Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

230 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.9)2.2%—Oracle MysqlFedoraproject FedoraRedhat Software CollectionsRedhat Enterprise Linux+323/4/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this…
ModificadaMedia (4.9)2.1%—Oracle MysqlFedoraproject FedoraRedhat Software CollectionsRedhat Enterprise Linux+323/4/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability…
ModificadaMedia (4.9)2.2%—Oracle MysqlCanonical Ubuntu LinuxFedoraproject FedoraRedhat Software Collections+423/4/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: PS). Supported versions that are affected are 5.7.25 and prior and 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful…
ModificadaMedia (4.9)2.1%—Oracle MysqlFedoraproject FedoraRedhat Software CollectionsRedhat Enterprise Linux+323/4/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks…
ModificadaMedia (4.9)2.1%—Oracle MysqlFedoraproject FedoraRedhat Software CollectionsRedhat Enterprise Linux+323/4/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Partition). Supported versions that are affected are 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this…
ModificadaMedia (4.9)2.1%—Oracle MysqlFedoraproject FedoraRedhat Software CollectionsRedhat Enterprise Linux+323/4/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability…
ModificadaMedia (4.9)2.1%—Oracle MysqlFedoraproject FedoraRedhat Software CollectionsRedhat Enterprise Linux+323/4/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks…
ModificadaMedia (4.9)2.2%—Oracle MysqlCanonical Ubuntu LinuxFedoraproject FedoraRedhat Software Collections+423/4/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.7.25 and prior and 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.…
ModificadaMedia (4.9)2.2%—Oracle MysqlFedoraproject FedoraRedhat Software CollectionsRedhat Enterprise Linux+323/4/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability…
ModificadaMedia (6.1)87%💥 ExploitJqueryDebian LinuxDrupalBackdropcms Backdrop+10120/4/201917/6/2026
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
ModificadaCrítica (9.1)4.4%—PHPCanonical Ubuntu LinuxNetapp Storage Automation StoreRedhat Software Collections+218/4/201917/6/2026
When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past allocated buffer in exif_iif_add_value function. This may lead to information disclosure or crash.
ModificadaCrítica (9.1)4.1%—PHPCanonical Ubuntu LinuxNetapp Storage Automation StoreRedhat Software Collections+218/4/201917/6/2026
When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3.4 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.
AnalizadaAlta (7.8)65%⚠ Explotación activa💥 ExploitApache Http ServerFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+238/4/201917/6/2026
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating…
ModificadaAlta (8.6)3.5%—Palletsprojects JinjaFedoraproject FedoraCanonical Ubuntu LinuxRedhat Software Collections+17/4/201917/6/2026
In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.
ModificadaAlta (7.5)8.8%—Rubyonrails RailsDebian LinuxRedhat CloudformsRedhat Software Collections+227/3/201917/6/2026
There is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 where specially crafted accept headers can cause action view to consume 100% cpu and make the server unresponsive.
AnalizadaAlta (7.5)99%⚠ Explotación activa💥 ExploitRubyonrails RailsDebian LinuxRedhat CloudformsOpensuse Leap+227/3/201917/6/2026
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed.
ModificadaAlta (7.5)6.2%—PHPCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+29/3/201917/6/2026
An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an Invalid Read in exif_process_SOFn.
ModificadaAlta (7.5)8.2%—PHPDebian LinuxCanonical Ubuntu LinuxOpensuse Leap+29/3/201917/6/2026
An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_MAKERNOTE because of mishandling the data_len variable.
ModificadaAlta (7.5)6.7%—PHPDebian LinuxCanonical Ubuntu LinuxOpensuse Leap+29/3/201917/6/2026
An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There is an uninitialized read in exif_process_IFD_in_MAKERNOTE because of mishandling the maker_note->offset relationship to value_len.
ModificadaMedia (5.4)0.64%—Personal Video Collection Script Project Personal Video Collection Script6/3/201917/6/2026
PHP Scripts Mall Personal Video Collection Script 4.0.4 has Stored XSS via the "Update profile" feature.
ModificadaMedia (4.9)2.7%—Oracle MysqlNetapp Oncommand Unified ManagerNetapp Oncommand Workflow AutomationNetapp Snapcenter+616/1/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Connection). Supported versions that are affected are 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this…
ModificadaMedia (5)0.41%—Oracle MysqlNetapp Oncommand Unified ManagerNetapp Oncommand Workflow AutomationNetapp Snapcenter+616/1/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Packaging). Supported versions that are affected are 8.0.13 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server.…
ModificadaMedia (4.1)0.40%—Oracle MysqlNetapp Oncommand Unified ManagerNetapp Oncommand Workflow AutomationNetapp Snapcenter+616/1/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Options). Supported versions that are affected are 8.0.13 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful…
ModificadaAlta (7.1)2.0%—Oracle MysqlCanonical Ubuntu LinuxNetapp Oncommand Unified ManagerNetapp Oncommand Workflow Automation+716/1/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise…
ModificadaMedia (6.5)1.6%—Oracle MysqlNetapp Oncommand Unified ManagerNetapp Oncommand Workflow AutomationNetapp Snapcenter+616/1/201917/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Security : Privileges). Supported versions that are affected are 8.0.13 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful…
Orbitaley — Vulnerabilidades