Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

113 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)3.6%—Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow AutomationNetapp Snapcenter+318/7/201817/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client mysqldump). Supported versions that are affected are 5.5.60 and prior, 5.6.40 and prior and 5.7.22 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL…
ModificadaMedia (4.9)1.9%—Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow AutomationNetapp Snapcenter+118/7/201817/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 8.0.11 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this…
ModificadaBaja (3.3)1.9%—Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow AutomationNetapp Snapcenter+718/7/201817/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Options). Supported versions that are affected are 5.5.60 and prior, 5.6.40 and prior and 5.7.22 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise…
ModificadaMedia (6.5)3.6%—Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow AutomationNetapp Snapcenter+218/7/201817/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are affected are 5.7.22 and prior and 8.0.11 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful…
ModificadaAlta (7.1)3.1%—Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow AutomationNetapp Snapcenter+418/7/201817/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.6.40 and prior, 5.7.22 and prior and 8.0.11 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.…
ModificadaMedia (5.3)3.0%—Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow AutomationNetapp Snapcenter+218/7/201817/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Memcached). Supported versions that are affected are 5.6.40 and prior, 5.7.22 and prior and 8.0.11 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via memcached to compromise MySQL…
ModificadaMedia (4.9)2.9%—Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow AutomationNetapp Snapcenter+218/7/201817/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are affected are 5.7.22 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this…
ModificadaMedia (6.5)2.9%—Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow AutomationNetapp Snapcenter+318/7/201817/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.22 and prior and 8.0.11 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks…
ModificadaMedia (4.3)2.4%—Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow AutomationNetapp Snapcenter+718/7/201817/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: MyISAM). Supported versions that are affected are 5.5.60 and prior, 5.6.40 and prior and 5.7.22 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.…
ModificadaMedia (4.3)2.5%—Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow AutomationNetapp Snapcenter+218/7/201817/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 5.7.22 and prior and 8.0.11 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL…
ModificadaMedia (4.9)3.4%—Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow AutomationNetapp Snapcenter+218/7/201817/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.7.22 and prior and 8.0.11 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful…
ModificadaMedia (5.5)9.0%—Apache SolrNetapp SnapcenterNetapp Storage Automation Store5/7/201817/6/2026
This vulnerability in Apache Solr 6.0.0 to 6.6.4 and 7.0.0 to 7.3.1 relates to an XML external entity expansion (XXE) in Solr config files (currency.xml, enumsConfig.xml referred from schema.xml, TIKA parsecontext config file). In addition, Xinclude functionality provided in these config files is also affected in a…
ModificadaCrítica (9.8)6.7%—PHPCanonical Ubuntu LinuxNetapp Storage Automation Store26/6/201817/6/2026
exif_read_from_impl in ext/exif/exif.c in PHP 7.2.x through 7.2.7 allows attackers to trigger a use-after-free (in exif_read_from_file) because it closes a stream that it is not responsible for closing. The vulnerable code is reachable through the PHP exif_read_data function.
ModificadaAlta (7.5)17%—Apache Http ServerRedhat Jboss Core ServicesCanonical Ubuntu LinuxNetapp Cloud Backup+118/6/201817/6/2026
By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.18-2.4.30,2.4.33).
ModificadaCrítica (9.8)21%—Apache TomcatCanonical Ubuntu LinuxDebian LinuxNetapp Oncommand Insight+416/5/201817/6/2026
The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather…
ModificadaAlta (8.8)2.5%—Pivotal Software Spring SecurityVmware Spring FrameworkOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+3811/5/201825/8/2026
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
ModificadaAlta (8.8)7.0%—PHPCanonical Ubuntu LinuxDebian LinuxNetapp Storage Automation Store29/4/201817/6/2026
An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. exif_read_data in ext/exif/exif.c has an out-of-bounds read for crafted JPEG data because exif_iif_add_value mishandles the case of a MakerNote that lacks a final '\0' character.
ModificadaAlta (7.5)8.5%—PHPCanonical Ubuntu LinuxDebian LinuxNetapp Storage Automation Store29/4/201817/6/2026
An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. ext/ldap/ldap.c allows remote LDAP servers to cause a denial of service (NULL pointer dereference and application crash) because of mishandling of the ldap_get_dn return value.
ModificadaMedia (6.1)3.5%—PHPCanonical Ubuntu LinuxDebian LinuxNetapp Storage Automation Store29/4/201817/6/2026
An issue was discovered in ext/phar/phar_object.c in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. There is Reflected XSS on the PHAR 403 and 404 error pages via request data of a request for a .phar file. NOTE: this vulnerability exists because of an incomplete fix for…
ModificadaAlta (7.5)10.0%💥 PoCPHPCanonical Ubuntu LinuxDebian LinuxNetapp Storage Automation Store29/4/201817/6/2026
An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. An infinite loop exists in ext/iconv/iconv.c because the iconv stream filter does not reject invalid multibyte sequences.
ModificadaMedia (4.7)0.80%—PHPCanonical Ubuntu LinuxDebian LinuxNetapp Storage Automation Store29/4/201817/6/2026
An issue was discovered in PHP before 5.6.35, 7.0.x before 7.0.29, 7.1.x before 7.1.16, and 7.2.x before 7.2.4. Dumpable FPM child processes allow bypassing opcache access controls because fpm_unix.c makes a PR_SET_DUMPABLE prctl call, allowing one user (in a multiuser environment) to obtain sensitive information from…
ModificadaMedia (4.9)2.8%—Oracle MysqlCanonical Ubuntu LinuxNetapp Oncommand InsightNetapp Oncommand Unified Manager+319/4/201817/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Performance Schema). Supported versions that are affected are 5.7.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks…
ModificadaMedia (4.9)2.8%—Oracle MysqlCanonical Ubuntu LinuxNetapp Oncommand InsightNetapp Oncommand Unified Manager+319/4/201817/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are affected are 5.7.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this…
ModificadaMedia (4.9)3.5%—Oracle MysqlCanonical Ubuntu LinuxDebian LinuxNetapp Oncommand Insight+419/4/201817/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Security : Privileges). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to…
ModificadaMedia (4.9)2.8%—Oracle MysqlCanonical Ubuntu LinuxNetapp Oncommand InsightNetapp Oncommand Unified Manager+319/4/201817/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.7.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this…