Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

129 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)3.5%—LibpngOracle Hyperion Infrastructure TechnologyOracle Mysql WorkbenchNetapp Active IQ Unified Manager+110/7/201917/6/2026
An issue has been found in third-party PNM decoding associated with libpng 1.6.35. It is a stack-based buffer overflow in the function get_token in pnm2png.c in pnm2png.
ModificadaCrítica (9.8)2.4%—Cloudera Data Science Workbench3/7/201917/6/2026
Remote code execution is possible in Cloudera Data Science Workbench version 1.3.0 and prior releases via unspecified attack vectors.
ModificadaMedia (5.3)1.2%—Cloudera Data Science Workbench21/6/201917/6/2026
An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.2.x through 1.4.0. Unauthenticated users can get a list of user accounts.
ModificadaAlta (7.1)2.0%—IBM Infosphere Information ServerIBM Infosphere Governance CatalogIBM Infosphere Information Server ON CloudIBM Infosphere Information Server Business Glossary+117/6/201917/6/2026
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150905.
ModificadaCrítica (9.9)0.99%—Cloudera Data Science Workbench7/6/201917/6/2026
An SQL injection vulnerability was found in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. This would allow any authenticated user to run arbitrary queries against CDSW's internal database. The database contains user contact information, encrypted CDSW passwords (in the case of local authentication), API…
ModificadaMedia (5.4)0.77%—Oracle Health Sciences Data Management Workbench23/4/201917/6/2026
Vulnerability in the Oracle Health Sciences Data Management Workbench component of Oracle Health Sciences Applications (subcomponent: User Interface). The supported version that is affected is 2.4.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…
ModificadaMedia (5.9)17%—OpensslCanonical Ubuntu LinuxDebian LinuxNetapp Active IQ Unified Manager+7827/2/201917/6/2026
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid…
ModificadaCrítica (9.1)92%—LibsshCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux+517/10/201817/6/2026
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.
ModificadaBaja (3.7)1.0%—Oracle Mysql Workbench18/7/201817/6/2026
Vulnerability in the MySQL Workbench component of Oracle MySQL (subcomponent: Workbench: Security: Encryption). Supported versions that are affected are 6.3.10 and earlier. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Workbench.…
ModificadaAlta (8.8)0.92%—Cloudera Data Science Workbench5/2/201817/6/2026
An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.x before 1.2.0. Several web application vulnerabilities allow malicious authenticated users of CDSW to escalate privileges in CDSW. CDSW users can exploit these vulnerabilities in combination to gain root access to CDSW nodes, gain access to the CDSW…
ModificadaCrítica (9.8)1.2%—Microfocus Fortify Audit WorkbenchMicrofocus Fortify Software Security Center2/2/201817/6/2026
XML External Entity (XXE) vulnerability in Micro Focus Fortify Audit Workbench (AWB) and Micro Focus Fortify Software Security Center (SSC), versions 16.10, 16.20, 17.10. This vulnerability could be exploited to allow a XML External Entity (XXE) injection.
ModificadaAlta (8.8)3.3%—Pysvn Project Svn-workbench6/9/201717/6/2026
svn-workbench 1.6.2 and earlier on a system with xeyes installed allows local users to execute arbitrary commands by using the "Command Shell" menu item while in the directory trunk/$(xeyes).
ModificadaAlta (7)0.52%—Rockwellautomation Connected Components Workbench19/5/201717/6/2026
A DLL Hijack issue was discovered in Rockwell Automation Connected Components Workbench (CCW). The following versions are affected: Connected Components Workbench - Developer Edition, v9.01.00 and earlier: 9328-CCWDEVENE, 9328-CCWDEVZHE, 9328-CCWDEVFRE, 9328-CCWDEVITE, 9328-CCWDEVDEE, 9328-CCWDEVESE, and…
ModificadaBaja (3.7)0.98%—Oracle Mysql Workbench24/4/201717/6/2026
Vulnerability in the MySQL Workbench component of Oracle MySQL (subcomponent: Workbench: Security : Encryption). Supported versions that are affected are 6.3.8 and earlier. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Workbench.…
ModificadaMedia (5)1.8%—Oracle Human Capital Management Configuration Workbench21/1/201617/6/2026
Unspecified vulnerability in the Oracle HCM Configuration Workbench component in Oracle E-Business Suite 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality via unknown vectors.
ModificadaBaja (3.5)0.91%—Workbench Email Project Workbench Email17/9/201517/6/2026
The Workbench Email module 7.x-3.x before 7.x-3.4 for Drupal allows remote authenticated users with certain permissions to bypass node and field validation by saving a node.
ModificadaMedia (5)1.3%—IBM Rational Test Virtualization ServerIBM Rational Test Workbench30/6/201517/6/2026
Rational Test Control Panel in IBM Rational Test Workbench and Rational Test Virtualization Server 8.0.0.x before 8.0.0.5, 8.0.1.x before 8.0.1.6, 8.5.0.x before 8.5.0.4, 8.5.1.x before 8.5.1.5, 8.6.0.x before 8.6.0.4, and 8.7.0.x before 8.7.0.2 uses the MD5 algorithm for password hashing, which makes it easier for…
ModificadaAlta (7.5)1.2%—SAP Hana Web-based Development Workbench2/6/201517/6/2026
SQL injection vulnerability in SAP HANA Web-based Development Workbench allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Notes 2153892.
ModificadaMedia (6.5)1.9%—Redhat KIE Workbench20/2/201517/6/2026
The default authorization constrains in KIE Workbench 6.0.x allows remote authenticated users to read or write to arbitrary files, bypass intended access restrictions, and possibly have other unspecified impact via unknown vectors.
ModificadaAlta (7.5)11%—Rockwellautomation Connected Components Workbench14/11/201417/6/2026
Rockwell Automation Connected Components Workbench (CCW) before 7.00.00 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an invalid property value to an ActiveX control that was built with an outdated compiler.
ModificadaMedia (4.3)0.93%—SAP Hana Web-based Development Workbench6/11/201417/6/2026
Cross-site scripting (XSS) vulnerability in SAP HANA Web-based Development Workbench allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5)1.2%—SAP Business Intelligence Development Workbench6/11/201417/6/2026
The User & Server configuration, InfoView refresh, user rights (BI-BIP-ADM) component in SAP Business Intellignece allows remote attackers to obtain audit event details via unspecified vectors.
ModificadaMedia (5)1.2%—SAP Business Intelligence Development Workbench6/11/201417/6/2026
The SAP Business Intelligence Development Workbench allows remote attackers to obtain sensitive information by reading unspecified files.
ModificadaMedia (5)1.4%—SAP OIL Industry Solution Traders AND Schedulers Workbench9/6/201417/6/2026
The SAP Trader's and Scheduler's Workbench (TSW) for SAP Oil & Gas has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.
ModificadaMedia (6.8)0.64%—IBM Infosphere Information Server Metadata Workbench16/5/201417/6/2026
Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere Information Server Metadata Workbench 8.1 through 9.1 allows remote attackers to hijack the authentication of arbitrary users.