Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1243 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.69%—Wpseeds WP Database Backup12/8/201917/6/2026
The wp-database-backup plugin before 4.3.1 for WordPress has CSRF.
ModificadaMedia (6.1)0.92%—Wpseeds WP Database Backup12/8/201917/6/2026
The wp-database-backup plugin before 4.3.1 for WordPress has XSS.
ModificadaAlta (8.8)0.68%—Wpseeds WP Database Backup12/8/201917/6/2026
The wp-database-backup plugin before 4.3.3 for WordPress has CSRF.
ModificadaMedia (6.1)0.92%—Wpseeds WP Database Backup12/8/201917/6/2026
The wp-database-backup plugin before 4.3.3 for WordPress has XSS.
ModificadaAlta (7.5)1.2%—Oracle Database Server23/7/201917/6/2026
Vulnerability in the Oracle ODBC Driver component of Oracle Database Server<span class=font-red><b> ***PRIVILEGE CANNOT BE NONE FOR AUTHENTICATED ATTACKS***</b></span>. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Difficult to exploit vulnerability allows low privileged attacker…
ModificadaAlta (7.6)1.1%—Oracle Database Server23/7/201917/6/2026
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows high privileged attacker having Create Any Index privilege with network access via OracleNet to compromise Core RDBMS. While the…
ModificadaMedia (4.6)0.89%—Oracle Database Server23/7/201917/6/2026
Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via OracleNet to compromise Oracle Text. Successful…
ModificadaMedia (6.8)1.1%—Oracle Database Server23/7/201917/6/2026
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to…
ModificadaMedia (4)0.41%—Oracle Database Server23/7/201917/6/2026
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Difficult to exploit vulnerability allows high privileged attacker having Local Logon privilege with logon to the infrastructure where Core RDBMS executes to compromise Core…
ModificadaMedia (5.4)0.74%—Oracle Database Server23/7/201917/6/2026
Vulnerability in the Application Express component of Oracle Database Server. Supported versions that are affected are 5.1 and 18.2. Easily exploitable vulnerability allows low privileged attacker having Valid Account privilege with network access via HTTP to compromise Application Express. Successful attacks require…
ModificadaAlta (7.5)2.4%—Davegamble CjsonOracle Timesten In-memory Database19/7/201917/6/2026
DaveGamble/cJSON cJSON 1.7.8 is affected by: Improper Check for Unusual or Exceptional Conditions. The impact is: Null dereference, so attack can cause denial of service. The component is: cJSON_GetObjectItemCaseSensitive() function. The attack vector is: crafted json file. The fixed version is: 1.7.9 and later.
ModificadaMedia (5.5)2.6%—Uclouvain OpenjpegOpensuse LeapDebian LinuxOracle Database Server+126/6/201917/6/2026
In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. This issue is similar to CVE-2018-6616.
ModificadaMedia (5.9)9.7%—Apache ActivemqApache DrillApache ZookeeperDebian Linux+623/5/201917/6/2026
An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. DigestAuthenticationProvider overloads the Id…
ModificadaCrítica (9.8)2.6%—Davegamble CjsonOracle Timesten In-memory Database9/5/201917/6/2026
cJSON before 1.7.11 allows out-of-bounds access, related to multiline comments.
ModificadaCrítica (9.8)2.5%—Davegamble CjsonOracle Timesten In-memory Database9/5/201917/6/2026
cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal.
ModificadaAlta (8.2)0.42%—Oracle Database23/4/201917/6/2026
Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows high privileged attacker having Grid Infrastructure User privilege with logon to the infrastructure where Portable…
ModificadaMedia (5.3)1.2%—Oracle Database Server23/4/201917/6/2026
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.2.0.1 and 18c. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Core RDBMS. Successful attacks of this vulnerability can result in…
ModificadaMedia (6.6)1.1%—Oracle Database Server23/4/201917/6/2026
Vulnerability in the RDBMS DataPump component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Difficult to exploit vulnerability allows high privileged attacker having DBA role privilege with network access via Oracle Net to compromise RDBMS DataPump.…
ModificadaAlta (7.5)1.2%—Oracle Database Server23/4/201917/6/2026
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to…
ModificadaCrítica (9.1)1.7%—Oracle Database Server23/4/201917/6/2026
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.2.0.1 and 18c. Easily exploitable vulnerability allows high privileged attacker having DBFS_ROLE privilege with network access via Oracle Net to compromise Core RDBMS. While the vulnerability is in Core…
ModificadaAlta (8.2)0.42%—Oracle Database Server23/4/201917/6/2026
Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows high privileged attacker having Grid Infrastructure User privilege with logon to the infrastructure where Portable…
ModificadaMedia (6.5)1.5%—Jenkins Audit TO Database4/4/201917/6/2026
A missing permission check in Jenkins Audit to Database Plugin in the DbAuditPublisherDescriptorImpl#doTestJdbcConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.
ModificadaMedia (6.5)1.3%—Jenkins Audit TO Database4/4/201917/6/2026
A cross-site request forgery vulnerability in Jenkins Audit to Database Plugin in the DbAuditPublisherDescriptorImpl#doTestJdbcConnection form validation method allows attackers to initiate a connection to an attacker-specified server.
ModificadaAlta (8.8)1.3%—Jenkins Audit TO Database4/4/201917/6/2026
Jenkins Audit to Database Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
ModificadaMedia (6.8)0.33%—Mcafee Database Security12/3/201917/6/2026
Data Leakage Attacks vulnerability in the web interface in McAfee Database Security prior to the 4.6.6 March 2019 update allows local users to expose passwords via incorrectly auto completing password fields in the admin browser login screen.
Orbitaley — Vulnerabilidades