Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
601 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.5) | 0.42% | — | Oracle MysqlNetapp Oncommand Unified ManagerNetapp Oncommand Workflow AutomationNetapp Snapcenter+1 | 16/1/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Shell). Supported versions that are affected are 8.0.13 and prior. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks… | |
| Modificada | Media (4.9) | 3.4% | — | Oracle MysqlMariadbRedhat Enterprise LinuxRedhat Enterprise Linux EUS+7 | 16/1/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks… | |
| Modificada | Media (6.4) | 2.5% | — | Oracle MysqlMariadbNetapp Active IQ Unified ManagerNetapp Oncommand Insight+9 | 16/1/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Connection Handling). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Difficult to exploit vulnerability allows low privileged attacker with access to the physical communication segment… | |
| Modificada | Media (4.9) | 2.6% | — | Oracle MysqlNetapp Oncommand Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation+1 | 16/1/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability… | |
| Modificada | Media (4.9) | 3.4% | — | Oracle MysqlCanonical Ubuntu LinuxNetapp Oncommand InsightNetapp Oncommand Unified Manager+7 | 16/1/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise… | |
| Modificada | Media (6.5) | 3.9% | — | Oracle MysqlCanonical Ubuntu LinuxMariadbNetapp Active IQ Unified Manager+9 | 16/1/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL… | |
| Modificada | Media (5.5) | 2.1% | — | Oracle MysqlNetapp Oncommand Unified ManagerNetapp Oncommand Workflow AutomationNetapp Snapcenter+6 | 16/1/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Alta (8.1) | 2.5% | — | Oracle Mysql ConnectorsNetapp Active IQ Unified ManagerNetapp Oncommand Workflow AutomationNetapp Snapcenter | 16/1/2019 | 17/6/2026 | Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/Python). Supported versions that are affected are 8.0.13 and prior and 2.1.8 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise MySQL Connectors. Successful… | |
| Modificada | Media (6.5) | 3.3% | — | Oracle MysqlCanonical Ubuntu LinuxNetapp Oncommand Unified ManagerNetapp Oncommand Workflow Automation+7 | 16/1/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supported versions that are affected are 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful… | |
| Modificada | Media (4.9) | 3.1% | — | Oracle MysqlCanonical Ubuntu LinuxNetapp Oncommand Unified ManagerNetapp Oncommand Workflow Automation+7 | 16/1/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.… | |
| Modificada | Crítica (9.8) | 9.7% | — | Fasterxml Jackson-databindDebian LinuxOracle Banking PlatformOracle Business Process Management Suite+16 | 2/1/2019 | 17/6/2026 | FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization. | |
| Modificada | Crítica (9.8) | 13% | — | Fasterxml Jackson-databindDebian LinuxOracle Banking PlatformOracle Business Process Management Suite+21 | 2/1/2019 | 17/6/2026 | FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization. | |
| Modificada | Crítica (9.8) | 6.1% | — | PerlCanonical Ubuntu LinuxDebian LinuxNetapp E-series Santricity OS Controller+4 | 7/12/2018 | 17/6/2026 | Perl before 5.26.3 has a buffer overflow via a crafted regular expression that triggers invalid write operations. | |
| Modificada | Crítica (9.1) | 9.5% | — | PerlCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux+5 | 7/12/2018 | 17/6/2026 | Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process memory. | |
| Modificada | Crítica (9.8) | 12% | — | PerlCanonical Ubuntu LinuxDebian LinuxNetapp E-series Santricity OS Controller+14 | 7/12/2018 | 17/6/2026 | Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations. | |
| Modificada | Crítica (9.8) | 13% | — | PerlCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux+4 | 5/12/2018 | 17/6/2026 | Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations. | |
| Modificada | Media (5.9) | 12% | — | OpensslCanonical Ubuntu LinuxDebian LinuxNodejs Node.js+15 | 30/10/2018 | 17/6/2026 | The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected 1.1.1). Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.0.2q (Affected… | |
| Modificada | Crítica (9.1) | 92% | 💥 Exploit | LibsshCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux+5 | 17/10/2018 | 17/6/2026 | A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access. | |
| Modificada | Media (4.3) | 1.4% | — | Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Unified ManagerNetapp Oncommand Workflow Automation+2 | 17/10/2018 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks… | |
| Modificada | Media (4.9) | 2.1% | — | Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Unified ManagerNetapp Oncommand Workflow Automation+2 | 17/10/2018 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Windows). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (4.4) | 2.3% | — | Oracle MysqlCanonical Ubuntu LinuxNetapp Active IQ Unified ManagerNetapp Oncommand Insight+3 | 17/10/2018 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful… | |
| Modificada | Media (4.4) | 2.5% | — | Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Unified ManagerNetapp Oncommand Workflow Automation+3 | 17/10/2018 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Logging). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.… | |
| Modificada | Media (4.9) | 4.0% | — | Oracle MysqlNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation+7 | 17/10/2018 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Storage Engines). Supported versions that are affected are 5.5.61 and prior, 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple… | |
| Modificada | Media (4.9) | 2.1% | — | Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Unified ManagerNetapp Oncommand Workflow Automation+2 | 17/10/2018 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: JSON). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (4.9) | 2.1% | — | Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Unified ManagerNetapp Oncommand Workflow Automation+2 | 17/10/2018 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Roles). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of… |