Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

70 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.60%—Microsoft Odbc Driver FOR SQL ServerMicrosoft SQL Server16/6/202317/6/2026
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
ModificadaAlta (7.8)0.60%—Microsoft Odbc Driver FOR SQL ServerMicrosoft OLE DB Driver FOR SQL ServerMicrosoft SQL Server16/6/202317/6/2026
Microsoft ODBC and OLE DB Remote Code Execution Vulnerability
ModificadaCrítica (9.8)1.6%—Progress Datadirect Odbc Oracle Wire Protocol Driver9/6/202317/6/2026
A buffer overflow was discovered in Progress DataDirect Connect for ODBC before 08.02.2770 for Oracle. An overly large value for certain options of a connection string may overrun the buffer allocated to process the string value. This allows an attacker to execute code of their choice on an affected host by copying…
ModificadaMedia (5.9)0.32%—Progress Datadirect Odbc Oracle Wire Protocol Driver9/6/202317/6/2026
An issue was discovered in Progress DataDirect Connect for ODBC before 08.02.2770 for Oracle. When using Oracle Advanced Security (OAS) encryption, if an error is encountered initializing the encryption object used to encrypt data, the code falls back to a different encryption mechanism that uses an insecure random…
ModificadaAlta (7.8)0.82%—Microsoft OdbcMicrosoft OLE DB11/4/202317/6/2026
Microsoft ODBC and OLE DB Remote Code Execution Vulnerability
ModificadaAlta (7.8)0.69%—Microsoft OdbcMicrosoft OLE DB11/4/202317/6/2026
Microsoft ODBC and OLE DB Remote Code Execution Vulnerability
ModificadaAlta (7.8)3.7%—Insightsoftware Magnitude Simba Amazon Redshift Odbc Driver9/5/202217/6/2026
An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift ODBC Driver (1.4.14 through 1.4.21.1001 and 1.4.22 through 1.4.x before 1.4.52) may allow a local user to execute arbitrary code.
ModificadaAlta (7.8)0.37%—Insightsoftware Magnitude Simba Amazon Athena Odbc Driver9/5/202217/6/2026
An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Athena ODBC Driver 1.1.1 through 1.1.x before 1.1.17 may allow a local user to execute arbitrary code.
ModificadaAlta (7)0.31%—Opensuse Backports SLEFedoraproject FedoraSqliteodbc Project Sqliteodbc30/4/202017/6/2026
SQLiteODBC 0.9996, as packaged for certain Linux distributions as 0.9996-4, has a race condition leading to root privilege escalation because any user can replace a /tmp/sqliteodbc$$ file with new contents that cause loading of an arbitrary library.
ModificadaAlta (7.8)0.45%—UnixodbcDebian LinuxOpensuseRedhat Enterprise Linux14/11/201916/6/2026
The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string.
ModificadaCrítica (9.8)1.8%—SAP Maxdb Odbc Driver9/5/201817/6/2026
SAP MaxDB ODBC driver (all versions before 7.9.09.07) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
ModificadaCrítica (9.8)3.0%—Unixodbc26/2/201817/6/2026
The SQLWriteFileDSN function in odbcinst/SQLWriteFileDSN.c in unixODBC 2.3.5 has strncpy arguments in the wrong order, which allows attackers to cause a denial of service or possibly have unspecified other impact.
ModificadaCrítica (9.8)2.5%—Unixodbc22/2/201817/6/2026
In unixODBC before 2.3.5, there is a buffer overflow in the unicode_to_ansi_copy() function in DriverManager/__info.c.
ModificadaAlta (7.3)1.5%💥 ExploitIBM Data Server ClientIBM Data Server Driver FOR Odbc AND CLIIBM Data Server Driver PackageIBM Data Server Runtime Client+227/6/201717/6/2026
IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a stack-based buffer overflow, caused by improper bounds checking which could allow a local attacker to execute arbitrary code. IBM X-Force ID: 125159.
ModificadaAlta (7.1)0.37%—IBM Data Server ClientIBM Data Server Driver FOR Odbc AND CLIIBM Data Server Driver PackageIBM Data Server Runtime Client+227/6/201717/6/2026
IBM DB2 for Linux, UNIX and Windows 9.2, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) is vulnerable to a buffer overflow that could allow a local user to overwrite DB2 files or cause a denial of service. IBM X-Force ID: 120668.
ModificadaBaja (2.1)0.51%—Unixodbc31/8/201216/6/2026
Buffer overflow in the SQLDriverConnect function in unixODBC 2.3.1 allows local users to cause a denial of service (crash) via a long string in the DRIVER option. NOTE: this issue might not be a vulnerability, since the ability to set this option typically implies that the attacker already has legitimate access to…
ModificadaBaja (2.1)0.44%—Unixodbc31/8/201216/6/2026
Buffer overflow in the SQLDriverConnect function in unixODBC 2.0.10, 2.3.1, and earlier allows local users to cause a denial of service (crash) via a long string in the FILEDSN option. NOTE: this issue might not be a vulnerability, since the ability to set this option typically implies that the attacker already has…
ModificadaAlta (7.8)1.3%—Myodbc23/1/200716/6/2026
MyODBC Japanese conversion edition 3.51.06, 2.50.29, and 2.50.25 allows remote attackers to cause a denial of service via a certain string in a response, which has unspecified impact on the MySQL database.
ModificadaAlta (7.2)0.40%—Gentoo Qt-unixodbc16/12/200516/6/2026
Untrusted search path vulnerability in Qt-UnixODBC before 3.3.4-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a malicious shared object in the Portage temporary build directory, which is part of the RUNPATH.
ModificadaMedia (5)1.5%—Kunani Odbc FTP Server31/12/200216/6/2026
Directory traversal vulnerability in the Kunani ODBC FTP Server 1.0.10 allows remote attackers to read arbitrary files via a "..\" (dot dot backslash) in a GET request.
Orbitaley — Vulnerabilidades