Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

571 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)2.6%—Oracle Mysql Connector/net19/10/201717/6/2026
Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/Net). Supported versions that are affected are 6.9.9 and earlier. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of…
ModificadaAlta (7.8)0.55%—Polycom Btoe Connector28/8/201717/6/2026
Polycom BToE Connector before 3.0.0 uses weak permissions (Everyone: Full Control) for "Program Files (x86)\polycom\polycom btoe connector\plcmbtoesrv.exe," which allows local users to gain privileges via a Trojan horse file.
ModificadaMedia (5.3)2.0%—Oracle MysqlOracle Mysql Connector/cDebian Linux8/8/201717/6/2026
Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/C). Supported versions that are affected are 6.1.10 and earlier. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of…
ModificadaBaja (3.3)0.41%—Oracle Connector/python24/4/201717/6/2026
Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/Python). Supported versions that are affected are 2.1.5 and earlier. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL…
ModificadaBaja (3.3)0.45%—Oracle Connector/j24/4/201717/6/2026
Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 5.1.41 and earlier. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors.…
ModificadaMedia (6.4)1.7%—Oracle Mysql Connectors24/4/201717/6/2026
Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 5.1.41 and earlier. Easily "exploitable" vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. While the vulnerability…
ModificadaAlta (8.5)2.9%—Oracle Connector/j24/4/201717/6/2026
Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 5.1.40 and earlier. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. While the vulnerability…
ModificadaCrítica (9.8)90%💥 ExploitApache Log4jNetapp Oncommand API ServicesNetapp Oncommand InsightNetapp Oncommand Workflow Automation+7517/4/201717/6/2026
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
ModificadaCrítica (9.8)23%—Apache Tomcat JK Connector12/4/201717/6/2026
Buffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42.
ModificadaAlta (8.1)2.3%—Forgerock Racf Connector3/2/201717/6/2026
Unspecified methods in the RACF Connector component before 1.1.1.0 in ForgeRock OpenIDM and OpenICF improperly call the SearchControls constructor with returnObjFlag set to true, which allows remote attackers to execute arbitrary code via a crafted serialized Java object, aka LDAP entry poisoning.
ModificadaMedia (6.1)0.71%—IBM Social Rendering Templates FOR Digital Data Connector1/2/201717/6/2026
IBM Social Rendering Templates for Digital Data Connector is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
ModificadaAlta (7.8)0.30%—Cisco Fireamp Connector Endpoint Software14/12/201617/6/2026
A vulnerability in the system management of certain FireAMP system processes in Cisco FireAMP Connector Endpoint software could allow an authenticated, local attacker to stop certain protected FireAMP processes without requiring a password. Stopping certain critical processes could cause a denial of service (DoS)…
ModificadaMedia (5.6)2.2%—Oracle Mysql Connector/python25/10/201617/6/2026
Unspecified vulnerability in the MySQL Connector component 2.1.3 and earlier and 2.0.4 and earlier in Oracle MySQL allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Connector/Python.
ModificadaAlta (8.1)1.9%—Ietf Transport Layer SecurityNetapp Clustered Data Ontap Antivirus ConnectorNetapp Data Ontap EdgeNetapp Host Agent+921/9/201617/6/2026
The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateType but does not directly document the ability to compute the master secret in certain situations with a client secret key and server public key but not a server secret key, which…
ModificadaMedia (5.9)7.1%💥 PoCOracle MysqlOracle Mysql Connector/cMariadbFedoraproject Fedora+816/5/201617/6/2026
Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, aka a "BACKRONYM" attack.
ModificadaAlta (7.2)0.61%—HP Arcsight Connector ApplianceHP Arcsight LoggerHP Arcsight Command CenterHP Arcsight Connectors+34/11/201517/6/2026
HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight account access.
ModificadaMedia (6.9)1.3%—HP Arcsight Smartconnectors4/11/201517/6/2026
The CWSAPI SOAP service in HP ArcSight SmartConnectors before 7.1.6 has a hardcoded password, which makes it easier for remote attackers to obtain administrative access by leveraging knowledge of this password.
ModificadaMedia (6.8)1.5%—HP Arcsight Smartconnectors4/11/201517/6/2026
HP ArcSight SmartConnectors before 7.1.6 do not verify X.509 certificates from Logger devices, which allows man-in-the-middle attackers to spoof devices and obtain sensitive information via a crafted certificate.
ModificadaMedia (5)7.1%—Apache Tomcat Connectors21/4/201517/6/2026
Apache Tomcat Connectors (mod_jk) before 1.2.41 ignores JkUnmount rules for subtrees of previous JkMount rules, which allows remote attackers to access otherwise restricted artifacts via unspecified vectors.
ModificadaMedia (6.8)0.94%—HP Arcsight Connector Appliance FirmwareHP Arcsight Connector ApplianceHP Arcsight Logger16/2/201316/6/2026
Unspecified vulnerability in HP ArcSight Connector Appliance 6.3 and earlier and ArcSight Logger 5.2 and earlier allows remote authenticated users to execute arbitrary code via unknown vectors.
ModificadaMedia (5)3.8%—HP Arcsight Connector Appliance FirmwareHP Arcsight Connector ApplianceHP Arcsight Logger16/2/201316/6/2026
Unspecified vulnerability in HP ArcSight Connector Appliance before 6.3 and ArcSight Logger 5.2 and earlier allows remote attackers to obtain sensitive information via unknown vectors.
ModificadaMedia (6.5)2.4%—HP Arcsight Connector Appliance FirmwareHP Arcsight Connector ApplianceHP Arcsight Logger16/2/201316/6/2026
Unspecified vulnerability in HP ArcSight Connector Appliance 6.3 and earlier and ArcSight Logger 5.2 and earlier allows remote authenticated users to obtain sensitive information, modify data, or cause a denial of service via unknown vectors.
ModificadaMedia (4.3)2.6%—HP Arcsight Connector Appliance FirmwareHP Arcsight Connector ApplianceHP Arcsight Logger Appliance FirmwareHP Arcsight Logger Appliance8/8/201216/6/2026
Cross-site scripting (XSS) vulnerability in the import functionality in HP ArcSight Connector appliance 6.2.0.6244.0 and ArcSight Logger appliance 5.2.0.6288.0 allows remote attackers to inject arbitrary web script or HTML via a crafted file.
ModificadaMedia (4)1.9%—MysqlMysql Community ServerMysql ServerOracle Mysql+13/5/201216/6/2026
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.19 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
ModificadaBaja (3.6)0.55%—HP Windows Event LOG SmartconnectorHP Arcsight C1000 ApplianceHP Arcsight C1300 ApplianceHP Arcsight C3200 Appliance+319/7/201116/6/2026
Windows Event Log SmartConnector in HP ArcSight Connector Appliance before 6.1 uses world-writable permissions for exported report files, which allows local users to change or delete log data by modifying a file, a different vulnerability than CVE-2011-0770.
Orbitaley — Vulnerabilidades