Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

100 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.60%—Microsoft Odbc Driver FOR SQL ServerMicrosoft SQL Server16/6/202317/6/2026
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
ModificadaAlta (7.8)0.60%—Microsoft Odbc Driver FOR SQL ServerMicrosoft SQL Server16/6/202317/6/2026
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
ModificadaAlta (7.8)0.60%—Microsoft Odbc Driver FOR SQL ServerMicrosoft OLE DB Driver FOR SQL ServerMicrosoft SQL Server16/6/202317/6/2026
Microsoft ODBC and OLE DB Remote Code Execution Vulnerability
ModificadaMedia (5.5)0.49%—Postgresql Jdbc DriverDebian Linux23/11/202217/6/2026
pgjdbc is an open source postgresql JDBC Driver. In affected versions a prepared statement using either `PreparedStatement.setText(int, InputStream)` or `PreparedStatemet.setBytea(int, InputStream)` will create a temporary file if the InputStream is larger than 2k. This will create a temporary file which is readable…
ModificadaAlta (8)2.2%—Postgresql Jdbc DriverDebian LinuxFedoraproject Fedora3/8/202217/6/2026
PostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to connect to a PostgreSQL database using standard, database independent Java code. The PGJDBC implementation of the `java.sql.ResultRow.refreshRow()` method is not performing escaping of column names so a malicious column name that contains a statement…
ModificadaAlta (7.8)0.48%—Insightsoftware Magnitude Simba Amazon Redshift Jdbc Driver9/5/202217/6/2026
An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift JDBC Driver 1.2.40 through 1.2.55 may allow a local user to execute code. NOTE: this is different from CVE-2022-29972.
ModificadaAlta (7.8)0.48%—Insightsoftware Magnitude Simba Amazon Athena Jdbc Driver9/5/202217/6/2026
An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Athena JDBC Driver 2.0.25 through 2.0.28 may allow a local user to execute code. NOTE: this is different from CVE-2022-29971.
ModificadaAlta (7.8)3.7%—Insightsoftware Magnitude Simba Amazon Redshift Odbc Driver9/5/202217/6/2026
An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift ODBC Driver (1.4.14 through 1.4.21.1001 and 1.4.22 through 1.4.x before 1.4.52) may allow a local user to execute arbitrary code.
ModificadaAlta (7.8)0.37%—Insightsoftware Magnitude Simba Amazon Athena Odbc Driver9/5/202217/6/2026
An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Athena ODBC Driver 1.1.1 through 1.1.x before 1.1.17 may allow a local user to execute arbitrary code.
ModificadaCrítica (9.8)3.0%—Postgresql Jdbc DriverDebian Linux10/3/202217/6/2026
In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary files through the loggerFile and loggerLevel connection properties. An example situation is that an attacker could create an executable JSP file under a Tomcat web root. NOTE: the…
ModificadaCrítica (9.8)3.1%—Postgresql Jdbc DriverFedoraproject FedoraQuarkusDebian Linux2/2/202217/6/2026
pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker control the jdbc url or properties. pgjdbc instantiates plugin instances based on class names provided…
ModificadaMedia (6.7)0.24%—Intel Ethernet Diagnostic Driver17/11/202117/6/2026
Improper input validation in the Intel(R) Ethernet Diagnostic Driver for Windows before version 1.4.0.10 may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaCrítica (9.8)5.2%—Siemens Simatic Driver Controller FirmwareSiemens S7-1200 CPU FirmwareSiemens S7-1500 CPU FirmwareSiemens Simatic S7-1500 Software Controller+228/5/202117/6/2026
A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V21.9), SIMATIC S7-1200 CPU family (incl. SIPLUS…
ModificadaAlta (7.7)4.1%—Postgresql Jdbc DriverQuarkusNetapp Steelstore Cloud Integrated StorageFedoraproject Fedora+14/6/202017/6/2026
PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE.
ModificadaMedia (5.5)1.2%—Whoopsie Project WhoopsieMongodb C Driver24/4/202017/6/2026
bson before 0.8 incorrectly uses int rather than size_t for many variables, parameters, and return values. In particular, the bson_ensure_space() parameter bytesNeeded could have an integer overflow via properly constructed bson input.
ModificadaAlta (7.8)4.4%💥 ExploitRicoh Generic Pcl5 DriverRicoh PC FAX Generic DriverRicoh Pcl6 (pcl XL) DriverRicoh Pcl6 Driver FOR Universal Print+424/1/202017/6/2026
An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attackers local privilege escalation. Affected drivers and versions are: PCL6 Driver for Universal Print - Version 4.0 or later PS Driver for Universal Print - Version 4.0 or later PC FAX Generic Driver -…
ModificadaAlta (8.3)3.3%—Broadcom Brcmfmac DriverRedhat Enterprise Linux16/1/202017/6/2026
The Broadcom brcmfmac WiFi driver prior to commit a4176ec356c73a46c07c181c6d04039fafa34a9f is vulnerable to a frame validation bypass. If the brcmfmac driver receives a firmware event frame from a remote source, the is_wlc_event_frame function will cause this frame to be discarded and unprocessed. If the driver…
ModificadaAlta (8.3)3.9%—Broadcom Brcmfmac DriverLinux Kernel16/1/202017/6/2026
The Broadcom brcmfmac WiFi driver prior to commit 1b5e2423164b3670e8bc9174e4762d297990deff is vulnerable to a heap buffer overflow. If the Wake-up on Wireless LAN functionality is configured, a malicious event frame can be constructed to trigger an heap buffer overflow in the brcmf_wowl_nd_results function. This…
ModificadaAlta (8.1)2.9%💥 PoCPostgresql Jdbc DriverRedhat Enterprise Linux30/8/201817/6/2026
A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check the host name if a host name verifier was not provided to the driver. This could lead to a condition where a man-in-the-middle attacker could masquerade as a trusted server by providing a certificate…
ModificadaCrítica (9.8)1.8%—SAP Maxdb Odbc Driver9/5/201817/6/2026
SAP MaxDB ODBC driver (all versions before 7.9.09.07) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
ModificadaAlta (7.8)2.4%—Ioserver OPC ServerIoserver OPC Drivers11/4/201417/6/2026
The Modbus slave/outstation driver in the OPC Drivers 1.0.20 and earlier in IOServer OPC Server allows remote attackers to cause a denial of service (out-of-bounds read and daemon crash) via a crafted packet.
ModificadaAlta (7.2)0.39%—Nvidia Unix Graphic Driver19/11/201216/6/2026
NVIDIA UNIX graphics driver before 295.71 and before 304.32 allows local users to write to arbitrary physical memory locations and gain privileges by modifying the VGA window using /dev/nvidia0.
ModificadaAlta (7.5)2.9%—PostgresqlPostgresql Jdbc Driver6/10/201216/6/2026
Interaction error in the PostgreSQL JDBC driver before 8.2, when used with a PostgreSQL server with the "standard_conforming_strings" option enabled, such as the default configuration of PostgreSQL 9.1, does not properly escape unspecified JDBC statement parameters, which allows remote attackers to perform SQL…
ModificadaMedia (6.8)0.43%—Realtek HD Audio Codec Drivers25/4/200816/6/2026
Realtek HD Audio Codec Drivers RTKVHDA.sys and RTKVHDA64.sys before 6.0.1.5605 on Windows Vista allow local users to create, write, and read registry keys via a crafted IOCTL request.
ModificadaMedia (6.8)0.52%—Realtek HD Audio Codec Drivers25/4/200816/6/2026
Integer overflow in Realtek HD Audio Codec Drivers RTKVHDA.sys and RTKVHDA64.sys before 6.0.1.5605 on Windows Vista allows local users to execute arbitrary code via a crafted IOCTL request.
Orbitaley — Vulnerabilidades