Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
113 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 3.7% | — | Oracle MysqlCanonical Ubuntu LinuxDebian LinuxNetapp Oncommand Insight+5 | 17/10/2018 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.… | |
| Modificada | Alta (7.7) | 3.7% | — | Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Unified ManagerNetapp Oncommand Workflow Automation+3 | 17/10/2018 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. While the… | |
| Modificada | Media (6.5) | 2.5% | — | Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Unified ManagerNetapp Oncommand Workflow Automation+2 | 17/10/2018 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (5.9) | 4.4% | — | Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Unified ManagerNetapp Oncommand Workflow Automation+3 | 17/10/2018 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Audit). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server.… | |
| Modificada | Media (6.5) | 3.7% | — | Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Unified ManagerNetapp Oncommand Workflow Automation+5 | 17/10/2018 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.6.41 and prior, 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.… | |
| Modificada | Media (6.5) | 2.2% | — | Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Unified ManagerNetapp Oncommand Workflow Automation+2 | 17/10/2018 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (5.9) | 51% | — | Apache Http ServerCanonical Ubuntu LinuxRedhat Enterprise LinuxOracle Enterprise Manager OPS Center+5 | 25/9/2018 | 17/6/2026 | In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2 connections. A possible mitigation is to not enable the h2 protocol. | |
| Modificada | Media (6.1) | 4.1% | 💥 Exploit | PHPDebian LinuxNetapp Storage Automation Store | 16/9/2018 | 17/6/2026 | The Apache2 component in PHP before 5.6.38, 7.0.x before 7.0.32, 7.1.x before 7.1.22, and 7.2.x before 7.2.10 allows XSS via the body of a "Transfer-Encoding: chunked" request, because the bucket brigade is mishandled in the php_handler function in sapi/apache2handler/sapi_apache2.c. | |
| Modificada | Alta (7.5) | 5.1% | — | PHPNetapp Storage Automation Store | 7/8/2018 | 17/6/2026 | An issue was discovered in ext/standard/link_win32.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. The linkinfo function on Windows doesn't implement the open_basedir check. This could be abused to find files on paths outside of the allowed directories. | |
| Modificada | Alta (7.5) | 3.2% | — | PHPNetapp Storage Automation Store | 3/8/2018 | 17/6/2026 | An issue was discovered in PHP 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. Inappropriately parsing an HTTP response leads to a segmentation fault because http_header_value in ext/standard/http_fopen_wrapper.c can be a NULL value that is mishandled in an atoi call. | |
| Modificada | Alta (7.5) | 9.0% | — | PHPCanonical Ubuntu LinuxDebian LinuxNetapp Storage Automation Store | 3/8/2018 | 17/6/2026 | An issue was discovered in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. An Integer Overflow leads to a heap-based buffer over-read in exif_thumbnail_extract of exif.c. | |
| Modificada | Media (5.5) | 4.3% | — | PHPCanonical Ubuntu LinuxDebian LinuxNetapp Storage Automation Store | 2/8/2018 | 17/6/2026 | exif_process_IFD_in_MAKERNOTE in ext/exif/exif.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG file. | |
| Modificada | Crítica (9.8) | 7.6% | — | PHPNetapp Storage Automation Store | 2/8/2018 | 17/6/2026 | PHP 7.x through 7.1.5 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a long string because of an Integer overflow in mysqli_real_escape_string. | |
| Modificada | Alta (7.5) | 3.0% | — | PHPNetapp Storage Automation Store | 2/8/2018 | 17/6/2026 | PHP 7.1.5 has an Out of bounds access in php_pcre_replace_impl via a crafted preg_replace call. | |
| Modificada | Baja (2.8) | 0.42% | — | Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow AutomationNetapp Snapcenter+1 | 18/7/2018 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Shell: Core / Client). Supported versions that are affected are 8.0.11 and prior. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server.… | |
| Modificada | Baja (2.7) | 1.3% | — | Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow AutomationNetapp Snapcenter+1 | 18/7/2018 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 8.0.11 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (5) | 2.7% | — | Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow AutomationNetapp Snapcenter+7 | 18/7/2018 | 17/6/2026 | Vulnerability in the MySQL Client component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.60 and prior, 5.6.40 and prior, 5.7.22 and prior and 8.0.11 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols… | |
| Modificada | Media (4.9) | 1.9% | — | Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow AutomationNetapp Snapcenter+1 | 18/7/2018 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 8.0.11 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (4.9) | 1.9% | — | Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow AutomationNetapp Snapcenter+1 | 18/7/2018 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 8.0.11 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability… | |
| Modificada | Media (4.9) | 1.9% | — | Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow AutomationNetapp Snapcenter+1 | 18/7/2018 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 8.0.11 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (4.9) | 3.4% | — | Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow AutomationNetapp Snapcenter+2 | 18/7/2018 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.7.22 and prior and 8.0.11 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful… | |
| Modificada | Media (4.9) | 1.9% | — | Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow AutomationNetapp Snapcenter+1 | 18/7/2018 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 8.0.11 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks… | |
| Modificada | Media (5.3) | 1.8% | — | Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow AutomationNetapp Snapcenter+1 | 18/7/2018 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Roles). Supported versions that are affected are 8.0.11 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of… | |
| Modificada | Media (6.5) | 2.0% | — | Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow AutomationNetapp Snapcenter+1 | 18/7/2018 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.11 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (4.9) | 2.9% | — | Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow AutomationNetapp Snapcenter+2 | 18/7/2018 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Audit Log). Supported versions that are affected are 5.7.22 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… |