Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3037▲ 502 respecto a la semana anterior
Críticas / altas1448▲ 249 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 158 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4) | 1.9% | — | MysqlMysql Community ServerMysql ServerOracle Mysql+1 | 3/5/2012 | 16/6/2026 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.19 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer. | |
| Modificada | Media (6.5) | 1.3% | — | Mysql Community Server | 18/2/2008 | 16/6/2026 | MySQL Server 5.1.x before 5.1.23 and 6.0.x before 6.0.4 does not check the rights of the entity executing BINLOG, which allows remote authorized users to execute arbitrary BINLOG statements. | |
| Modificada | Alta (7.1) | 14% | — | Mysql ServerMysql Community ServerMysql Enterprise Server | 10/12/2007 | 16/6/2026 | MySQL Community Server 5.0.x before 5.0.51, Enterprise Server 5.0.x before 5.0.52, Server 5.1.x before 5.1.23, and Server 6.0.x before 6.0.4, when a table relies on symlinks created through explicit DATA DIRECTORY and INDEX DIRECTORY options, allows remote authenticated users to overwrite system table information and… | |
| Modificada | Media (5) | 14% | — | Mysql Community Server | 15/7/2007 | 16/6/2026 | MySQL Community Server before 5.0.45 allows remote attackers to cause a denial of service (daemon crash) via a malformed password packet in the connection protocol. | |
| Modificada | Baja (3.5) | 1.6% | — | Mysql Community Server | 15/7/2007 | 16/6/2026 | MySQL Community Server before 5.0.45 allows remote authenticated users to gain update privileges for a table in another database via a view that refers to this external table. | |
| Modificada | Media (4) | 1.8% | — | Mysql Community Server | 15/7/2007 | 16/6/2026 | MySQL Community Server before 5.0.45 does not require privileges such as SELECT for the source table in a CREATE TABLE LIKE statement, which allows remote authenticated users to obtain sensitive information such as the table structure. | |
| Modificada | Media (4.3) | 1.6% | — | Communityserver.org Community Server | 14/2/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search/SearchResults.aspx in Community Server allows remote attackers to inject arbitrary web script or HTML via the q parameter. | |
| Modificada | Media (5) | 1.5% | — | Telligent Systems Community Server Forums | 29/1/2007 | 16/6/2026 | Telligent Community Server 2.1 and earlier allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service calls with a source URI that corresponds to (1) a large file, which triggers a long download session without a timeout constraint; or (2) a file with a binary content… | |
| Modificada | Media (4.3) | 1.5% | — | Communityserver.org Community Server | 4/2/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Community Server allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors. NOTE: this candidate does not contain any actionable or distinguishing information. Perhaps it should not be included in CVE. NOTE: the provenance of this… | |
| Modificada | Media (4.3) | 0.97% | — | Telligent Systems Community Server Forums | 5/7/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SearchResults.aspx in Community Forum allows remote attackers to inject arbitrary web script or HTML via the q parameter. | |
| Modificada | Media (5) | 83% | — | Cisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+72 | 31/5/2005 | 16/6/2026 | Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old. | |
| Modificada | Alta (7.5) | 2.5% | — | Cisco Unity Server | 15/12/2004 | 16/6/2026 | Cisco Unity 2.x, 3.x, and 4.x, when integrated with Microsoft Exchange, has several hard coded usernames and passwords, which allows remote attackers to gain unauthorized access and change configuration settings or read outgoing or incoming e-mail messages. | |
| Modificada | Alta (7.5) | 1.6% | — | Cisco Unity Server | 28/10/2002 | 16/6/2026 | Cisco Unity 2.x and 3.x uses well-known default user accounts, which could allow remote attackers to gain access and place arbitrary calls. | |
| Modificada | Media (4.6) | 0.35% | — | Cisco Unity Server | 11/10/2002 | 16/6/2026 | The default configuration of Cisco Unity 2.x and 3.x does not block international operator calls in the predefined restriction tables, which could allow authenticated users to place international calls using call forwarding. |