Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
617 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.14% | — | Invariant-systems-ai AiirAI | 4/10/2026 | 6/10/2026 | A flaw has been found in invariant-systems-ai aiir up to 1.7.0. The affected element is an unknown function of the component Policy Gate Handler. Executing a manipulation can lead to improper verification of cryptographic signature. The attack can be executed remotely. It is advisable to upgrade the affected… | |
| Pendiente de análisis | Baja (3.7) | 0.37% | — | Mariadb Connector JAI | 17/9/2026 | 23/9/2026 | MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, ClientMessage.readPacket processes a server-initiated LOCAL INFILE protocol packet 0xfb without enforcing allowLocalInfile=false. When an application sends a LOAD DATA LOCAL… | |
| Aplazada | Media (6.5) | 0.22% | — | Product Variations Swatches FOR WoocommerceAI | 3/9/2026 | 4/9/2026 | Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions. | |
| Pendiente de análisis | Media (5.9) | 0.23% | — | Mariadb Connector R2dbcAI | 28/8/2026 | 8/9/2026 | MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2dbc-mariadb does not gate clear-text password authentication plugins on transport encryption because the AuthenticationPlugin interface has no capability for a plugin to require a secure connection. A… | |
| Pendiente de análisis | Media (5.9) | 0.49% | — | Mariadb Connector R2dbcAIMariadbAI | 28/8/2026 | 8/9/2026 | MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2dbc-mariadb encodes and decodes all character data under the assumption that the connection character set is UTF-8. A server can announce a mid-session change to character_set_client through the… | |
| Pendiente de análisis | Media (5.9) | 0.87% | — | Mariadb Connector/jAIMariadbAI | 28/8/2026 | 8/9/2026 | MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, the connector encodes and decodes protocol text and performs client-side escaping under the assumption that the connection character set is UTF-8. The server can report a… | |
| Pendiente de análisis | Media (5.9) | 0.39% | — | Mariadb Connector JAIMariadbAI | 28/8/2026 | 8/9/2026 | MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, PAM dialog authentication can be coerced into transmitting the account password over an insecure connection. The mysql_clear_password plugin is gated behind a secure… | |
| Pendiente de análisis | Media (5.9) | 0.44% | — | Mariadb Connector/jAI | 28/8/2026 | 8/9/2026 | MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, when a Java application connects with sslMode=verify-full or sslMode=verify-ca, supplies a password, and does not configure serverSslCert or trustStore, Connector/J can accept… | |
| Pendiente de análisis | Media (6.5) | 0.47% | — | Mariadb Connector/node.jsAI | 28/8/2026 | 8/9/2026 | MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js permits SQL injection when attacker-controlled Buffer parameters are escaped client-side under the big5, gbk, sjis, cp932, or gb18030 client… | |
| Pendiente de análisis | Media (5.9) | 0.42% | — | Mariadb Connector/node.jsAI | 28/8/2026 | 8/9/2026 | MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js can disclose an account password when PAM dialog authentication is negotiated over an insecure transport. In… | |
| Pendiente de análisis | Alta (7.5) | 0.57% | — | Mariadb Connector Node.jsAI | 28/8/2026 | 8/9/2026 | MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to versions 3.3.3, 3.4.6, and 3.5.3, when ssl is enabled without a pinned CA or server certificate, MariaDB Connector/Node.js sends credentials before completing certificate fingerprint validation. In… | |
| Aplazada | Media (4) | 0.16% | — | Aria2AI | 25/8/2026 | 8/9/2026 | aria2 <=1.37.0 has a stack-buffer-underflow vulnerability in the IOFile::getLine() function. | |
| Aplazada | Media (6.2) | 0.16% | — | Aria2AI | 24/8/2026 | 8/9/2026 | Aria2 version 1.37.0 and below is affected by a Divide By Zero issue in src/bittorrent_helper.cc, which allows a remote malicious user to cause a Denial of Service | |
| Aplazada | Alta (7.1) | 0.25% | — | Swatchly - Woocommerce Variation Swatches FOR ProductsAI | 20/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products <= 1.4.13 versions. | |
| Aplazada | Baja (2.1) | 0.43% | — | Akariasai Self RAGAI | 13/7/2026 | 13/7/2026 | A vulnerability was determined in AkariAsai self-rag up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99. Affected by this issue is the function Indexer.deserialize_from of the file retrieval_lm/src/index.py of the component retrieval_lm. Executing a manipulation of the argument index_meta.faiss can lead to… | |
| Pendiente de análisis | Alta (7.6) | 0.47% | — | Langchain4jAILangchain4j-mariadbAILangchain4j-pgvectorAI | 10/7/2026 | 13/7/2026 | LangChain4j is a Java library for building LLM-powered applications on the JVM. Prior to 1.2.1-beta8, 1.5.1-beta11, 1.11.8-beta19, and 1.16.3-beta26, the MariaDB and pgvector embedding stores build metadata-filter SQL by string-concatenating filter keys, and in MariaDB string values, directly into the query without… | |
| Pendiente de análisis | Media (5.3) | 0.31% | — | Bitnami Mariadb GaleraAIBitnami Mariadb Galera Helm ChartAI | 18/6/2026 | 22/6/2026 | Bitnami MariaDB Galera container images and Helm chart are affected by a hardcoded default credential vulnerability in the Galera replication health-check user. The MARIADB_REPLICATION_USER and MARIADB_REPLICATION_PASSWORD environment variables defaulted to monitor and monitor respectively. This user is granted… | |
| Modificada | Alta (7.2) | 1.6% | — | Mariadb | 12/6/2026 | 3/8/2026 | MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, a high-privileged MariaDB user could've used wsrep_sst_receive_address or wsrep_sst_donor global system variables to execute… | |
| Modificada | Alta (7.2) | 1.1% | — | Mariadb | 12/6/2026 | 3/8/2026 | MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, during the SST the donor node is interpolating parameters that the joiner sent into the command line. Not all parameters were… | |
| Modificada | Media (5.3) | 0.84% | — | Mariadb | 12/6/2026 | 3/8/2026 | MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, MariaDB allowed SELECT ... INTO OUTFILE and SELECT ... INTO DUMPFILE without verifying the FILE privilege if the FROM clause… | |
| Modificada | Media (6.9) | 1.0% | — | MariadbRedhat Enterprise Linux | 12/6/2026 | 17/9/2026 | MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though… | |
| Analizada | Alta (7.8) | 0.17% | — | Mariadb | 12/6/2026 | 17/6/2026 | MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, mbstream did not check for /../ in the path when unpacking the archive. A proper backup can never contain such paths, but a… | |
| Modificada | Media (6.3) | 1.7% | — | Mariadb | 12/6/2026 | 3/8/2026 | MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, MariaDB on WIndows with installed CONNECT engine and enabled REST support interpolated table HTTP attribute into the curl… | |
| Analizada | Media (4.3) | 0.27% | — | Mariadb | 12/6/2026 | 17/6/2026 | MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting EXECUTE access to a stored routine via a role, could see the routine definition even without SHOW CREATE ROUTINE privilege. This issue has been patched in versions… | |
| Modificada | Alta (8) | 0.97% | — | Mariadb | 12/6/2026 | 3/8/2026 | MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before 10.11.17, 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, during the SST the donor node is interpolating parameters that the joiner sent into the command line. Not all parameters were… |