Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
591 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4) | 1.4% | — | Oracle Enterprise Manager Grid Control | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 11.1.0.1, 11.2.0.4, 12.1.0.4, and 12.1.0.5 allows remote authenticated users to affect confidentiality via unknown vectors related to UI Framework. | |
| Modificada | Media (6.8) | 1.8% | — | Oracle Enterprise Manager Grid Control | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 11.1.0.1, 12.1.0.4, and 12.1.0.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to UI Framework. | |
| Modificada | Media (4.6) | 0.40% | — | Oracle Enterprise Manager Grid Control | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 11.1.0.1 and 11.2.0.4 allows local users to affect confidentiality, integrity, and availability via vectors related to Agent Next Gen. | |
| Modificada | Media (4.3) | 1.6% | — | Oracle Enterprise Manager Grid Control | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.4 allows remote attackers to affect confidentiality via vectors related to Agent Next Gen. | |
| Modificada | Alta (7.5) | 2.9% | — | F5 Big-iq Application Delivery ControllerF5 Big-ip Local Traffic ManagerF5 Big-ip Access Policy ManagerF5 Big-ip Edge Gateway+14 | 20/1/2016 | 17/6/2026 | Memory leak in the last hop kernel module in F5 BIG-IP LTM, GTM, and Link Controller 10.1.x, 10.2.x before 10.2.4 HF13, 11.x before 11.2.1 HF15, 11.3.x, 11.4.x, 11.5.x before 11.5.3 HF2, and 11.6.x before HF6, BIG-IP AAM 11.4.x, 11.5.x before 11.5.3 HF2 and 11.6.0 before HF6, BIG-IP AFM and PEM 11.3.x, 11.4.x, 11.5.x… | |
| Modificada | Alta (9) | 69% | 💥 Exploit | F5 Big-iq SecurityF5 Big-ip Application Acceleration ManagerF5 Big-ip WAN Optimization ManagerF5 Big-iq ADC+14 | 7/12/2015 | 17/6/2026 | The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6, BIG-IP AAM 11.4.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6, BIG-IP Edge Gateway, WebAccelerator, and WOM 11.3.0, BIG-IP GTM 11.3.0 before 11.6.0 HF6, BIG-IP PSM 11.3.0… | |
| Modificada | Media (5) | 4.8% | — | Opensuse LeapOpensuseBouncycastle Bouncy Castle Crypto PackageOracle Application Testing Suite+3 | 9/11/2015 | 17/6/2026 | The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obtain private keys via a series of crafted elliptic curve Diffie Hellman (ECDH) key exchanges, aka an "invalid curve attack." | |
| Modificada | Alta (9) | 3.9% | — | F5 Big-iq DeviceF5 Big-ip Policy Enforcement ManagerF5 Big-ip Global Traffic ManagerF5 Big-ip Analytics+14 | 6/11/2015 | 17/6/2026 | The datastor kernel module in F5 BIG-IP Analytics, APM, ASM, Link Controller, and LTM 11.1.0 before 12.0.0, BIG-IP AAM 11.4.0 before 12.0.0, BIG-IP AFM, PEM 11.3.0 before 12.0.0, BIG-IP Edge Gateway, WebAccelerator, and WOM 11.1.0 through 11.3.0, BIG-IP GTM 11.1.0 through 11.6.0, BIG-IP PSM 11.1.0 through 11.4.1,… | |
| Modificada | Media (5) | 1.9% | — | Oracle Enterprise Manager Grid Control | 21/10/2015 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.4 and 12.1.0.5 allows remote attackers to affect availability via unknown vectors related to Agent Next Gen. | |
| Modificada | Media (4.1) | 0.34% | — | Oracle Enterprise Manager Grid Control | 21/10/2015 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.4 and 12.1.0.5 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Agent Next Gen. | |
| Modificada | Media (5.8) | 1.7% | — | Oracle Enterprise Manager Grid Control | 21/10/2015 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.4 and 12.1.0.5 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Agent Next Gen. | |
| Modificada | Baja (3.6) | 1.2% | — | Oracle Enterprise Manager Grid Control | 21/10/2015 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Ops Center component in Oracle Enterprise Manager Grid Control 12.1.0.1 and 12.2.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Ops Center. | |
| Modificada | Media (4) | 6.8% | 💥 Exploit | F5 Enterprise ManagerF5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+10 | 17/9/2015 | 17/6/2026 | Directory traversal vulnerability in the configuration utility in F5 BIG-IP before 12.0.0 and Enterprise Manager 3.0.0 through 3.1.1 allows remote authenticated users to access arbitrary files in the web root via unspecified vectors. | |
| Modificada | Media (4) | 1.7% | — | HP Virtual Connect Enterprise Manager SDK | 27/8/2015 | 17/6/2026 | HP Virtual Connect Enterprise Manager (VCEM) SDK before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote authenticated users to obtain sensitive information via unspecified vectors. | |
| Modificada | Alta (7.5) | 3.9% | — | HP Virtual Connect Enterprise Manager SDK | 27/8/2015 | 17/6/2026 | HP Virtual Connect Enterprise Manager (VCEM) SDK before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote attackers to obtain sensitive information or modify data via unspecified vectors. | |
| Modificada | Baja (3.5) | 0.77% | — | IBM Case Manager | 20/7/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Error dialog in IBM Case Manager 5.2.1 before 5.2.1.2 allow remote authenticated users to inject arbitrary web script or HTML via crafted input to the (1) addressability or (2) comments component. | |
| Modificada | Media (5) | 2.8% | — | Oracle Enterprise Manager Database ControlOracle Enterprise Manager Grid Control | 16/7/2015 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager for Oracle Database component in Oracle Enterprise Manager Grid Control EM Base Platform 11.1.0.1, and EM DB Control 11.2.0.3 and 11.2.0.4, allows remote attackers to affect confidentiality via vectors related to RAC Management. | |
| Modificada | Media (5.5) | 1.7% | — | Oracle Enterprise Manager Plugin FOR Database ControlOracle Enterprise Manager Database ControlOracle Enterprise Manager Grid Control | 16/7/2015 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager for Oracle Database component in Oracle Enterprise Manager Grid Control EM Base Platform 11.1.0.1; EM Plugin for DB 12.1.0.5, 12.1.0.6, 12.1.0.7; and EM DB Control 11.1.0.7, 11.2.0.3, and 11.2.0.4 allows remote authenticated users to affect confidentiality and… | |
| Modificada | Media (4.3) | 2.0% | — | Oracle Enterprise Manager Database ControlOracle Enterprise Manager Grid ControlOracle Enterprise Manager Plugin FOR Database Control | 16/7/2015 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager for Oracle Database component in Oracle Enterprise Manager Grid Control EM Base Platform: 11.1.0.1; EM Plugin for DB: 12.1.0.5, 12.1.0.6, 12.1.0.7; EM DB Control: 11.1.0.7, 11.2.0.3, and 11.2.0.4 allows remote attackers to affect integrity via unknown vectors related… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Adobe Flash PlayerOpensuse EvergreenOpensuseSuse Linux Enterprise Desktop+11 | 23/6/2015 | 17/6/2026 | Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in June 2015. | |
| Modificada | Media (6.4) | 8.3% | — | Haxx CurlHaxx LibcurlHP System Management HomepageOracle Enterprise Manager OPS Center+1 | 22/6/2015 | 17/6/2026 | The smb_request_state function in cURL and libcurl 7.40.0 through 7.42.1 allows remote SMB servers to obtain sensitive information from memory or cause a denial of service (out-of-bounds read and crash) via crafted length and offset values. | |
| Modificada | Alta (7.8) | 9.7% | — | Ipsec-toolsCanonical Ubuntu LinuxFedoraproject FedoraF5 Big-ip Application Acceleration Manager+21 | 29/5/2015 | 17/6/2026 | racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a series of crafted UDP requests. | |
| Modificada | Media (5) | 7.3% | — | Oracle Enterprise Manager OPS CenterHaxx CurlHaxx LibcurlCanonical Ubuntu Linux+2 | 1/5/2015 | 17/6/2026 | The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow remote proxy servers to obtain sensitive information by reading the header contents. | |
| Modificada | Media (4.3) | 1.4% | — | Oracle Enterprise Manager Grid Control | 16/4/2015 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control MOS 12.1.0.5 and 12.1.0.6 allows remote attackers to affect integrity via unknown vectors related to My Oracle Support Plugin. | |
| Modificada | Media (5) | 1.3% | — | Oracle Enterprise Manager Grid Control | 21/1/2015 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.3 and 12.1.0.4 allows remote attackers to affect confidentiality via unknown vectors related to UI Framework. |