Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.7) | 0.53% | — | Enterprisedb Postgres Advanced ServerAI | 14/5/2024 | 17/6/2026 | All versions of EnterpriseDB Postgres Advanced Server (EPAS) from 15.0 prior to 15.7.0 and from 16.0 prior to 16.3.0 may allow users using edbldr to bypass role permissions from pg_read_server_files. This could allow low privilege users to read files to which they would not otherwise have access. | |
| Modificada | Media (6.5) | 0.53% | — | Enterprisedb Postgres Advanced Server | 12/12/2023 | 17/6/2026 | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It permits an authenticated user to use DBMS_PROFILER to remove all accumulated profiling data on a system-wide basis, regardless of that… | |
| Modificada | Alta (8.8) | 0.63% | — | Enterprisedb Postgres Advanced Server | 12/12/2023 | 17/6/2026 | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It contains the function _dbms_aq_move_to_exception_queue that may be used to elevate a user's privileges to superuser. This function accepts… | |
| Modificada | Alta (8.8) | 0.77% | — | Enterprisedb Postgres Advanced Server | 12/12/2023 | 17/6/2026 | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It may allow an authenticated user to bypass authorization requirements and access underlying implementation functions. When a superuser has… | |
| Modificada | Crítica (9.8) | 0.76% | — | Enterprisedb Postgres Advanced Server | 12/12/2023 | 17/6/2026 | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It contain packages, standalone packages, and functions that run SECURITY DEFINER but are inadequately secured against search_path attacks. | |
| Modificada | Media (4.3) | 0.45% | — | Enterprisedb Postgres Advanced Server | 12/12/2023 | 17/6/2026 | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It allows an authenticated user to refresh any materialized view, regardless of that user's permissions. | |
| Modificada | Media (6.5) | 0.59% | — | Enterprisedb Postgres Advanced Server | 12/12/2023 | 17/6/2026 | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. When using UTL_ENCODE, an authenticated user can read any large object, regardless of that user's permissions. | |
| Modificada | Media (6.5) | 0.59% | — | Enterprisedb Postgres Advanced Server | 12/12/2023 | 17/6/2026 | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It contains the functions get_url_as_text and get_url_as_bytea that are publicly executable, thus permitting an authenticated user to read any… | |
| Modificada | Media (4.3) | 0.47% | — | Enterprisedb Postgres Advanced Server | 12/12/2023 | 17/6/2026 | An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It allows an authenticated user to to obtain information about whether certain files exist on disk, what errors if any occur when attempting… | |
| Modificada | Alta (7.5) | 0.43% | — | Enterprisedb Postgres Advanced Server | 23/4/2023 | 17/6/2026 | EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used with CREATE/ALTER USER/GROUP/ROLE, and redacting was configured with edb_filter_log.redact_password_commands. The fixed versions are 10.23.33, 11.18.29, 12.13.17, 13.9.13, and… | |
| Modificada | Alta (8.8) | 1.1% | — | Okta Advanced Server Access | 6/3/2023 | 17/6/2026 | Okta Advanced Server Access Client versions 1.13.1 through 1.65.0 are vulnerable to command injection due to the third party library webbrowser. An outdated library, webbrowser, used by the ASA client was found to be vulnerable to command injection. To exploit this issue, an attacker would need to phish the user to… | |
| Modificada | Alta (8.8) | 1.5% | — | Okta Advanced Server Access | 23/3/2022 | 17/6/2026 | Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 was found to be vulnerable to command injection via a specially crafted URL. An attacker, who has knowledge of a valid team name for the victim and also knows a valid target host where the user has access, can execute commands on the local… | |
| Modificada | Alta (8.8) | 17% | — | Okta Advanced Server Access Client FOR Windows | 21/2/2022 | 17/6/2026 | Okta Advanced Server Access Client for Windows prior to version 1.57.0 was found to be vulnerable to command injection via a specially crafted URL. | |
| Modificada | Media (6.1) | 0.83% | — | Gforge Advanced Server | 25/3/2019 | 17/6/2026 | GForge Advanced Server 6.4.4 allows XSS via the commonsearch.php words parameter, as demonstrated by a snippet/search/?words= substring. | |
| Modificada | Media (6.5) | 5.1% | 💥 Exploit | Enterprisedb Postgres Advanced Server | 31/8/2007 | 16/6/2026 | EnterpriseDB Advanced Server 8.2 does not properly handle certain debugging function calls that occur before a call to pldbg_create_listener, which allows remote authenticated users to cause a denial of service (daemon crash) and possibly execute arbitrary code via a SELECT statement that invokes a pldbg_ function, as… | |
| Modificada | Alta (9.3) | 38% | 💥 Exploit | Microsoft Windows-ntMicrosoft Windows 2000Microsoft Windows 2000 Advanced ServerMicrosoft Windows 2003 Server+3 | 14/2/2006 | 16/6/2026 | Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute. | |
| Modificada | Alta (7.5) | 4.0% | — | Hauri LivecallHauri Virobot Advanced ServerHauri Virobot ExpertHauri Virobot Linux Server | 30/8/2005 | 16/6/2026 | Stack-based buffer overflow in the ACE archive decompression library (vrAZace.dll) in HAURI Anti-Virus products including ViRobot Expert 4.0, Advanced Server, Linux Server 2.0, and LiveCall, when compressed file scanning is enabled, allows remote attackers to execute arbitrary code via an ACE archive that contains a… | |
| Modificada | Media (5) | 3.5% | — | Hauri LivecallHauri Virobot Advanced ServerHauri Virobot ExpertHauri Virobot Linux Server | 23/8/2005 | 16/6/2026 | Directory traversal vulnerability in HAURI Anti-Virus products including ViRobot Expert 4.0, Advanced Server, Linux Server 2.0, and LiveCall allows remote attackers to overwrite arbitrary files via ".." sequences in filenames contained in (1) ACE, (2) ARJ, (3) CAB, (4) LZH, (5) RAR, (6) TAR and (7) ZIP files. | |
| Modificada | Alta (7.5) | 22% | 💥 Exploit | Sendmail Advanced Message ServerSendmailSendmail PROSendmail Switch+10 | 6/10/2003 | 16/6/2026 | A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences. | |
| Modificada | Alta (10) | 66% | — | Sendmail Advanced Message ServerSendmailSendmail PROSendmail Switch+14 | 6/10/2003 | 16/6/2026 | The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c. | |
| Modificada | Media (5) | 2.7% | — | Hp-uxHP Advanced Server 9000 | 31/12/2002 | 16/6/2026 | RFC-NETBIOS in HP Advanced Server/9000 B.04.05 through B.04.09, when running HP-UX 11.00 or 11.11, allows remote attackers to cause a denial of service (panic) via a malformed UDP packet on port 139. |