Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
636 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 77% | 💥 Exploit | Oracle Database ServerOracle Enterprise Manager Grid Control | 19/1/2011 | 16/6/2026 | Unspecified vulnerability in the Client System Analyzer component in Oracle Database Server 11.1.0.7 and 11.2.0.1 and Enterprise Manager Grid Control 10.2.0.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the January… | |
| Modificada | Media (6.4) | 2.2% | — | Oracle Enterprise Manager Grid Control | 19/1/2011 | 16/6/2026 | Unspecified vulnerability in the Real User Experience Insight component in Oracle Enterprise Manager Grid Control 6.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Processing. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not… | |
| Modificada | Alta (9) | 3.0% | — | Tibco Activematrix BPMTibco Activematrix Businessworks Service EngineTibco Activematrix Service BUSTibco Activematrix Service Grid+2 | 17/12/2010 | 16/6/2026 | Unspecified vulnerability in the ActiveMatrix Runtime component in TIBCO ActiveMatrix Service Grid 3.0.0, 3.0.1, and 3.1.0; ActiveMatrix Service Bus 3.0.0 and 3.0.1; ActiveMatrix BusinessWorks Service Engine 5.9.0; ActiveMatrix BPM 1.0.1 and 1.0.2; Silver BPM Service 1.0.1; and Silver CAP Service 1.0.0 allows remote… | |
| Modificada | Media (6.9) | 0.30% | — | Nordugrid-arc | 8/12/2010 | 16/6/2026 | Untrusted search path vulnerability in NorduGrid Advanced Resource Connector (ARC) before 0.8.3 allows local users to gain privileges via vectors related to the LD_LIBRARY_PATH environment variable. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (10) | 4.5% | — | Tibco Activematrix Businessworks Service EngineTibco Activematrix Service BUSTibco Activematrix Service GridTibco Activematrix Service Performance Manager | 26/10/2010 | 16/6/2026 | The (1) ActiveMatrix Runtime and (2) ActiveMatrix Administrator components in TIBCO ActiveMatrix Service Grid before 2.3.1, ActiveMatrix Service Bus before 2.3.1, ActiveMatrix BusinessWorks Service Engine before 5.8.1, and ActiveMatrix Service Performance Manager before 1.3.2 do not properly handle JMX connections,… | |
| Modificada | Alta (7.5) | 2.6% | — | Oracle Database ServerOracle Fusion MiddlewareOracle Enterprise Manager Grid Control | 14/10/2010 | 16/6/2026 | Unspecified vulnerability in the Database Control component in EM Console in Oracle Database Server 10.1.0.5 and 10.2.0.3, Oracle Fusion Middleware 10.1.2.3 and 10.1.4.3, and Enterprise Manager Grid Control allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. | |
| Modificada | Media (4.3) | 0.90% | — | Oracle Enterprise Manager Grid Control | 13/7/2010 | 16/6/2026 | Unspecified vulnerability in the Console component in Oracle Enterprise Manager Grid Control 10.1.0.6 and 10.2.0.5 allows remote attackers to affect integrity via unknown vectors. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Toolsjx COM Grid | 6/5/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Table JX (com_grid) component for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) data_search and (2) rpp parameters to index.php. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Grid2000 Flexcell Grid Control | 27/1/2009 | 16/6/2026 | Multiple insecure method vulnerabilities in the FlexCell.Grid ActiveX control (FlexCell.ocx) in FlexCell Grid Control 5.6.9 allow remote attackers to create and overwrite arbitrary files via the (1) SaveFile and (2) ExportToXML methods. | |
| Modificada | Alta (9.3) | 8.9% | 💥 Exploit | Share2 Easy Grid Control | 16/1/2009 | 16/6/2026 | Insecure method vulnerability in the EasyGrid.SGCtrl.32 ActiveX control in EasyGrid.ocx 1.0.0.1 in AAA EasyGrid ActiveX 3.51 allows remote attackers to create and overwrite arbitrary files via the (1) DoSaveFile or (2) DoSaveHtmlFile method. NOTE: vector 1 could be leveraged for code execution by creating executable… | |
| Modificada | Media (5.5) | 1.5% | — | Oracle Enterprise Manager Grid Control 10G | 14/1/2009 | 16/6/2026 | Unspecified vulnerability in the Oracle Enterprise Manager component in Oracle Enterprise Manager 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors. | |
| Modificada | Media (5) | 1.2% | — | SUN Grid Engine | 7/1/2009 | 16/6/2026 | Sun GridEngine 5.3 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077. | |
| Modificada | Alta (10) | 3.9% | — | Grid2000 Flexcell Grid Control | 10/12/2008 | 16/6/2026 | Insecure method vulnerability in the FlexCell.Grid ActiveX control in FlexCell.ocx 5.7.0.1 in FlexCell Grid ActiveX Component allows remote attackers to create and overwrite arbitrary files via the HttpDownloadFile method. NOTE: this could be leveraged for code execution by creating executable files in Startup folders… | |
| Modificada | Alta (9.3) | 4.1% | — | Componentone Vsflexgrid | 19/9/2008 | 16/6/2026 | Stack-based buffer overflow in the VSFlexGrid.VSFlexGridL ActiveX control in ComponentOne VSFlexGrid 7.0.1.151 and 8.0.20072.239 allows remote attackers to execute arbitrary code via a long first argument to the Archive method. NOTE: the provenance of this information is unknown; the details are obtained solely from… | |
| Modificada | Media (4.9) | 0.34% | — | SUN N1 Grid Engine | 11/4/2008 | 16/6/2026 | Unspecified vulnerability in the Qmaster daemon in Sun N1 Grid Engine 6.1 allows local users to cause a denial of service (daemon crash) via unspecified vectors. | |
| Modificada | Media (6.8) | 3.5% | 💥 Exploit | Componentone Flexgrid | 20/11/2007 | 16/6/2026 | Multiple stack-based buffer overflows in the VSFlexGrid.VSFlexGridL ActiveX control in ComponentOne FlexGrid 7.1 Light allow remote attackers to cause a denial of service and possibly execute arbitrary code via a long string in the (1) Text, (2) EditSelText, (3) EditText, and (4) CellFontName property values. | |
| Modificada | Media (4.3) | 1.6% | — | Pear Structures Datagrid Datasource Mdb2 | 13/11/2007 | 16/6/2026 | The LOB functionality in PEAR MDB2 before 2.5.0a1 interprets a request to store a URL string as a request to retrieve and store the contents of the URL, which might allow remote attackers to use MDB2 as an indirect proxy or obtain sensitive information via a URL into a form field in an MDB2 application, as… | |
| Modificada | Alta (10) | 7.7% | — | Oracle Enterprise Grid Console ServerOracle Opmn Daemon | 18/10/2007 | 16/6/2026 | Format string vulnerability in the logging function in the Oracle OPMN daemon, as used on Oracle Enterprise Grid Console server 10.2.0.1, allows remote attackers to execute arbitrary code via format string specifiers in the URI in an HTTP request to port 6003, aka Oracle reference number 6296175. NOTE: this might be… | |
| Modificada | Media (5) | 0.98% | — | Pear Structures Datagrid Datasource Mdb2 | 9/7/2007 | 16/6/2026 | Unspecified vulnerability in the fetch function in MDB2.php in PEAR Structures-DataGrid-DataSource-MDB2 0.1.9 and earlier allows attackers to "manipulate the generated sorting queries." | |
| Modificada | Media (4.3) | 1.0% | — | Bitego Bosdatagrid | 26/6/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in bosDataGrid 2.50 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) GridSearch, (2) gsearch, or (3) ParentID parameter to an unspecified component. | |
| Modificada | Alta (7.5) | 3.9% | — | SUN N1 Grid Engine | 31/7/2006 | 16/6/2026 | Unspecified vulnerability in the daemons for Sun N1 Grid Engine 5.3 and N1 Grid Engine 6.0 allows local users to cause a denial of service (grid service shutdown) and possibly execute arbitrary code using buffer overflows via unknown vectors that cause (1) qmaster or (2) execd to terminate. | |
| Modificada | Media (4.6) | 0.24% | — | SUN Grid EngineSUN N1 Grid Engine | 9/6/2006 | 16/6/2026 | Unspecified vulnerability in Sun Grid Engine 5.3 and Sun N1 Grid Engine 6.0, when configured in Certificate Security Protocol (CSP) Mode, allows local users to shut down the grid service or gain access, even if access is denied. | |
| Modificada | Alta (10) | 4.6% | — | Jdedwards Enterpriseone ToolsOneworld ToolsOracle Application ServerOracle Collaboration Suite+8 | 20/4/2006 | 16/6/2026 | Unspecified vulnerability in the Oracle Thesaurus Management System component in Oracle E-Business Suite and OPA 4.5.2 Applications has unknown impact and attack vectors, aka Vuln# OPA01. | |
| Modificada | Alta (7.2) | 0.39% | — | SUN Grid EngineSUN N1 Grid Engine | 30/3/2006 | 16/6/2026 | Unspecified vulnerability in rsh in Sun Microsystems Sun Grid Engine 5.3 before 20060327 and N1 Grid Engine 6.0 before 20060327 allows local users to gain root privileges. | |
| Modificada | Alta (7.5) | 4.8% | — | Oracle 10G Enterprise Manager Grid ControlOracle Application ServerOracle Collaboration SuiteOracle Database Server+8 | 4/2/2006 | 16/6/2026 | Unspecified vulnerability in the Net Listener component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, and 9.2.0.7 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB11. |