Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

3145 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.1)2.0%—Oracle MysqlCanonical Ubuntu LinuxNetapp Oncommand Unified ManagerNetapp Oncommand Workflow Automation+716/1/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise…
ModificadaMedia (6.5)1.6%—Oracle MysqlNetapp Oncommand Unified ManagerNetapp Oncommand Workflow AutomationNetapp Snapcenter+616/1/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Security : Privileges). Supported versions that are affected are 8.0.13 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful…
ModificadaMedia (4.9)3.1%—Oracle MysqlNetapp Oncommand Unified ManagerNetapp Oncommand Workflow AutomationNetapp Snapcenter+716/1/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL…
ModificadaMedia (4.9)3.2%—Oracle MysqlNetapp Oncommand Unified ManagerNetapp Oncommand Workflow AutomationNetapp Snapcenter+716/1/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise…
ModificadaMedia (4.9)2.6%—Oracle MysqlNetapp Oncommand Unified ManagerNetapp Oncommand Workflow AutomationNetapp Snapcenter+616/1/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this…
ModificadaMedia (6.5)4.6%—Oracle MysqlDebian LinuxCanonical Ubuntu LinuxNetapp Oncommand Unified Manager+1116/1/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL…
ModificadaMedia (4.9)3.4%—Oracle MysqlMariadbRedhat Enterprise LinuxRedhat Enterprise Linux EUS+716/1/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks…
ModificadaMedia (6.4)2.5%—Oracle MysqlMariadbNetapp Active IQ Unified ManagerNetapp Oncommand Insight+916/1/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Connection Handling). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Difficult to exploit vulnerability allows low privileged attacker with access to the physical communication segment…
ModificadaMedia (4.9)3.4%—Oracle MysqlCanonical Ubuntu LinuxNetapp Oncommand InsightNetapp Oncommand Unified Manager+716/1/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise…
ModificadaMedia (6.5)3.9%—Oracle MysqlCanonical Ubuntu LinuxMariadbNetapp Active IQ Unified Manager+916/1/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL…
ModificadaBaja (3.1)3.0%—Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux+716/1/201917/6/2026
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). The supported version that is affected is Java SE: 8u192. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human…
ModificadaMedia (5.5)2.1%—Oracle MysqlNetapp Oncommand Unified ManagerNetapp Oncommand Workflow AutomationNetapp Snapcenter+616/1/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this…
ModificadaMedia (6.5)3.3%—Oracle MysqlCanonical Ubuntu LinuxNetapp Oncommand Unified ManagerNetapp Oncommand Workflow Automation+716/1/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supported versions that are affected are 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful…
ModificadaBaja (3.1)3.4%—Oracle JDKOracle JRECanonical Ubuntu LinuxNetapp Oncommand Unified Manager+1416/1/201917/6/2026
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u201, 8u192 and 11.0.1; Java SE Embedded: 8u191. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE.…
ModificadaMedia (4.9)3.1%—Oracle MysqlCanonical Ubuntu LinuxNetapp Oncommand Unified ManagerNetapp Oncommand Workflow Automation+716/1/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.…
ModificadaMedia (5.7)0.49%—Redhat CephDebian LinuxOpensuse LeapRedhat Ceph Storage+215/1/201917/6/2026
It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt encryption keys used in ceph disk encryption.
ModificadaMedia (6.5)2.1%—Redhat CephDebian LinuxOpensuse LeapRedhat Ceph Storage+215/1/201917/6/2026
It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users can cause a denial of service against OMAPs holding bucket indices.
ModificadaAlta (8.1)4.0%—EtcdRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+114/1/201917/6/2026
etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-based access control (RBAC) is used and client-cert-auth is enabled. If an etcd client server TLS certificate contains a Common Name (CN) which matches a valid RBAC username, a remote attacker may…
ModificadaMedia (4.9)2.2%—Docker EngineRedhat Enterprise Linux Server12/1/201917/6/2026
Docker Engine before 18.09 allows attackers to cause a denial of service (dockerd memory consumption) via a large integer in a --cpuset-mems or --cpuset-cpus value, related to daemon/daemon_unix.go, pkg/parsers/parsers.go, and pkg/sysinfo/sysinfo.go.
ModificadaAlta (7.8)3.0%—Systemd Project SystemdRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+711/1/201917/6/2026
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when many entries are sent to the journal socket. A local attacker, or a remote one if systemd-journal-remote is used, may use this flaw to crash systemd-journald or execute…
ModificadaAlta (7.8)0.71%—Systemd Project SystemdRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+711/1/201917/6/2026
An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a program with long command line arguments calls syslog. A local attacker may use this flaw to crash systemd-journald or escalate his privileges. Versions through v240 are…
ModificadaBaja (3.3)1.1%—Systemd Project SystemdDebian LinuxCanonical Ubuntu LinuxNetapp Active IQ Performance Analytics Services+1711/1/201917/6/2026
An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions from v221 to v239 are vulnerable.
ModificadaMedia (6.7)0.45%—Polkit Project PolkitDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+511/1/201917/6/2026
In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. This is related to lack of uid checking in polkitbackend/polkitbackendinteractiveauthority.c.
ModificadaMedia (5.3)3.7%—Openbsd OpensshWinscpNetapp Cloud BackupNetapp Element Software+1810/1/201917/6/2026
In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.
ModificadaMedia (6.5)1.2%—Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+19/1/201917/6/2026
Insufficient enforcement of file access permission in the activeTab case in Extensions in Google Chrome prior to 68.0.3440.75 allowed an attacker who convinced a user to install a malicious extension to access files on the local file system via a crafted Chrome Extension.