Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2685▼ 177 respecto a la semana anterior
Críticas / altas1223▼ 305 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 186 respecto a la semana anterior
–

1245 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)2.7%—Oracle Database Server20/4/200616/6/2026
Vulnerabilidad de inyección de Oracle Database Server 9.2.0.7 y 10.1.0.5 permite a atacantes remotos ejecutar órdenes SQL de su elección mediante la función DELETE_FROM_TALBE en el paquete DBMS_LOGMNGR_SESSION (Log Miner), tcc Vuln# DB06.
ModificadaAlta (7.5)5.3%—Oracle Database Server20/4/200616/6/2026
Vulnerabilidad no especificada en Oracle Database Server 9.0.1.5 y 9.2.0.7 con impacto y vectores de ataque desconocidos en el componente Oracle Enterprise Manager Intelligent Agent, tcc Vuln# DB07.
ModificadaAlta (10)4.8%—Oracle Database Server20/4/200616/6/2026
Vulnerabilidad no especificada en Oracle Database Server 9.2.0.6 con impacto y vectores de ataque desconocidos en el componente Advanced Replication (Replicación Avanzada), tcc Vuln# DB02.
ModificadaAlta (7.5)14%—Oracle Database Server20/4/200616/6/2026
Desbordamiento de búfer en el componente Advanced Replication en Oracle Database Server 10.1.0.4 permite a usuarios de la base de datos ejecutar código de su elección a través del procedimiento VERIFY_LOG del paquete DBMS_SNAPSHOT_UTL, también conocido como Vuln# DB03.
ModificadaAlta (10)4.6%—Jdedwards Enterpriseone ToolsOneworld ToolsOracle Application ServerOracle Collaboration Suite+820/4/200616/6/2026
Unspecified vulnerability in the Oracle Thesaurus Management System component in Oracle E-Business Suite and OPA 4.5.2 Applications has unknown impact and attack vectors, aka Vuln# OPA01.
ModificadaAlta (9)4.6%—Oracle Database Server20/4/200616/6/2026
Vulnerabilidad no especificada en Oracle Database Server 8.1.7.4, 9.0.1.5, 9.2.0.7, 10.1.0.5, y 10.2.0.2 con impacto y vectores de ataque desconocidos en el componente Export (Exportación), también conocido como Vuln# DB05. NOTA: los detalles son inasequibles desde Oracle, pero en fecha 27/04/2006, no han hecho…
ModificadaAlta (7.5)4.0%—Oracle Database Server20/4/200616/6/2026
Vulnerabilidad no especificada en Oracle Database Server 8.1.7.4, 9.0.1.5, y 9.2.0.6 con impacto y vectores de ataque desconocidos en el componente Oracle Spatial, tcc Vuln# DB09.
ModificadaAlta (9)4.6%—Oracle Database Server20/4/200616/6/2026
Vulnerabilidad no especificada en Oracle Database Server 9.2.0.7 and 10.1.0.4 tiene impacto y vectores de ataque desconocidos en el componente Oracle Spatial, tcc Vuln# DB12. NOTA: no hay detalles disponibles de Oracle, pero desde 20060521, no han disputado públicamente una queja de un investigador independiente…
ModificadaAlta (7.2)1.7%—Oracle Database Server20/4/200616/6/2026
Vulnerabilidad no especificada en Oracle Database Server 8.1.7.4, 9.0.1.5 y 9.2.0.7 con impacto y vectores de ataque desconocidos en el componente Oracle Spatial, tcc Vuln# DB13.
ModificadaMedia (4.3)4.1%💥 ExploitKevin Johnson Basic Analysis AND Security EngineRoman Danyliw Analysis Console FOR Intrusion Databases (acid)3/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in the PrintFreshPage function in (1) Basic Analysis and Security Engine (BASE) 1.2.4 and (2) Analysis Console for Intrusion Databases (ACID) 0.9.6b23 allows remote attackers to inject arbitrary web script or HTML via the (a) back parameter to base_graph_main.php, (b) netmask…
ModificadaAlta (7.5)4.8%—Oracle 10G Enterprise Manager Grid ControlOracle Application ServerOracle Collaboration SuiteOracle Database Server+84/2/200616/6/2026
Unspecified vulnerability in the Net Listener component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, and 9.2.0.7 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB11.
ModificadaAlta (7.5)8.5%💥 ExploitOracle Database Server4/2/200616/6/2026
SQL injection vulnerability in the SYS.DBMS_METADATA_UTIL package in Oracle Database 10g, and possibly earlier versions, might allow remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it…
ModificadaAlta (7.5)4.3%—Oracle Database Server4/2/200616/6/2026
SQL injection vulnerability in the Data Pump Metadata API in Oracle Database 10g and possibly earlier might allow remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively…
ModificadaAlta (7.5)9.7%—Oracle Database Server4/2/200616/6/2026
Oracle Database 8i, 9i, and 10g allow remote authenticated users to execute arbitrary SQL statements in the context of the SYS user and bypass audit logging, including statements to create new privileged database accounts, via a modified AUTH_ALTER_SESSION attribute in the authentication phase of the Transparent…
ModificadaAlta (7.5)4.3%—Oracle Database Server4/2/200616/6/2026
SQL injection vulnerability in the Oracle Text component of Oracle Database 10g, and possibly earlier versions, might allow remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be…
ModificadaMedia (5.8)4.9%💥 ExploitIndexcor Ezdatabase19/1/200616/6/2026
index.php in EZDatabase before 2.1.2 does not properly cleanse the p parameter before constructing and including a .php filename, which allows remote attackers to conduct directory traversal attacks, and produces resultant cross-site scripting (XSS) and path disclosure.
ModificadaAlta (10)5.1%—Oracle Database Server18/1/200616/6/2026
Unspecified vulnerability in the Advanced Queuing component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.6, 10.1.0.3 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB01.
ModificadaAlta (10)29%💥 ExploitOracle Application ServerOracle Database Server18/1/200616/6/2026
Unspecified vulnerability in the Oracle HTTP Server component of Oracle Database Server 10.1.0.5 and Application Server 10.1.2.0.2 has unspecified impact and attack vectors, as identified by Oracle Vuln# OHS02.
ModificadaAlta (10)4.2%—Oracle Database Server18/1/200616/6/2026
Multiple unspecified vulnerabilities in Oracle Database server 10.1.0.5 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB04 and (2) DB06 in the (a) Data Pump component; (3) DB10 in the (b) Net Listener component; and (4) DB16 in the (c) Oracle Text component. NOTE: details are…
ModificadaAlta (10)6.3%—Oracle Database Server18/1/200616/6/2026
Multiple unspecified vulnerabilities in Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.5 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB07 in the Dictionary component and (2) DB14 in the Oracle Label Security component. NOTE: Oracle has not disputed reliable researcher…
ModificadaAlta (10)5.9%—Oracle Application ServerOracle Collaboration SuiteOracle Database ServerOracle E-business Suite18/1/200616/6/2026
Multiple unspecified vulnerabilities in Oracle Database Server 10.2.0.1, Application Server 9.0.4.2 and 10.1.2.1, Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i), and E-Business Suite and Applications 11.5.10 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) WF02 and (2) WF03 in…
ModificadaAlta (9)4.0%—Oracle Database Server18/1/200616/6/2026
Unspecified vulnerability in the Query Optimizer component of Oracle Database server 9.0.1.5, 9.2.0.7, and 10.1.0.5 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB19.
ModificadaAlta (10)5.9%—Oracle Database Server18/1/200616/6/2026
Unspecified vulnerability in the Connection Manager component of Oracle Database server 8.1.7.4 and 9.0.1.5 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB03.
ModificadaAlta (10)4.7%—Oracle Database Server18/1/200616/6/2026
Multiple unspecified vulnerabilities in Oracle Database server 9.2.0.7 and 10.1.0.5 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB05 in the (a) Data Pump component; (2) DB15 in the (b) Oracle Text component; (3) DB22 in the (c) Streams Apply component; (4) DB23 and (5) DB24 in the (d)…
ModificadaAlta (10)5.9%—Oracle Application ServerOracle Collaboration SuiteOracle Database ServerOracle E-business Suite18/1/200616/6/2026
Unspecified vulnerability in Oracle Database Server 9.2.0.7, Application Server 9.0.4.2 and 10.1.2.1, Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i), and E-Business Suite and Applications 11.5.10 has unspecified impact and attack vectors, as identified by Oracle Vuln# WF01 in the Oracle Workflow Cartridge…
Orbitaley — Vulnerabilidades