Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

478 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.6%—Oracle Enterprise Manager Grid Control21/1/201617/6/2026
Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 11.1.0.1, 12.1.0.4, and 12.1.0.5 allows remote attackers to affect confidentiality via unknown vectors related to Agent Next Gen.
ModificadaMedia (6.5)1.6%—Oracle Enterprise Manager Grid Control21/1/201617/6/2026
Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.4 and 12.1.0.5 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Loader Service.
ModificadaMedia (4)1.4%—Oracle Enterprise Manager Grid Control21/1/201617/6/2026
Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 11.1.0.1, 11.2.0.4, 12.1.0.4, and 12.1.0.5 allows remote authenticated users to affect confidentiality via unknown vectors related to UI Framework.
ModificadaMedia (6.8)1.8%—Oracle Enterprise Manager Grid Control21/1/201617/6/2026
Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 11.1.0.1, 12.1.0.4, and 12.1.0.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to UI Framework.
ModificadaMedia (4.6)0.40%—Oracle Enterprise Manager Grid Control21/1/201617/6/2026
Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 11.1.0.1 and 11.2.0.4 allows local users to affect confidentiality, integrity, and availability via vectors related to Agent Next Gen.
ModificadaMedia (4.3)1.6%—Oracle Enterprise Manager Grid Control21/1/201617/6/2026
Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.4 allows remote attackers to affect confidentiality via vectors related to Agent Next Gen.
ModificadaAlta (7.5)2.9%—F5 Big-iq Application Delivery ControllerF5 Big-ip Local Traffic ManagerF5 Big-ip Access Policy ManagerF5 Big-ip Edge Gateway+1420/1/201617/6/2026
Memory leak in the last hop kernel module in F5 BIG-IP LTM, GTM, and Link Controller 10.1.x, 10.2.x before 10.2.4 HF13, 11.x before 11.2.1 HF15, 11.3.x, 11.4.x, 11.5.x before 11.5.3 HF2, and 11.6.x before HF6, BIG-IP AAM 11.4.x, 11.5.x before 11.5.3 HF2 and 11.6.0 before HF6, BIG-IP AFM and PEM 11.3.x, 11.4.x, 11.5.x…
ModificadaAlta (9)69%💥 ExploitF5 Big-iq SecurityF5 Big-ip Application Acceleration ManagerF5 Big-ip WAN Optimization ManagerF5 Big-iq ADC+147/12/201517/6/2026
The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6, BIG-IP AAM 11.4.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6, BIG-IP Edge Gateway, WebAccelerator, and WOM 11.3.0, BIG-IP GTM 11.3.0 before 11.6.0 HF6, BIG-IP PSM 11.3.0…
ModificadaMedia (5)4.8%—Opensuse LeapOpensuseBouncycastle Bouncy Castle Crypto PackageOracle Application Testing Suite+39/11/201517/6/2026
The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obtain private keys via a series of crafted elliptic curve Diffie Hellman (ECDH) key exchanges, aka an "invalid curve attack."
ModificadaAlta (9)3.9%—F5 Big-iq DeviceF5 Big-ip Policy Enforcement ManagerF5 Big-ip Global Traffic ManagerF5 Big-ip Analytics+146/11/201517/6/2026
The datastor kernel module in F5 BIG-IP Analytics, APM, ASM, Link Controller, and LTM 11.1.0 before 12.0.0, BIG-IP AAM 11.4.0 before 12.0.0, BIG-IP AFM, PEM 11.3.0 before 12.0.0, BIG-IP Edge Gateway, WebAccelerator, and WOM 11.1.0 through 11.3.0, BIG-IP GTM 11.1.0 through 11.6.0, BIG-IP PSM 11.1.0 through 11.4.1,…
ModificadaMedia (5)1.9%—Oracle Enterprise Manager Grid Control21/10/201517/6/2026
Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.4 and 12.1.0.5 allows remote attackers to affect availability via unknown vectors related to Agent Next Gen.
ModificadaMedia (4.1)0.34%—Oracle Enterprise Manager Grid Control21/10/201517/6/2026
Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.4 and 12.1.0.5 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Agent Next Gen.
ModificadaMedia (5.8)1.7%—Oracle Enterprise Manager Grid Control21/10/201517/6/2026
Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.4 and 12.1.0.5 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Agent Next Gen.
ModificadaBaja (3.6)1.2%—Oracle Enterprise Manager Grid Control21/10/201517/6/2026
Unspecified vulnerability in the Enterprise Manager Ops Center component in Oracle Enterprise Manager Grid Control 12.1.0.1 and 12.2.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Ops Center.
ModificadaMedia (4)6.8%💥 ExploitF5 Enterprise ManagerF5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+1017/9/201517/6/2026
Directory traversal vulnerability in the configuration utility in F5 BIG-IP before 12.0.0 and Enterprise Manager 3.0.0 through 3.1.1 allows remote authenticated users to access arbitrary files in the web root via unspecified vectors.
ModificadaMedia (4)1.7%—HP Virtual Connect Enterprise Manager SDK27/8/201517/6/2026
HP Virtual Connect Enterprise Manager (VCEM) SDK before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote authenticated users to obtain sensitive information via unspecified vectors.
ModificadaAlta (7.5)3.9%—HP Virtual Connect Enterprise Manager SDK27/8/201517/6/2026
HP Virtual Connect Enterprise Manager (VCEM) SDK before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote attackers to obtain sensitive information or modify data via unspecified vectors.
ModificadaMedia (5)2.8%—Oracle Enterprise Manager Database ControlOracle Enterprise Manager Grid Control16/7/201517/6/2026
Unspecified vulnerability in the Enterprise Manager for Oracle Database component in Oracle Enterprise Manager Grid Control EM Base Platform 11.1.0.1, and EM DB Control 11.2.0.3 and 11.2.0.4, allows remote attackers to affect confidentiality via vectors related to RAC Management.
ModificadaMedia (5.5)1.7%—Oracle Enterprise Manager Plugin FOR Database ControlOracle Enterprise Manager Database ControlOracle Enterprise Manager Grid Control16/7/201517/6/2026
Unspecified vulnerability in the Enterprise Manager for Oracle Database component in Oracle Enterprise Manager Grid Control EM Base Platform 11.1.0.1; EM Plugin for DB 12.1.0.5, 12.1.0.6, 12.1.0.7; and EM DB Control 11.1.0.7, 11.2.0.3, and 11.2.0.4 allows remote authenticated users to affect confidentiality and…
ModificadaMedia (4.3)2.0%—Oracle Enterprise Manager Database ControlOracle Enterprise Manager Grid ControlOracle Enterprise Manager Plugin FOR Database Control16/7/201517/6/2026
Unspecified vulnerability in the Enterprise Manager for Oracle Database component in Oracle Enterprise Manager Grid Control EM Base Platform: 11.1.0.1; EM Plugin for DB: 12.1.0.5, 12.1.0.6, 12.1.0.7; EM DB Control: 11.1.0.7, 11.2.0.3, and 11.2.0.4 allows remote attackers to affect integrity via unknown vectors related…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitAdobe Flash PlayerOpensuse EvergreenOpensuseSuse Linux Enterprise Desktop+1123/6/201517/6/2026
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in June 2015.
ModificadaMedia (6.4)8.3%—Haxx CurlHaxx LibcurlHP System Management HomepageOracle Enterprise Manager OPS Center+122/6/201517/6/2026
The smb_request_state function in cURL and libcurl 7.40.0 through 7.42.1 allows remote SMB servers to obtain sensitive information from memory or cause a denial of service (out-of-bounds read and crash) via crafted length and offset values.
ModificadaAlta (7.8)9.7%—Ipsec-toolsCanonical Ubuntu LinuxFedoraproject FedoraF5 Big-ip Application Acceleration Manager+2129/5/201517/6/2026
racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a series of crafted UDP requests.
ModificadaMedia (5)7.3%—Oracle Enterprise Manager OPS CenterHaxx CurlHaxx LibcurlCanonical Ubuntu Linux+21/5/201517/6/2026
The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow remote proxy servers to obtain sensitive information by reading the header contents.
ModificadaMedia (4.3)1.4%—Oracle Enterprise Manager Grid Control16/4/201517/6/2026
Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control MOS 12.1.0.5 and 12.1.0.6 allows remote attackers to affect integrity via unknown vectors related to My Oracle Support Plugin.