Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
1488 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.9) | 0.89% | — | Oracle MysqlNetapp Oncommand Insight | 17/10/2023 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.7.42 and prior and 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful… | |
| Modificada | Media (5.3) | 0.34% | — | Hcltech Bigfix Insights FOR Vulnerability Remediation | 11/10/2023 | 17/6/2026 | BigFix Insights/IVR fixlet uses improper credential handling within certain fixlet content. An attacker can gain access to information that is not explicitly authorized. | |
| Modificada | Alta (8.2) | 0.33% | — | Hcltech Bigfix Insights FOR Vulnerability Remediation | 11/10/2023 | 17/6/2026 | BigFix Insights for Vulnerability Remediation (IVR) uses weak cryptography that can lead to credential exposure. An attacker could gain access to sensitive information, modify data in unexpected ways, etc. | |
| Modificada | Crítica (9.8) | 1.7% | — | Microsoft Azure Hdinsight | 10/10/2023 | 17/6/2026 | Azure HDInsight Apache Oozie Workflow Scheduler XXE Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Analizada | Media (6.1) | 0.56% | — | Monsterinsights Userfeedback | 29/9/2023 | 17/6/2026 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in UserFeedback Team User Feedback plugin <= 1.0.7 versions. | |
| Analizada | Alta (8.8) | 24% | ⚠ Explotación activa💥 PoC | Apple IpadosApple Iphone OSApple MacosFedoraproject Fedora+10 | 21/9/2023 | 17/6/2026 | The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7. | |
| Modificada | Alta (7.2) | 2.0% | — | Microsoft Azure Hdinsight | 12/9/2023 | 17/6/2026 | Azure HDInsight Apache Ambari JDBC Injection Elevation of Privilege Vulnerability | |
| Modificada | Media (5.4) | 0.44% | — | I-pro Video Insight | 5/9/2023 | 17/6/2026 | Stored cross-site scripting vulnerability in Map setting page of VI Web Client prior to 7.9.6 allows a remote authenticated attacker to inject an arbitrary script. | |
| Modificada | Media (5.4) | 0.44% | — | I-pro Video Insight | 5/9/2023 | 17/6/2026 | Stored cross-site scripting vulnerability in View setting page of VI Web Client prior to 7.9.6 allows a remote authenticated attacker to inject an arbitrary script. | |
| Modificada | Media (6.1) | 0.51% | — | I-pro Video Insight | 5/9/2023 | 17/6/2026 | Reflected cross-site scripting vulnerability in VI Web Client prior to 7.9.6 allows a remote unauthenticated attacker to inject an arbitrary script. | |
| Modificada | Media (6.1) | 0.50% | — | I-pro Video Insight | 5/9/2023 | 17/6/2026 | Open redirect vulnerability in VI Web Client prior to 7.9.6 allows a remote unauthenticated attacker to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL. | |
| Modificada | Media (4.5) | 1.0% | — | Microsoft Azure Hdinsight | 8/8/2023 | 10/8/2026 | Azure Apache Hadoop Spoofing Vulnerability | |
| Modificada | Media (4.5) | 1.0% | — | Microsoft Azure Hdinsight | 8/8/2023 | 10/8/2026 | Azure Apache Ambari Spoofing Vulnerability | |
| Modificada | Media (4.5) | 1.0% | — | Microsoft Azure Hdinsight | 8/8/2023 | 10/8/2026 | Azure Apache Oozie Spoofing Vulnerability | |
| Modificada | Media (4.6) | 0.97% | — | Microsoft Azure Hdinsight | 8/8/2023 | 10/8/2026 | Azure HDInsight Jupyter Notebook Spoofing Vulnerability | |
| Modificada | Media (4.5) | 1.4% | — | Microsoft Azure Hdinsight | 8/8/2023 | 10/8/2026 | Azure Apache Hive Spoofing Vulnerability | |
| Modificada | Media (5.4) | 0.39% | — | Monsterinsights Exactmetrics | 8/8/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ExactMetrics plugin <= 7.14.1 versions. | |
| Modificada | Alta (7.5) | 1.2% | — | Insightsoftware Jreport | 27/7/2023 | 9/7/2026 | Directory traversal vulnerability in Jinfornet Jreport 15.6 allows unauthenticated attackers to gain sensitive information. | |
| Modificada | Alta (7) | 0.18% | — | Esri Arcgis Insights | 19/7/2023 | 17/6/2026 | There is SQL injection vulnerability in Esri ArcGIS Insights Desktop for Mac and Windows version 2022.1 that may allow a local, authorized attacker to execute arbitrary SQL commands against the back-end database. The effort required to generate the crafted input required to exploit this issue is complex and requires… | |
| Modificada | Alta (7.5) | 0.67% | — | Esri Arcgis Insights | 19/7/2023 | 17/6/2026 | There is SQL injection vulnerability in Esri ArcGIS Insights 2022.1 for ArcGIS Enterprise and that may allow a remote, authorized attacker to execute arbitrary SQL commands against the back-end database. The effort required to generate the crafted input required to exploit this issue is complex and requires… | |
| Modificada | Media (4.4) | 1.7% | — | Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+2 | 18/7/2023 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.33 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (4.9) | 1.4% | — | Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+2 | 18/7/2023 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.33 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (4.9) | 1.8% | — | Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+2 | 18/7/2023 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.33 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… | |
| Modificada | Media (4.9) | 1.4% | — | Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+2 | 18/7/2023 | 17/6/2026 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.33 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this… |