Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
230 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.9) | 3.1% | — | Oracle MysqlNetapp Oncommand Unified ManagerNetapp Oncommand Workflow AutomationNetapp Snapcenter+7 | 16/1/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL… | |
| Modificada | Media (4.9) | 3.2% | — | Oracle MysqlNetapp Oncommand Unified ManagerNetapp Oncommand Workflow AutomationNetapp Snapcenter+7 | 16/1/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise… | |
| Modificada | Media (4.9) | 2.6% | — | Oracle MysqlNetapp Oncommand Unified ManagerNetapp Oncommand Workflow AutomationNetapp Snapcenter+6 | 16/1/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (5.5) | 2.1% | — | Oracle MysqlNetapp Oncommand Unified ManagerNetapp Oncommand Workflow AutomationNetapp Snapcenter+6 | 16/1/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (6.5) | 3.3% | — | Oracle MysqlCanonical Ubuntu LinuxNetapp Oncommand Unified ManagerNetapp Oncommand Workflow Automation+7 | 16/1/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supported versions that are affected are 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful… | |
| Modificada | Media (4.9) | 3.1% | — | Oracle MysqlCanonical Ubuntu LinuxNetapp Oncommand Unified ManagerNetapp Oncommand Workflow Automation+7 | 16/1/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.… | |
| Modificada | Crítica (9.8) | 3.2% | 💥 Exploit | Thephpfactory Collection Factory | 28/9/2018 | 17/6/2026 | SQL Injection exists in the Collection Factory 4.1.9 component for Joomla! via the filter_order or filter_order_Dir parameter. | |
| Modificada | Crítica (9.8) | 3.3% | 💥 Exploit | Joomlathat Music Collection | 28/9/2018 | 17/6/2026 | SQL Injection exists in the Music Collection 3.0.3 component for Joomla! via the id parameter. | |
| Modificada | Alta (7.1) | 1.7% | — | Apache Portable RuntimeDebian LinuxRedhat Jboss Core ServicesRedhat Jboss Enterprise WEB Server+7 | 24/10/2017 | 17/6/2026 | When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting this value to an apr_time_exp_t value, potentially revealing the contents of a different static heap value or resulting… | |
| Modificada | Alta (7.8) | 1.1% | — | Nttdocomo Photo Collection PC Software | 29/8/2017 | 17/6/2026 | Untrusted search path vulnerability in Photo Collection PC Software Ver.4.0.2 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Crítica (9.1) | 4.0% | — | Oracle Advanced Collections | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Advanced Collections component in Oracle E-Business Suite 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via vectors related to Report JSPs. | |
| Modificada | Crítica (9.8) | 19% | 💥 PoC | GIT Project GITRedhat Software CollectionsCanonical Ubuntu LinuxOpensuse | 13/4/2016 | 17/6/2026 | The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed protocols, which might allow remote attackers to execute arbitrary code via a URL in a (a) .gitmodules file or (b) unknown… | |
| Analizada | Alta (7.5) | 96% | ⚠ Explotación activa💥 Exploit | Rubyonrails RailsOpensuse LeapOpensuseSuse Linux Enterprise Module FOR Containers+2 | 16/2/2016 | 17/6/2026 | Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a… | |
| Modificada | Alta (7.5) | 82% | — | F5 NginxCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+2 | 15/2/2016 | 17/6/2026 | The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process crash) via a crafted UDP DNS response. | |
| Modificada | Media (5.5) | 1.4% | — | Oracle Advanced Collections | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Advanced Collections component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, and 12.1.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Administration, a different vulnerability than CVE-2016-0556. | |
| Modificada | Crítica (9.8) | 19% | 💥 PoC | Apache Commons Collections | 15/12/2015 | 7/10/2026 | Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, Service, and Acceleration; Network and Content Security Devices; Network Management and Provisioning; Routing and Switching - Enterprise and Service Provider; Unified Computing;… | |
| Modificada | Media (5.4) | 0.27% | — | Pdlk Hardest Game Collection | 16/10/2014 | 17/6/2026 | The Hardest Game Collection (aka com.lotfun.abuse) application 1.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.8% | — | IBM Eclipse Help SystemIBM Spss Data Collection | 3/6/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in IBM Eclipse Help System (IEHS) 3.4.3 and 3.6.2, as used in IBM SPSS Data Collection 6.0, 6.0.1, and 7.0, allow remote attackers to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (5) | 1.4% | — | Yomecolle NEC Biglobe Yome Collection | 5/7/2012 | 16/6/2026 | The NEC BIGLOBE Yome Collection application 1.8.3 and earlier for Android allows remote attackers to read the IMEI value from an SD card via a crafted application that lacks the READ_PHONE_STATE permission. | |
| Modificada | Media (4.3) | 1.8% | — | IBM Security Appscan SourceIBM Spss Data Collection | 20/6/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in deferredView.jsp in IBM Eclipse Help System (IEHS), as used in IBM Security AppScan Source 7.x and 8.x before 8.6 and IBM SPSS Data Collection Developer Library 6.0 and 6.0.1, allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (5.8) | 1.8% | — | IBM Security Appscan SourceIBM Spss Data Collection | 20/6/2012 | 16/6/2026 | Open redirect vulnerability in IBM Eclipse Help System (IEHS), as used in IBM Security AppScan Source 7.x and 8.x before 8.6 and IBM SPSS Data Collection Developer Library 6.0 and 6.0.1, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |
| Modificada | Alta (9.3) | 3.4% | — | IBM Spss Data CollectionIBM Spss Dimensions | 18/1/2012 | 16/6/2026 | Unspecified vulnerability in the Render method in the ExportHTML.ocx ActiveX control in ExportHTML.dll in IBM SPSS Dimensions 5.5 and SPSS Data Collection 5.6, 6.0, and 6.0.1 allows remote attackers to execute arbitrary code via a crafted HTML document. | |
| Modificada | Alta (9.3) | 3.4% | — | IBM Spss Data CollectionIBM Spss Dimensions | 18/1/2012 | 16/6/2026 | Unspecified vulnerability in the SetLicenseInfoEx method in an ActiveX control in mraboutb.dll in IBM SPSS Dimensions 5.5 and SPSS Data Collection 5.6, 6.0, and 6.0.1 allows remote attackers to execute arbitrary code via a crafted HTML document. | |
| Modificada | Media (5) | 14% | 💥 Exploit | Thorsten Riess COM Jcollection | 8/3/2010 | 16/6/2026 | Directory traversal vulnerability in the JCollection (com_jcollection) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | |
| Modificada | Baja (2.1) | 0.25% | — | SUN Lightweight Availability Collection Tool | 5/7/2009 | 16/6/2026 | Race condition in the Sun Lightweight Availability Collection Tool 3.0 on Solaris 7 through 10 allows local users to overwrite arbitrary files via unspecified vectors. |