Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 662 respecto a la semana anterior
Críticas / altas1264▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1244 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.4) | 0.34% | — | Oracle Database | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 12.1.0.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors. | |
| Modificada | Baja (2.4) | 1.3% | — | Oracle Database Server | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the RDBMS Security and SQL*Plus components in Oracle Database Server 11.2.0.4 and 12.1.0.2 allows remote administrators to affect confidentiality via vectors related to DBA. | |
| Modificada | Alta (7.8) | 0.49% | — | IBM Security Guardium Database Activity Monitor | 22/10/2016 | 17/6/2026 | IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows local users to obtain administrator privileges for command execution via unspecified vectors. | |
| Modificada | Alta (8.8) | 1.8% | — | IBM Security Guardium Database Activity Monitor | 22/10/2016 | 17/6/2026 | IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote authenticated users to spoof administrator accounts by sending a modified login request over HTTP. | |
| Modificada | Baja (3.7) | 1.0% | — | IBM Security Guardium Database Activity Monitor | 22/10/2016 | 17/6/2026 | IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 does not enable the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by leveraging use of HTTP. | |
| Modificada | Alta (8.8) | 1.2% | — | IBM Security Guardium Database Activity Monitor | 22/10/2016 | 17/6/2026 | IBM Security Guardium Database Activity Monitor 9.x through 9.5 before p700 and 10.x through 10.0.1 before p100 allows remote authenticated users to make HTTP requests with administrator privileges via unspecified vectors. | |
| Modificada | Alta (8.8) | 2.5% | — | IBM Security Guardium Database Activity Monitor | 21/10/2016 | 17/6/2026 | IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote authenticated users to execute arbitrary commands with root privileges via the search field. | |
| Modificada | Alta (7.5) | 95% | 💥 PoC | Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB ServerRedhat Jboss WEB ServerRedhat Enterprise Linux+5 | 1/9/2016 | 17/6/2026 | The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated… | |
| Modificada | Media (6.2) | 0.37% | — | IBM Tivoli Storage Flashcopy Manager FOR SQL ServerIBM Tivoli Storage Manager FOR Databases Data Protection FOR Microsoft SQL Server | 8/8/2016 | 17/6/2026 | IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server (aka IBM Spectrum Protect for Databases) 6.3 before 6.3.1.7 and 6.4 before 6.4.1.9 and Tivoli Storage FlashCopy Manager for Microsoft SQL Server (aka IBM Spectrum Protect Snapshot) 3.1 before 3.1.1.7 and 3.2 before 3.2.1.9 allow local… | |
| Modificada | Crítica (9) | 3.3% | — | Oracle Database | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the OJVM component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors. | |
| Modificada | Media (6.7) | 0.42% | — | Oracle Database | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Data Pump Import component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors. | |
| Modificada | Media (4.4) | 0.38% | — | Oracle Database | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the DB Sharding component in Oracle Database Server 12.1.0.2 allows local users to affect integrity via unknown vectors. | |
| Modificada | Baja (3.4) | 0.33% | — | Oracle Database | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Database Vault component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows local users to affect confidentiality and integrity via unknown vectors. | |
| Modificada | Alta (7.5) | 3.7% | — | Oracle Database | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Portable Clusterware component in Oracle Database Server 11.2.0.4 and 12.1.0.2 allows remote attackers to affect availability via unknown vectors. | |
| Modificada | Crítica (9) | 2.9% | — | Oracle Database | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in the Java VM component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. | |
| Modificada | Alta (7.5) | 1.5% | — | Honeywell Uniformance Process History Database | 21/4/2016 | 17/6/2026 | Buffer overflow in RDISERVER in Honeywell Uniformance Process History Database (PHD) R310, R320, and R321 allows remote attackers to cause a denial of service (service outage) via unspecified vectors. | |
| Modificada | Baja (3.3) | 0.58% | — | Oracle Database | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows local users to affect integrity via unknown vectors, a different vulnerability than CVE-2016-0690. | |
| Modificada | Baja (3.3) | 0.58% | — | Oracle Database | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows local users to affect integrity via unknown vectors, a different vulnerability than CVE-2016-0691. | |
| Modificada | Media (5.9) | 1.7% | — | Oracle Database | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 12.1.0.1 and 12.1.0.2 allows remote attackers to affect availability via unknown vectors. | |
| Modificada | Alta (7.5) | 9.1% | — | PerlDebian LinuxOracle Communications Billing AND Revenue ManagementOracle Configuration Manager+6 | 8/4/2016 | 17/6/2026 | Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp. | |
| Modificada | Media (5.4) | 0.71% | — | IBM Change AND Configuration Management DatabaseIBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Maximo FOR Energy Optimization+9 | 12/3/2016 | 17/6/2026 | SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 IFIX003, and 7.6.0 before 7.6.0.3 IFIX001; Maximo Asset Management 7.5.0 before 7.5.0.9 IFIX003, 7.5.1, and 7.6.0 before 7.6.0.3 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13… | |
| Modificada | Media (4.1) | 0.28% | — | IBM Change AND Configuration Management DatabaseIBM Maximo Asset ManagementIBM Maximo Asset Management EssentialsIBM Maximo FOR Energy Optimization+9 | 27/1/2016 | 17/6/2026 | IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 IFIX002, and 7.6.0 before 7.6.0.3 IFIX001; Maximo Asset Management 7.5.0 before 7.5.0.9 IFIX002, 7.5.1, and 7.6.0 before 7.6.0.3 IFIX001 for SmartCloud Control Desk; and Maximo Asset Management 7.1 through 7.1.1.13 and 7.2 for Tivoli IT Asset… | |
| Modificada | Alta (9) | 3.0% | — | Oracle Database Server | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Java VM component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2015-4794. | |
| Modificada | Media (5.5) | 1.7% | — | Oracle Database Server | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the XDB - XML Database component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality and availability via unknown vectors. | |
| Modificada | Media (4) | 1.3% | — | Oracle Database Server | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Security component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect integrity via unknown vectors. |