Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
4185 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.7% | — | ByobuCanonical Ubuntu Linux | 17/4/2020 | 17/6/2026 | Byobu Apport hook may disclose sensitive information since it automatically uploads the local user's .screenrc which may contain private hostnames, usernames and passwords. This issue affects: byobu | |
| Modificada | Alta (7.5) | 3.9% | — | Squid-cache SquidCanonical Ubuntu LinuxDebian Linux | 15/4/2020 | 17/6/2026 | An issue was discovered in Squid through 4.7 and 5. When receiving a request, Squid checks its cache to see if it can serve up a response. It does this by making a MD5 hash of the absolute URL of the request. If found, it servers the request. The absolute URL can include the decoded UserInfo (username and password)… | |
| Modificada | Crítica (9.8) | 6.7% | — | Squid-cache SquidDebian LinuxCanonical Ubuntu LinuxOpensuse Leap | 15/4/2020 | 17/6/2026 | An issue was discovered in Squid through 4.7. When handling the tag esi:when when ESI is enabled, Squid calls ESIExpression::Evaluate. This function uses a fixed stack buffer to hold the expression while it's being evaluated. When processing the expression, it could either evaluate the top of the stack, or add a new… | |
| Modificada | Crítica (9.8) | 3.9% | — | Squid-cache SquidDebian LinuxCanonical Ubuntu Linux | 15/4/2020 | 17/6/2026 | An issue was discovered in Squid through 4.7. When handling requests from users, Squid checks its rules to see if the request should be denied. Squid by default comes with rules to block access to the Cache Manager, which serves detailed server information meant for the maintainer. This rule is implemented via… | |
| Modificada | Media (5.9) | 5.9% | — | Squid-cache SquidCanonical Ubuntu LinuxDebian LinuxOpensuse Leap | 15/4/2020 | 17/6/2026 | An issue was discovered in Squid through 4.7. When Squid is parsing ESI, it keeps the ESI elements in ESIContext. ESIContext contains a buffer for holding a stack of ESIElements. When a new ESIElement is parsed, it is added via addStackElement. addStackElement has a check for the number of elements in this buffer, but… | |
| Modificada | Media (4.4) | 1.8% | — | Oracle MysqlFedoraproject FedoraCanonical Ubuntu LinuxNetapp Active IQ Unified Manager+3 | 15/4/2020 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 8.0.19 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (4.9) | 2.1% | — | Oracle MysqlFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+3 | 15/4/2020 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS). Supported versions that are affected are 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability… | |
| Modificada | Media (4.9) | 2.5% | — | Oracle MysqlFedoraproject FedoraCanonical Ubuntu LinuxNetapp Active IQ Unified Manager+3 | 15/4/2020 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (4.9) | 2.5% | — | Oracle MysqlFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+3 | 15/4/2020 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Baja (3.7) | 2.5% | — | Oracle MysqlMariadbCanonical Ubuntu LinuxNetapp Active IQ Unified Manager+3 | 15/4/2020 | 17/6/2026 | Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.6.47 and prior, 5.7.29 and prior and 8.0.18 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Client.… | |
| Modificada | Media (4.9) | 2.5% | — | Oracle MysqlFedoraproject FedoraCanonical Ubuntu LinuxNetapp Active IQ Unified Manager+3 | 15/4/2020 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (4.9) | 2.1% | — | Oracle MysqlFedoraproject FedoraCanonical Ubuntu LinuxNetapp Active IQ Unified Manager+3 | 15/4/2020 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Connection Handling). Supported versions that are affected are 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of… | |
| Modificada | Media (4.9) | 2.5% | — | Oracle MysqlFedoraproject FedoraCanonical Ubuntu LinuxNetapp Active IQ Unified Manager+3 | 15/4/2020 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (4.9) | 2.5% | — | Oracle MysqlFedoraproject FedoraCanonical Ubuntu LinuxNetapp Active IQ Unified Manager+3 | 15/4/2020 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Charsets). The supported version that is affected is 8.0.19. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can… | |
| Modificada | Media (4.9) | 2.5% | — | Oracle MysqlFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+3 | 15/4/2020 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (4.9) | 2.1% | — | Oracle MysqlFedoraproject FedoraCanonical Ubuntu LinuxNetapp Active IQ Unified Manager+3 | 15/4/2020 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of… | |
| Modificada | Media (4.9) | 2.5% | — | Oracle MysqlFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+3 | 15/4/2020 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can… | |
| Modificada | Media (4.9) | 2.4% | — | Oracle MysqlFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+3 | 15/4/2020 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can… | |
| Modificada | Media (4.9) | 2.1% | — | Oracle MysqlFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+3 | 15/4/2020 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (5.3) | 4.9% | — | Oracle JDKOracle JREOracle OpenjdkNetapp 7-mode Transition Tool+17 | 15/4/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Alta (7.5) | 2.8% | — | Oracle JDKOracle JREOracle OpenjdkNetapp 7-mode Transition Tool+15 | 15/4/2020 | 17/6/2026 | Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.6 and 14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE. Successful attacks of this vulnerability can result in… | |
| Modificada | Media (4.9) | 3.0% | — | Oracle MysqlNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation+6 | 15/4/2020 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions that are affected are 5.6.47 and prior, 5.7.29 and prior and 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise… | |
| Modificada | Alta (8.3) | 4.1% | — | Oracle JDKOracle JREOracle OpenjdkNetapp 7-mode Transition Tool+16 | 15/4/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Media (5.9) | 3.4% | — | Oracle MysqlFedoraproject FedoraCanonical Ubuntu LinuxNetapp Active IQ Unified Manager+3 | 15/4/2020 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Memcached). Supported versions that are affected are 5.6.47 and prior, 5.7.29 and prior and 8.0.19 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL… | |
| Modificada | Alta (8.3) | 6.2% | — | Oracle JDKOracle JREOracle OpenjdkNetapp 7-mode Transition Tool+16 | 15/4/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… |