Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
571 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 2.6% | — | Oracle Mysql Connector/net | 19/10/2017 | 17/6/2026 | Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/Net). Supported versions that are affected are 6.9.9 and earlier. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of… | |
| Modificada | Alta (7.8) | 0.55% | — | Polycom Btoe Connector | 28/8/2017 | 17/6/2026 | Polycom BToE Connector before 3.0.0 uses weak permissions (Everyone: Full Control) for "Program Files (x86)\polycom\polycom btoe connector\plcmbtoesrv.exe," which allows local users to gain privileges via a Trojan horse file. | |
| Modificada | Media (5.3) | 2.0% | — | Oracle MysqlOracle Mysql Connector/cDebian Linux | 8/8/2017 | 17/6/2026 | Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/C). Supported versions that are affected are 6.1.10 and earlier. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of… | |
| Modificada | Baja (3.3) | 0.41% | — | Oracle Connector/python | 24/4/2017 | 17/6/2026 | Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/Python). Supported versions that are affected are 2.1.5 and earlier. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL… | |
| Modificada | Baja (3.3) | 0.45% | — | Oracle Connector/j | 24/4/2017 | 17/6/2026 | Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 5.1.41 and earlier. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors.… | |
| Modificada | Media (6.4) | 1.7% | — | Oracle Mysql Connectors | 24/4/2017 | 17/6/2026 | Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 5.1.41 and earlier. Easily "exploitable" vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. While the vulnerability… | |
| Modificada | Alta (8.5) | 2.9% | — | Oracle Connector/j | 24/4/2017 | 17/6/2026 | Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 5.1.40 and earlier. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. While the vulnerability… | |
| Modificada | Crítica (9.8) | 90% | 💥 Exploit | Apache Log4jNetapp Oncommand API ServicesNetapp Oncommand InsightNetapp Oncommand Workflow Automation+75 | 17/4/2017 | 17/6/2026 | In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code. | |
| Modificada | Crítica (9.8) | 23% | — | Apache Tomcat JK Connector | 12/4/2017 | 17/6/2026 | Buffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42. | |
| Modificada | Alta (8.1) | 2.3% | — | Forgerock Racf Connector | 3/2/2017 | 17/6/2026 | Unspecified methods in the RACF Connector component before 1.1.1.0 in ForgeRock OpenIDM and OpenICF improperly call the SearchControls constructor with returnObjFlag set to true, which allows remote attackers to execute arbitrary code via a crafted serialized Java object, aka LDAP entry poisoning. | |
| Modificada | Media (6.1) | 0.71% | — | IBM Social Rendering Templates FOR Digital Data Connector | 1/2/2017 | 17/6/2026 | IBM Social Rendering Templates for Digital Data Connector is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Modificada | Alta (7.8) | 0.30% | — | Cisco Fireamp Connector Endpoint Software | 14/12/2016 | 17/6/2026 | A vulnerability in the system management of certain FireAMP system processes in Cisco FireAMP Connector Endpoint software could allow an authenticated, local attacker to stop certain protected FireAMP processes without requiring a password. Stopping certain critical processes could cause a denial of service (DoS)… | |
| Modificada | Media (5.6) | 2.2% | — | Oracle Mysql Connector/python | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the MySQL Connector component 2.1.3 and earlier and 2.0.4 and earlier in Oracle MySQL allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Connector/Python. | |
| Modificada | Alta (8.1) | 1.9% | — | Ietf Transport Layer SecurityNetapp Clustered Data Ontap Antivirus ConnectorNetapp Data Ontap EdgeNetapp Host Agent+9 | 21/9/2016 | 17/6/2026 | The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateType but does not directly document the ability to compute the master secret in certain situations with a client secret key and server public key but not a server secret key, which… | |
| Modificada | Media (5.9) | 7.1% | 💥 PoC | Oracle MysqlOracle Mysql Connector/cMariadbFedoraproject Fedora+8 | 16/5/2016 | 17/6/2026 | Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, aka a "BACKRONYM" attack. | |
| Modificada | Alta (7.2) | 0.61% | — | HP Arcsight Connector ApplianceHP Arcsight LoggerHP Arcsight Command CenterHP Arcsight Connectors+3 | 4/11/2015 | 17/6/2026 | HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight account access. | |
| Modificada | Media (6.9) | 1.3% | — | HP Arcsight Smartconnectors | 4/11/2015 | 17/6/2026 | The CWSAPI SOAP service in HP ArcSight SmartConnectors before 7.1.6 has a hardcoded password, which makes it easier for remote attackers to obtain administrative access by leveraging knowledge of this password. | |
| Modificada | Media (6.8) | 1.5% | — | HP Arcsight Smartconnectors | 4/11/2015 | 17/6/2026 | HP ArcSight SmartConnectors before 7.1.6 do not verify X.509 certificates from Logger devices, which allows man-in-the-middle attackers to spoof devices and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5) | 7.1% | — | Apache Tomcat Connectors | 21/4/2015 | 17/6/2026 | Apache Tomcat Connectors (mod_jk) before 1.2.41 ignores JkUnmount rules for subtrees of previous JkMount rules, which allows remote attackers to access otherwise restricted artifacts via unspecified vectors. | |
| Modificada | Media (6.8) | 0.94% | — | HP Arcsight Connector Appliance FirmwareHP Arcsight Connector ApplianceHP Arcsight Logger | 16/2/2013 | 16/6/2026 | Unspecified vulnerability in HP ArcSight Connector Appliance 6.3 and earlier and ArcSight Logger 5.2 and earlier allows remote authenticated users to execute arbitrary code via unknown vectors. | |
| Modificada | Media (5) | 3.8% | — | HP Arcsight Connector Appliance FirmwareHP Arcsight Connector ApplianceHP Arcsight Logger | 16/2/2013 | 16/6/2026 | Unspecified vulnerability in HP ArcSight Connector Appliance before 6.3 and ArcSight Logger 5.2 and earlier allows remote attackers to obtain sensitive information via unknown vectors. | |
| Modificada | Media (6.5) | 2.4% | — | HP Arcsight Connector Appliance FirmwareHP Arcsight Connector ApplianceHP Arcsight Logger | 16/2/2013 | 16/6/2026 | Unspecified vulnerability in HP ArcSight Connector Appliance 6.3 and earlier and ArcSight Logger 5.2 and earlier allows remote authenticated users to obtain sensitive information, modify data, or cause a denial of service via unknown vectors. | |
| Modificada | Media (4.3) | 2.6% | — | HP Arcsight Connector Appliance FirmwareHP Arcsight Connector ApplianceHP Arcsight Logger Appliance FirmwareHP Arcsight Logger Appliance | 8/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the import functionality in HP ArcSight Connector appliance 6.2.0.6244.0 and ArcSight Logger appliance 5.2.0.6288.0 allows remote attackers to inject arbitrary web script or HTML via a crafted file. | |
| Modificada | Media (4) | 1.9% | — | MysqlMysql Community ServerMysql ServerOracle Mysql+1 | 3/5/2012 | 16/6/2026 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.19 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer. | |
| Modificada | Baja (3.6) | 0.55% | — | HP Windows Event LOG SmartconnectorHP Arcsight C1000 ApplianceHP Arcsight C1300 ApplianceHP Arcsight C3200 Appliance+3 | 19/7/2011 | 16/6/2026 | Windows Event Log SmartConnector in HP ArcSight Connector Appliance before 6.1 uses world-writable permissions for exported report files, which allows local users to change or delete log data by modifying a file, a different vulnerability than CVE-2011-0770. |