Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2584▼ 301 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

668 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)1.0%—Microsoft SQL Server 2017Microsoft SQL Server 2019Microsoft SQL Server 2022Microsoft SQL Server 20258/9/202615/9/2026
Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (8.8)0.99%—Microsoft SQL Server 2017Microsoft SQL Server 2019Microsoft SQL Server 2022Microsoft SQL Server 20258/9/202616/9/2026
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (8.8)0.99%—Microsoft SQL Server 2017Microsoft SQL Server 2019Microsoft SQL Server 2022Microsoft SQL Server 20258/9/202616/9/2026
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (8.8)0.78%—Microsoft SQL Server 2017Microsoft SQL Server 2019Microsoft SQL Server 2022Microsoft SQL Server 20258/9/202616/9/2026
Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network.
AnalizadaMedia (6.5)1.00%—Microsoft SQL Server 2022Microsoft SQL Server 20258/9/202616/9/2026
Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network.
AnalizadaAlta (8.8)0.78%—Microsoft SQL Server 2017Microsoft SQL Server 2019Microsoft SQL Server 2022Microsoft SQL Server 20258/9/202616/9/2026
Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Pendiente de análisisCrítica (9.6)0.88%—Microsoft SQL ServerAI8/9/20269/9/2026
Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network.
AnalizadaAlta (8.8)0.82%—Microsoft SQL Server 2017Microsoft SQL Server 20198/9/202623/9/2026
Heap-based buffer overflow in Windows OLE DB allows an unauthorized attacker to execute code over a network.
En análisisMedia (6.5)0.92%—Microsoft SQL Server 2017Microsoft SQL Server 20198/9/202623/9/2026
Out-of-bounds read in Windows OLE DB allows an unauthorized attacker to disclose information over a network.
AnalizadaMedia (6.5)0.92%—Microsoft SQL Server 2017Microsoft SQL Server 20198/9/20262/10/2026
Out-of-bounds read in SQL Server allows an unauthorized attacker to disclose information over a network.
AnalizadaMedia (6.5)1.00%—Microsoft SQL Server 2017Microsoft SQL Server 2019Microsoft SQL Server 2022Microsoft SQL Server 20258/9/20262/10/2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
AnalizadaMedia (6.5)1.00%—Microsoft SQL Server 2017Microsoft SQL Server 2019Microsoft SQL Server 2022Microsoft SQL Server 20258/9/20262/10/2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
AnalizadaMedia (6.5)1.00%—Microsoft SQL Server 2019Microsoft SQL Server 2022Microsoft SQL Server 20258/9/20262/10/2026
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
AnalizadaAlta (8.1)1.1%—Microsoft SQL Server 2019Microsoft SQL Server 2022Microsoft SQL Server 20258/9/20262/10/2026
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
Pendiente de análisisMedia (6.5)0.40%—GrafanaAIMicrosoft SQL ServerAIPostgresqlAIMysqlAI2/9/20263/9/2026
An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the timeGroup macro through a WHERE clause, which Grafana's regex-based macro parsing does not reject. Evaluating the injected macro causes uncontrolled memory consumption that can terminate the Grafana…
AplazadaAlta (8.7)0.74%—Microsoft SQL ServerAIHrp2000 E-hrAI13/8/20261/10/2026
Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attackers to access protected resources by supplying a path traversal sequence in the request URI to bypass the oauthservlet authentication filter. Attackers can inject…
AnalizadaMedia (4.9)0.45%—Oracle Mysql ServerOracle Mysql Cluster21/7/202627/7/2026
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to…
AnalizadaMedia (4.9)0.45%—Oracle Mysql ServerOracle Mysql Cluster21/7/202627/7/2026
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to…
AnalizadaMedia (6.5)0.42%—Oracle Mysql ServerOracle Mysql Cluster21/7/202627/7/2026
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: JSON). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network…
AnalizadaMedia (6.5)0.42%—Oracle Mysql ServerOracle Mysql Cluster21/7/202627/7/2026
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: GIS). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise…
AnalizadaBaja (2.9)0.14%—Oracle Mysql ServerOracle Mysql Cluster21/7/202627/7/2026
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Pluggable Auth). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows unauthenticated attacker…
AnalizadaAlta (7.2)0.49%—Oracle Mysql ServerOracle Mysql Cluster21/7/202628/7/2026
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with…
AnalizadaMedia (6.5)0.42%—Oracle Mysql ServerOracle Mysql Cluster21/7/202627/7/2026
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are MySQL Server: 9.7.0-9.7.1; MySQL Cluster: 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to…
AnalizadaBaja (2.7)0.32%—Oracle Mysql ServerOracle Mysql Cluster21/7/202627/7/2026
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Performance Schema). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker…
AnalizadaMedia (6.2)0.17%—Oracle Mysql ServerOracle Mysql Cluster21/7/202627/7/2026
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with…