Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
617 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.62% | — | Scilicot I, Librarian | 31/5/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository mkucej/i-librarian-free prior to 5.10.4. | |
| Modificada | Media (6.7) | 0.22% | — | Vmware Aria OperationsVmware Cloud Foundation | 12/5/2023 | 17/6/2026 | VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'. | |
| Modificada | Alta (7.2) | 1.6% | — | Vmware Aria Operations FOR LogsVmware Cloud Foundation | 20/4/2023 | 17/6/2026 | VMware Aria Operations for Logs contains a command injection vulnerability. A malicious actor with administrative privileges in VMware Aria Operations for Logs can execute arbitrary commands as root. | |
| Modificada | Crítica (9.8) | 70% | 💥 Exploit | Vmware Aria Operations FOR LogsVmware Cloud Foundation | 20/4/2023 | 17/6/2026 | VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root. | |
| Modificada | Crítica (9.8) | 0.89% | — | I-librarian | 31/1/2023 | 17/6/2026 | i-librarian 4.10 is vulnerable to Arbitrary file upload in ajaxsupplement.php. | |
| Modificada | Media (6.5) | 1.5% | — | Mariadb | 20/1/2023 | 17/6/2026 | MariaDB Server before 10.3.34 thru 10.9.3 is vulnerable to Denial of Service. It is possible for function spider_db_mbase::print_warnings to dereference a null pointer. | |
| Modificada | Crítica (9.8) | 0.67% | — | Ariadne-cms Ariadne Component Library | 31/12/2022 | 17/6/2026 | A vulnerability was found in Ariadne Component Library up to 2.x. It has been classified as critical. Affected is an unknown function of the file src/url/Url.php. The manipulation leads to server-side request forgery. Upgrading to version 3.0 is able to address this issue. It is recommended to upgrade the affected… | |
| Modificada | Alta (8.8) | 0.79% | — | Gnome Gvariant Database | 26/12/2022 | 17/6/2026 | A vulnerability was found in GNOME gvdb. It has been classified as critical. This affects the function gvdb_table_write_contents_async of the file gvdb-builder.c. The manipulation leads to use after free. It is possible to initiate the attack remotely. The name of the patch is d83587b2a364eb9a9a53be7e6a708074e252de14.… | |
| Modificada | Media (4.4) | 1.2% | — | Oracle MysqlNetapp Oncommand InsightNetapp Oncommand Workflow AutomationMariadb | 18/10/2022 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: C API). Supported versions that are affected are 5.7.36 and prior and 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of… | |
| Modificada | Media (5.5) | 0.25% | — | MariadbFedoraproject Fedora | 27/8/2022 | 17/6/2026 | In MariaDB before 10.9.2, compress_write in extra/mariabackup/ds_compress.cc does not release data_mutex upon a stream write failure, which allows local users to trigger a deadlock. | |
| Modificada | Alta (7.5) | 2.4% | — | MariadbDebian LinuxFedoraproject Fedora | 1/7/2022 | 17/6/2026 | MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at /libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc. | |
| Modificada | Alta (7.5) | 2.2% | — | MariadbFedoraproject Fedora | 1/7/2022 | 17/6/2026 | MariaDB v10.5 to v10.7 was discovered to contain a segmentation fault via the component st_select_lex_unit::exclude_level. | |
| Modificada | Alta (7.5) | 2.0% | — | MariadbDebian Linux | 1/7/2022 | 17/6/2026 | MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Exec_time_tracker::get_loops/Filesort_tracker::report_use/filesort. | |
| Modificada | Alta (7.5) | 1.8% | — | MariadbDebian Linux | 1/7/2022 | 17/6/2026 | MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_args::walk_args. | |
| Modificada | Alta (7.5) | 1.6% | — | Mariadb | 1/7/2022 | 17/6/2026 | MariaDB v10.4 to v10.8 was discovered to contain a segmentation fault via the component Item_field::fix_outer_field. | |
| Modificada | Alta (7.5) | 2.0% | — | MariadbDebian Linux | 1/7/2022 | 17/6/2026 | MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_func_in::cleanup/Item::cleanup_processor. | |
| Modificada | Alta (7.5) | 2.3% | — | MariadbDebian LinuxFedoraproject Fedora | 1/7/2022 | 17/6/2026 | MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component sub_select. | |
| Modificada | Alta (7.5) | 2.0% | — | MariadbDebian Linux | 1/7/2022 | 17/6/2026 | MariaDB v10.2 to v10.6.1 was discovered to contain a segmentation fault via the component Item_subselect::init_expr_cache_tracker. | |
| Modificada | Alta (7.5) | 2.1% | — | MariadbFedoraproject Fedora | 1/7/2022 | 17/6/2026 | MariaDB v10.5 to v10.7 was discovered to contain an assertion failure at table->get_ref_count() == 0 in dict0dict.cc. | |
| Modificada | Alta (7.5) | 2.2% | — | MariadbFedoraproject Fedora | 1/7/2022 | 17/6/2026 | MariaDB v10.4 to v10.7 was discovered to contain an use-after-poison in prepare_inplace_add_virtual at /storage/innobase/handler/handler0alter.cc. | |
| Modificada | Crítica (9.8) | 1.0% | — | Ariang Project Ariang | 15/6/2022 | 17/6/2026 | AriaNg v0.1.0~v1.2.2 is affected by an incorrect access control vulnerability through not authenticating visitors' access rights. | |
| Modificada | Alta (7.8) | 0.34% | — | Itarian Endpoint Manager Communication Client | 9/6/2022 | 17/6/2026 | The ITarian Endpoint Manage Communication Client, prior to version 6.43.41148.21120, is compiled using insecure OpenSSL settings. Due to this setting, a malicious actor with low privileges access to a system can escalate his privileges to SYSTEM abusing an insecure openssl.conf lookup. | |
| Modificada | Alta (8.8) | 1.8% | — | Itarian On-premiseItarian Saas Service Desk | 9/6/2022 | 17/6/2026 | The ITarian platform (SAAS / on-premise) offers the possibility to run code on agents via a function called procedures. It is possible to require a mandatory approval process. Due to a vulnerability in the approval process, present in any version prior to 6.35.37347.20040, a malicious actor (with a valid session… | |
| Modificada | Alta (7.5) | 0.82% | — | Itarian On-premiseItarian Saas Service Desk | 9/6/2022 | 17/6/2026 | Within the Service Desk module of the ITarian platform (SAAS and on-premise), a remote attacker can obtain sensitive information, caused by the failure to set the HTTP Only flag. A remote attacker could exploit this vulnerability to gain access to the management interface by using this vulnerability in combination… | |
| Modificada | Media (5.5) | 0.21% | — | Mariadb | 25/5/2022 | 17/6/2026 | MariaDB Server before 10.7 is vulnerable to Denial of Service. While executing the plugin/server_audit/server_audit.c method log_statement_ex, the held lock lock_bigbuffer is not released correctly, which allows local users to trigger a denial of service due to the deadlock. |