Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3028▼ 62 respecto a la semana anterior
Críticas / altas1422▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
668 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 18% | — | Microsoft SQL Server | 10/11/2016 | 17/6/2026 | Microsoft SQL Server 2016 mishandles the FILESTREAM path, which allows remote authenticated users to gain privileges via unspecified vectors, aka "SQL Analysis Services Information Disclosure Vulnerability." | |
| Modificada | Media (6.1) | 8.2% | — | Microsoft SQL Server | 10/11/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the MDS API in Microsoft SQL Server 2016 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "MDS API XSS Vulnerability." | |
| Modificada | Alta (8.8) | 12% | — | Microsoft SQL Server | 10/11/2016 | 17/6/2026 | Microsoft SQL Server 2014 SP1, 2014 SP2, and 2016 does not properly perform a cast of an unspecified pointer, which allows remote authenticated users to gain privileges via unknown vectors, aka "SQL RDBMS Engine Elevation of Privilege Vulnerability." | |
| Modificada | Alta (8.8) | 12% | — | Microsoft SQL Server | 10/11/2016 | 17/6/2026 | Microsoft SQL Server 2016 does not properly perform a cast of an unspecified pointer, which allows remote authenticated users to gain privileges via unknown vectors, aka "SQL RDBMS Engine Elevation of Privilege Vulnerability." | |
| Modificada | Media (6.2) | 0.37% | — | IBM Tivoli Storage Flashcopy Manager FOR SQL ServerIBM Tivoli Storage Manager FOR Databases Data Protection FOR Microsoft SQL Server | 8/8/2016 | 17/6/2026 | IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server (aka IBM Spectrum Protect for Databases) 6.3 before 6.3.1.7 and 6.4 before 6.4.1.9 and Tivoli Storage FlashCopy Manager for Microsoft SQL Server (aka IBM Spectrum Protect Snapshot) 3.1 before 3.1.1.7 and 3.2 before 3.2.1.9 allow local… | |
| Modificada | Baja (1.9) | 0.42% | — | IBM Tivoli Storage Manager FOR Databases Data Protection FOR Microsoft SQL ServerIBM Tivoli Storage Manager FOR Mail Data Protection FOR Microsoft Exchange ServerIBM Tivoli Storage Flashcopy Manager | 14/11/2015 | 17/6/2026 | IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server (aka Spectrum Protect for Databases) 5.5 before 5.5.6.2, 6.3 before 6.3.1.6, 6.4 before 6.4.1.8, and 7.1 before 7.1.4; Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server (aka Spectrum Protect for Mail) 5.5… | |
| Modificada | Alta (7.5) | 2.5% | — | Drupal 7 Driver FOR SQL Server AND SQL Azure Project Drupal 7 Driver FOR SQL Server AND SQL Azure | 21/10/2015 | 17/6/2026 | The escapeLike function in sqlsrv/database.inc in the Drupal 7 driver for SQL Server and SQL Azure 7.x-1.x before 7.x-1.4 does not properly escape certain characters, which allows remote attackers to execute arbitrary SQL commands via vectors involving a module using the db_like function. | |
| Modificada | Baja (2.1) | 0.33% | — | IBM Tivoli Storage Flashcopy ManagerIBM Tivoli Storage Manager FOR Databases Data Protection FOR Microsoft SQL ServerIBM Tivoli Storage Manager FOR Mail Data Protection FOR Microsoft Exchange Server | 23/8/2015 | 17/6/2026 | IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server 5.5 before 5.5.6.1, 6.3 before 6.3.1.5, 6.4 before 6.4.1.7, and 7.1 before 7.1.2; Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 5.5 before 5.5.1.1, 6.1 before 6.1.3.7, 6.3 before 6.3.1.5, 6.4 before… | |
| Modificada | Baja (2.1) | 0.40% | — | IBM Tivoli Storage Flashcopy ManagerIBM Tivoli Storage Manager FOR Databases Data Protection FOR Microsoft SQL ServerIBM Tivoli Storage Manager FOR Mail Data Protection FOR Microsoft Exchange Server | 23/8/2015 | 17/6/2026 | IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server 7.1 before 7.1.2, Tivoli Storage Manager for Mail: Data Protection for Microsoft Exchange Server 7.1 before 7.1.2, and Tivoli Storage FlashCopy Manager 4.1 before 4.1.2 place cleartext passwords in exception messages, which allows… | |
| Modificada | Alta (8.5) | 12% | — | Microsoft SQL Server | 14/7/2015 | 17/6/2026 | Microsoft SQL Server 2008 SP3 and SP4, 2008 R2 SP2 and SP3, 2012 SP1 and SP2, and 2014 does not prevent use of uninitialized memory in certain attempts to execute virtual functions, which allows remote authenticated users to execute arbitrary code via a crafted query, aka "SQL Server Remote Code Execution… | |
| Modificada | Alta (7.1) | 10% | — | Microsoft SQL Server | 14/7/2015 | 17/6/2026 | Microsoft SQL Server 2008 SP3 and SP4, 2008 R2 SP2 and SP3, 2012 SP1 and SP2, and 2014, when transactional replication is configured, does not prevent use of uninitialized memory in unspecified function calls, which allows remote authenticated users to execute arbitrary code by leveraging certain permissions and… | |
| Modificada | Media (6.5) | 19% | — | Microsoft SQL Server | 14/7/2015 | 17/6/2026 | Microsoft SQL Server 2008 SP3 and SP4, 2008 R2 SP2 and SP3, 2012 SP1 and SP2, and 2014 uses an incorrect class during casts of unspecified pointers, which allows remote authenticated users to gain privileges by leveraging certain write access, aka "SQL Server Elevation of Privilege Vulnerability." | |
| Modificada | Media (6.8) | 26% | — | Microsoft SQL Server | 12/8/2014 | 17/6/2026 | Microsoft SQL Server 2008 SP3, 2008 R2 SP2, and 2012 SP1 does not properly control use of stack memory for processing of T-SQL batch commands, which allows remote authenticated users to cause a denial of service (daemon hang) via a crafted T-SQL statement, aka "Microsoft SQL Server Stack Overrun Vulnerability." | |
| Modificada | Media (4.3) | 15% | — | Microsoft SQL Server | 12/8/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Master Data Services (MDS) in Microsoft SQL Server 2012 SP1 and 2014 on 64-bit platforms allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "SQL Master Data Services XSS Vulnerability." | |
| Modificada | Media (5) | 55% | — | Oracle Supply Chain Products SuiteOracle Supply Chain Products Suite Sql-server | 15/1/2014 | 16/6/2026 | Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 12.2.0, and 12.2.1 allows remote attackers to affect confidentiality via unknown vectors related to DM Others. | |
| Modificada | Media (5) | 59% | — | Oracle Supply Chain Products SuiteOracle Supply Chain Products Suite Sql-server | 15/1/2014 | 16/6/2026 | Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 12.2.1, 12.2.2, and 12.2.3 allows remote attackers to affect confidentiality via unknown vectors related to DM Others. | |
| Modificada | Media (4.3) | 7.2% | — | Oracle Supply Chain Products SuiteOracle Supply Chain Products Suite Sql-server | 15/1/2014 | 17/6/2026 | Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0.x, 7.3.1.x, 12.2.0, 12.2.1, and 12.2.2 allows remote attackers to affect integrity via unknown vectors related to DM Others. | |
| Modificada | Media (5.5) | 8.8% | — | Oracle Supply Chain Products SuiteOracle Supply Chain Products Suite Sql-server | 15/1/2014 | 17/6/2026 | Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 12.2.1, and 12.2.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to DM Others. | |
| Modificada | Baja (3.5) | 1.6% | — | Oracle Supply Chain Products SuiteOracle Supply Chain Products Suite Sql-server | 15/1/2014 | 17/6/2026 | Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0.x, 7.3.1.x, 12.2.0, 12.2.1, and 12.2.2 allows remote authenticated users to affect integrity via unknown vectors related to DM Others. | |
| Modificada | Alta (7.5) | 49% | — | Lianja SQL Server | 4/7/2013 | 16/6/2026 | Stack-based buffer overflow in db_netserver in Lianja SQL Server before 1.0.0RC5.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted string to TCP port 8001. | |
| Modificada | Media (4.3) | 16% | — | Microsoft SQL ServerMicrosoft SQL Server Reporting Services | 9/10/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the SQL Server Report Manager in Microsoft SQL Server 2000 Reporting Services SP2 and SQL Server 2005 SP4, 2008 SP2 and SP3, 2008 R2 SP1, and 2012 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "Reflected XSS Vulnerability." | |
| Analizada | Alta (8.8) | 72% | ⚠ Explotación activa | Microsoft Commerce ServerMicrosoft Host Integration ServerMicrosoft OfficeMicrosoft Office WEB Components+3 | 15/8/2012 | 16/6/2026 | The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL Server 2008 SP2, SP3, R2, R2 SP1, and R2 SP2, Commerce Server 2002 SP4, Commerce Server 2007 SP2,… | |
| Modificada | Media (4) | 1.9% | — | MysqlMysql Community ServerMysql ServerOracle Mysql+1 | 3/5/2012 | 16/6/2026 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.19 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer. | |
| Analizada | Alta (8.8) | 100% | ⚠ Explotación activa | Microsoft OfficeMicrosoft Office WEB ComponentsMicrosoft SQL Server 2000Microsoft SQL Server 2005+6 | 10/4/2012 | 16/6/2026 | The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components SP3; SQL Server 2000 SP4, 2005 SP4, and 2008 SP2, SP3, and R2; BizTalk Server 2002 SP1; Commerce… | |
| Modificada | Media (4.3) | 15% | — | Microsoft Office InfopathMicrosoft SQL ServerMicrosoft SQL Server Management Studio ExpressMicrosoft Visual Studio | 16/6/2011 | 16/6/2026 | The XML Editor in Microsoft InfoPath 2007 SP2 and 2010; SQL Server 2005 SP3 and SP4 and 2008 SP1, SP2, and R2; SQL Server Management Studio Express (SSMSE) 2005; and Visual Studio 2005 SP1, 2008 SP1, and 2010 does not properly handle external entities, which allows remote attackers to read arbitrary files via a… |