Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

1488 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.9)0.89%—Oracle MysqlNetapp Oncommand Insight17/10/202317/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.7.42 and prior and 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful…
ModificadaMedia (5.3)0.34%—Hcltech Bigfix Insights FOR Vulnerability Remediation11/10/202317/6/2026
BigFix Insights/IVR fixlet uses improper credential handling within certain fixlet content. An attacker can gain access to information that is not explicitly authorized.
ModificadaAlta (8.2)0.33%—Hcltech Bigfix Insights FOR Vulnerability Remediation11/10/202317/6/2026
BigFix Insights for Vulnerability Remediation (IVR) uses weak cryptography that can lead to credential exposure. An attacker could gain access to sensitive information, modify data in unexpected ways, etc.
ModificadaCrítica (9.8)1.7%—Microsoft Azure Hdinsight10/10/202317/6/2026
Azure HDInsight Apache Oozie Workflow Scheduler XXE Elevation of Privilege Vulnerability
AnalizadaAlta (7.5)100%⚠ Explotación activa💥 ExploitSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/202311/8/2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
AnalizadaMedia (6.1)0.56%—Monsterinsights Userfeedback29/9/202317/6/2026
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in UserFeedback Team User Feedback plugin <= 1.0.7 versions.
AnalizadaAlta (8.8)24%⚠ Explotación activa💥 PoCApple IpadosApple Iphone OSApple MacosFedoraproject Fedora+1021/9/202317/6/2026
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.
ModificadaAlta (7.2)2.0%—Microsoft Azure Hdinsight12/9/202317/6/2026
Azure HDInsight Apache Ambari JDBC Injection Elevation of Privilege Vulnerability
ModificadaMedia (5.4)0.44%—I-pro Video Insight5/9/202317/6/2026
Stored cross-site scripting vulnerability in Map setting page of VI Web Client prior to 7.9.6 allows a remote authenticated attacker to inject an arbitrary script.
ModificadaMedia (5.4)0.44%—I-pro Video Insight5/9/202317/6/2026
Stored cross-site scripting vulnerability in View setting page of VI Web Client prior to 7.9.6 allows a remote authenticated attacker to inject an arbitrary script.
ModificadaMedia (6.1)0.51%—I-pro Video Insight5/9/202317/6/2026
Reflected cross-site scripting vulnerability in VI Web Client prior to 7.9.6 allows a remote unauthenticated attacker to inject an arbitrary script.
ModificadaMedia (6.1)0.50%—I-pro Video Insight5/9/202317/6/2026
Open redirect vulnerability in VI Web Client prior to 7.9.6 allows a remote unauthenticated attacker to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL.
ModificadaMedia (4.5)1.0%—Microsoft Azure Hdinsight8/8/202310/8/2026
Azure Apache Hadoop Spoofing Vulnerability
ModificadaMedia (4.5)1.0%—Microsoft Azure Hdinsight8/8/202310/8/2026
Azure Apache Ambari Spoofing Vulnerability
ModificadaMedia (4.5)1.0%—Microsoft Azure Hdinsight8/8/202310/8/2026
Azure Apache Oozie Spoofing Vulnerability
ModificadaMedia (4.6)0.97%—Microsoft Azure Hdinsight8/8/202310/8/2026
Azure HDInsight Jupyter Notebook Spoofing Vulnerability
ModificadaMedia (4.5)1.4%—Microsoft Azure Hdinsight8/8/202310/8/2026
Azure Apache Hive Spoofing Vulnerability
ModificadaMedia (5.4)0.39%—Monsterinsights Exactmetrics8/8/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ExactMetrics plugin <= 7.14.1 versions.
ModificadaAlta (7.5)1.2%—Insightsoftware Jreport27/7/20239/7/2026
Directory traversal vulnerability in Jinfornet Jreport 15.6 allows unauthenticated attackers to gain sensitive information.
ModificadaAlta (7)0.18%—Esri Arcgis Insights19/7/202317/6/2026
There is SQL injection vulnerability in Esri ArcGIS Insights Desktop for Mac and Windows version 2022.1 that may allow a local, authorized attacker to execute arbitrary SQL commands against the back-end database. The effort required to generate the crafted input required to exploit this issue is complex and requires…
ModificadaAlta (7.5)0.67%—Esri Arcgis Insights19/7/202317/6/2026
There is SQL injection vulnerability in Esri ArcGIS Insights 2022.1 for ArcGIS Enterprise and that may allow a remote, authorized attacker to execute arbitrary SQL commands against the back-end database. The effort required to generate the crafted input required to exploit this issue is complex and requires…
ModificadaMedia (4.4)1.7%—Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+218/7/202317/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.33 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this…
ModificadaMedia (4.9)1.4%—Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+218/7/202317/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.33 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this…
ModificadaMedia (4.9)1.8%—Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+218/7/202317/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.33 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this…
ModificadaMedia (4.9)1.4%—Oracle Mysql ServerFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+218/7/202317/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.33 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this…