Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

787 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.7)1.2%—Oracle MysqlSuse Linux Enterprise DebuginfoOpensuse LeapOpensuse+1321/4/201617/6/2026
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier allows local users to affect integrity and availability via vectors related to Federated.
ModificadaAlta (8.4)0.56%—QemuCanonical Ubuntu LinuxDebian LinuxRedhat Openstack+712/4/201617/6/2026
The net_checksum_calculate function in net/checksum.c in QEMU allows local guest OS users to cause a denial of service (out-of-bounds heap read and crash) via the payload length in a crafted packet.
AnalizadaAlta (8.8)48%⚠ Explotación activaDebian LinuxCanonical Ubuntu LinuxGoogle ChromeSuse Package HUB+629/3/201617/6/2026
The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted JavaScript code.
ModificadaMedia (6.5)4.6%—MIT Kerberos 5Opensuse LeapOpensuseDebian Linux+713/2/201617/6/2026
Multiple memory leaks in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 allow remote authenticated users to cause a denial of service (memory consumption) via a request specifying a NULL principal name.
ModificadaMedia (5.3)3.7%—MIT Kerberos 5Oracle LinuxOracle SolarisDebian Linux+813/2/201617/6/2026
The xdr_nullstring function in lib/kadm5/kadm_rpc_xdr.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 does not verify whether '\0' characters exist as expected, which allows remote authenticated users to obtain sensitive information or cause a denial of service (out-of-bounds read) via…
ModificadaAlta (8.6)6.6%—QemuCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+712/1/201617/6/2026
The VNC websocket frame decoder in QEMU allows remote attackers to cause a denial of service (memory and CPU consumption) via a large (1) websocket payload or (2) HTTP headers section.
ModificadaCrítica (9)7.7%—QemuRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUSRedhat Enterprise Linux Server+58/1/201617/6/2026
Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larger MTU, allows remote attackers to cause a denial of service (guest OS crash) or execute arbitrary code via a large packet.
ModificadaAlta (7.5)5.3%—OpenldapOracle LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+57/12/201517/6/2026
The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors.
ModificadaCrítica (9.8)6.4%—PcreOracle LinuxFedoraproject FedoraRedhat Enterprise Linux Desktop+62/12/201517/6/2026
The pcre_compile function in pcre_compile.c in PCRE before 8.38 mishandles certain [: nesting, which allows remote attackers to cause a denial of service (CPU consumption) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.
ModificadaAlta (7.5)10%—LibpngFedoraproject FedoraOpensuse LeapOpensuse+1613/11/201517/6/2026
Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x before 1.6.19 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other…
ModificadaBaja (3.5)3.5%—Oracle MysqlOracle LinuxOracle SolarisOpensuse Leap+1122/10/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via vectors related to Server : DML, a different vulnerability than CVE-2015-4858.
AnalizadaMedia (5.3)14%⚠ Explotación activaOracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux Desktop+1722/10/201517/6/2026
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.
ModificadaMedia (4.6)4.2%—Oracle LinuxOracle SolarisOracle MysqlDebian Linux+921/10/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.44 and earlier, and 5.6.25 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to DML.
ModificadaMedia (4)30%💥 ExploitOracle LinuxOracle SolarisOpensuse LeapOpensuse+1121/10/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Parser.
ModificadaBaja (3.5)2.4%—Oracle SolarisOracle MysqlCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+621/10/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Server : Security : Privileges.
ModificadaBaja (3.5)3.5%—Oracle LinuxOracle SolarisOpensuse LeapOpensuse+1121/10/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB.
ModificadaMedia (4)3.9%—Oracle LinuxOracle SolarisOpensuse LeapOpensuse+1121/10/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via vectors related to DML, a different vulnerability than CVE-2015-4913.
ModificadaBaja (2.8)4.0%—Oracle LinuxOracle SolarisOpensuse LeapOpensuse+1121/10/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : SP.
ModificadaMedia (4)3.0%—Oracle SolarisOracle MysqlMariadbCanonical Ubuntu Linux+1321/10/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Server : Security : Privileges.
ModificadaMedia (4)3.0%—Oracle MysqlOpensuse LeapOpensuseOracle Solaris+1021/10/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Types.
ModificadaMedia (4)7.5%—Oracle MysqlOracle LinuxOracle SolarisMariadb+921/10/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.44 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB.
ModificadaMedia (4)3.7%—Oracle MysqlOracle LinuxOracle SolarisOpensuse Leap+1121/10/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via vectors related to Server : DDL.
ModificadaMedia (4)4.2%—Opensuse LeapOpensuseOracle LinuxOracle Solaris+1121/10/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Partition, a different vulnerability than CVE-2015-4792.
ModificadaBaja (1.7)3.9%—Opensuse LeapOpensuseRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+1121/10/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Partition, a different vulnerability than CVE-2015-4802.
AnalizadaAlta (7.8)65%⚠ Explotación activa💥 ExploitAdobe Flash PlayerOpensuse EvergreenOpensuseSuse Linux Enterprise Desktop+615/10/201517/6/2026
Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in the wild in October 2015.
Orbitaley — Vulnerabilidades