Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
617 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.23% | — | Mariadb | 25/5/2022 | 17/6/2026 | MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/ds_compress.cc, when an error occurs (i.e., going to the err label) while executing the method create_worker_threads, the held lock thd->ctrl_mutex is not released correctly, which allows local users to trigger a denial of service due… | |
| Modificada | Media (5.5) | 0.23% | — | Mariadb | 25/5/2022 | 17/6/2026 | MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/ds_compress.cc, when an error occurs (pthread_create returns a nonzero value) while executing the method create_worker_threads, the held lock is not released correctly, which allows local users to trigger a denial of service due to the… | |
| Modificada | Media (5.5) | 0.22% | — | Mariadb | 25/5/2022 | 17/6/2026 | MariaDB Server before 10.7 is vulnerable to Denial of Service. In extra/mariabackup/ds_xbstream.cc, when an error occurs (stream_ctxt->dest_file == NULL) while executing the method xbstream_open, the held lock is not released correctly, which allows local users to trigger a denial of service due to the deadlock. Note:… | |
| Modificada | Media (5.4) | 0.77% | — | Jenkins Global Variable String Parameter | 17/5/2022 | 17/6/2026 | Jenkins Global Variable String Parameter Plugin 1.2 and earlier does not escape the name and description of Global Variable String parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Media (4.4) | 1.2% | — | Oracle MysqlNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation+2 | 19/4/2022 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.37 and prior and 8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of… | |
| Modificada | Media (4.9) | 2.0% | — | Oracle MysqlNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation+3 | 19/4/2022 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: FTS). Supported versions that are affected are 5.7.37 and prior and 8.0.28 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks… | |
| Modificada | Alta (7.5) | 1.7% | — | Mariadb | 14/4/2022 | 17/6/2026 | MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_mb_wc_latin1 at /strings/ctype-latin1.c. | |
| Modificada | Alta (7.5) | 2.1% | — | MariadbDebian Linux | 14/4/2022 | 17/6/2026 | MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component VDec::VDec at /sql/sql_type.cc. | |
| Modificada | Alta (7.5) | 1.6% | — | Mariadb | 14/4/2022 | 17/6/2026 | MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_wildcmp_8bit_impl at /strings/ctype-simple.c. | |
| Modificada | Alta (7.5) | 2.2% | — | MariadbDebian Linux | 14/4/2022 | 17/6/2026 | MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_cmpfunc.cc. | |
| Modificada | Alta (7.5) | 1.7% | — | Mariadb | 14/4/2022 | 17/6/2026 | MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/field_conv.cc. | |
| Modificada | Alta (7.5) | 2.2% | — | MariadbDebian Linux | 14/4/2022 | 17/6/2026 | MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_func.cc:148. | |
| Modificada | Alta (7.5) | 2.2% | — | MariadbDebian Linux | 14/4/2022 | 17/6/2026 | There is an Assertion failure in MariaDB Server v10.9 and below via 'node->pcur->rel_pos == BTR_PCUR_ON' at /row/row0mysql.cc. | |
| Modificada | Alta (7.5) | 2.2% | — | MariadbDebian Linux | 14/4/2022 | 17/6/2026 | MariaDB Server v10.9 and below was discovered to contain a use-after-free via the component Binary_string::free_buffer() at /sql/sql_string.h. | |
| Modificada | Alta (7.5) | 1.6% | — | Mariadb | 14/4/2022 | 17/6/2026 | MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_cmpfunc.h. | |
| Modificada | Alta (7.5) | 2.2% | — | MariadbDebian Linux | 14/4/2022 | 17/6/2026 | MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/sql_window.cc. | |
| Modificada | Alta (7.5) | 1.5% | — | Mariadb | 14/4/2022 | 17/6/2026 | MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_subselect.cc. | |
| Modificada | Alta (7.5) | 2.5% | — | MariadbDebian Linux | 12/4/2022 | 17/6/2026 | MariaDB Server v10.7 and below was discovered to contain a global buffer overflow in the component decimal_bin_size, which is exploited via specially crafted SQL statements. | |
| Modificada | Alta (7.5) | 2.3% | — | MariadbDebian Linux | 12/4/2022 | 17/6/2026 | MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component sql/sql_class.cc. | |
| Modificada | Alta (7.5) | 1.6% | — | Mariadb | 12/4/2022 | 17/6/2026 | An issue in the component Used_tables_and_const_cache::used_tables_and_const_cache_join of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements. | |
| Modificada | Alta (7.5) | 2.2% | — | MariadbDebian Linux | 12/4/2022 | 17/6/2026 | An issue in the component Item_subselect::init_expr_cache_tracker of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements. | |
| Modificada | Alta (7.5) | 2.1% | — | MariadbDebian Linux | 12/4/2022 | 17/6/2026 | MariaDB Server v10.6 and below was discovered to contain an use-after-free in the component my_strcasecmp_8bit, which is exploited via specially crafted SQL statements. | |
| Modificada | Alta (7.5) | 1.5% | — | Mariadb | 12/4/2022 | 17/6/2026 | MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component Item_field::used_tables/update_depend_map_for_order. | |
| Modificada | Alta (7.5) | 2.2% | — | MariadbDebian Linux | 12/4/2022 | 17/6/2026 | An issue in the component Field::set_default of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements. | |
| Modificada | Alta (7.5) | 2.3% | — | MariadbDebian Linux | 12/4/2022 | 17/6/2026 | An issue in the component my_decimal::operator= of MariaDB Server v10.6.3 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements. |