.2.0.4 and 11.1.0.6 has unknown impact and local attack vectors. NOTE: the previous information was obtained from the Oracle July 2008 CPU. Oracle has not commented on reliable researcher claims that this is an untrusted search path… | |
| Modificada | Baja (3.5) | 1.1% | — | Oracle Database ServerOracle Enterprise Manager 10GOracle Instance Management Component | 15/7/2008 | 16/6/2026 | Unspecified vulnerability in the Instance Management component in Oracle Database 10.1.0.5 and Enterprise Manager 10.1.0.6 has unknown impact and remote authenticated attack vectors. | |
| Modificada | Media (6.5) | 3.4% | — | Oracle Advanced Queuing ComponentOracle Database 9IOracle Database Server | 15/7/2008 | 16/6/2026 | Unspecified vulnerability in the Advanced Queuing component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.6 has unknown impact and remote authenticated attack vectors related to SYS.DBMS_AQELM. NOTE: the previous information was obtained from the Oracle July 2008 CPU. Oracle has not commented… |