Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
2768 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.41% | — | Wpbase CacheAI | 6/10/2026 | 6/10/2026 | Subscriber Denial of Service Attack in WPBase Cache <= 5.5.6 versions. | |
| Aplazada | Alta (7.1) | 0.24% | — | Database FOR CF7AI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Database for CF7 <= 1.2.6 versions. | |
| En análisis | Crítica (9.9) | 0.40% | — | LangflowAILangflow-baseAILangflow LFXAI | 5/10/2026 | 6/10/2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.3, the MCP stdio transport launched whatever command / args a user put in an MCP server configuration, with no allowlist and (before 1.10.3) wrapped in bash -c "exec {command} ...". Any user able to reach the MCP server… | |
| Aplazada | Alta (8.5) | 0.26% | — | Wp-base WP Base BookingAI | 5/10/2026 | 6/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue affects WP BASE Booking: from n/a through 6.4.0. | |
| Aplazada | Crítica (9.3) | 0.25% | — | Wp-base WP Base BookingAI | 5/10/2026 | 6/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue affects WP BASE Booking: from n/a through 6.4.0. | |
| Aplazada | Baja (2.1) | 0.30% | — | JeebaseAI | 5/10/2026 | 6/10/2026 | A vulnerability was determined in Jeebase 0.0.1. This vulnerability affects the function updateUser of the file /user/update/info of the component UserService. Executing a manipulation of the argument user/tempUser can lead to dynamically-determined object attributes. The attack can be executed remotely. The exploit… | |
| Pendiente de análisis | Crítica (9) | 0.38% | — | 389project 389 DS BaseAI | 1/10/2026 | 2/10/2026 | A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in place of the client's… | |
| Pendiente de análisis | Alta (7.5) | 0.35% | — | Port389 389-ds-baseAI | 1/10/2026 | 2/10/2026 | A flaw was found in 389-ds-base. An unauthenticated remote attacker can send a complete LDAP operation followed by the first bytes of an incomplete LDAPMessage on the same connection, causing the server to hand that connection to a second worker thread before the first worker's result is flushed. The second worker… | |
| Aplazada | Alta (8.3) | 0.26% | — | BudibaseAI | 1/10/2026 | 1/10/2026 | Budibase through 3.41.0 contains a server-side request forgery vulnerability in AI table generation because the uploadUrl function in packages/server/src/utilities/fileUtils.ts uses raw node-fetch instead of fetchWithBlacklist. Authenticated builder users can send a prompt to POST /api/ai/tables that places an… | |
| Aplazada | Baja (2.1) | 0.21% | — | David-crty DatabasementAI | 1/10/2026 | 5/10/2026 | A vulnerability was determined in David-Crty databasement up to 1.7.1. Affected is the function SnapshotPolicy.viewAny/SnapshotPolicy.view of the file /api/v1/snapshots of the component Snapshot Model. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has… | |
| Aplazada | Baja (1.2) | 0.29% | — | David-crty DatabasementAI | 1/10/2026 | 1/10/2026 | A vulnerability was found in David-Crty databasement up to 1.7.1. This impacts the function https:/github.com/David-Crty/databasement/pull/511 of the file app/Http/Requests/Api/V1/RestoreRequest.php of the component database-servers API Endpoint. The manipulation of the argument schema_name results in path traversal.… | |
| Pendiente de análisis | Baja (0.3) | 0.11% | — | Wikimedia WikbaseAI | 30/9/2026 | 30/9/2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Wikbase extension allows Cross-Site Scripting (XSS). This issue affects MediaWiki Wikbase extension: 1.46, 1.45, and 1.43. | |
| Pendiente de análisis | Alta (7.2) | 0.28% | — | Wikimedia WikibaseAI | 30/9/2026 | 30/9/2026 | Deserialization of untrusted data vulnerability in The Wikimedia Foundation MediaWiki Wikibase extension allows Leverage Executable Code in Non-Executable Files. This issue affects MediaWiki Wikibase extension: 1.46, 1.45, and 1.43. | |
| Pendiente de análisis | Media (6.3) | 0.47% | — | VaadinAIVaadin CoreAIVaadin Charts FlowAIVaadin ChartsAI+1 | 30/9/2026 | 30/9/2026 | A prototype pollution vulnerability exists in the deep merge helpers of Vaadin Charts and Vaadin Component Base. Merging an object the application does not control into a chart configuration or into a component's i18n property writes onto Object.prototype, making the injected properties visible to every object in the… | |
| Pendiente de análisis | Alta (8.6) | 0.34% | — | BasercmsAI | 30/9/2026 | 30/9/2026 | When converting baserCMS4-style addons to baserCMS5-style ones, BcAddonMigrator includes "config.php" from the addon, which means the PHP code in the file is executed. Arbitrary files on the system may be read or deleted by an administrative user. | |
| Aplazada | Media (5.1) | 0.14% | — | BasercmsAI | 30/9/2026 | 1/10/2026 | A stored cross-site scripting vulnerability via custom content descriptions exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser. | |
| Aplazada | Media (5.1) | 0.15% | — | BasercmsAI | 30/9/2026 | 1/10/2026 | A cross-site scripting vulnerability via script validation bypass exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser. | |
| Aplazada | Media (6.9) | 0.32% | — | BasercmsAI | 30/9/2026 | 1/10/2026 | A missing authentication for critical function vulnerability exists in baserCMS. If this vulnerability is exploited, a remote attacker may obtain sensitive information. | |
| Aplazada | Media (5.1) | 0.14% | — | BasercmsAI | 30/9/2026 | 1/10/2026 | A stored cross-site scripting vulnerability via appended strings in email form fields exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser. | |
| Aplazada | Crítica (9.1) | 0.24% | — | Bytebase DbhubAI | 29/9/2026 | 30/9/2026 | bytebase dbhub v1.2.0 was discovered to contain a SQL injection vulnerability in the /utils/sql-parser.ts component. This vulnerability allows attackers to access sensitive databse information via a crafted SQL statement. | |
| Aplazada | Alta (8.8) | 0.15% | — | Basecamp UprightAI | 29/9/2026 | 30/9/2026 | basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f contains a login cross-site request forgery issue in the static credentials callback. | |
| Pendiente de análisis | Alta (8.6) | 0.37% | — | Google MCP Toolbox FOR DatabasesAI | 29/9/2026 | 29/9/2026 | Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0 allows a remote authenticated attacker with tool execution permissions to bypass directory boundary restrictions via symbolic links. Because path validation checks… | |
| Pendiente de análisis | Media (6.1) | 0.15% | — | Wikimedia WikibaseAI | 29/9/2026 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Wikibase Extension allows Stored XSS. This issue affects Mediawiki - Wikibase Extension: from * before 1.46.1, 1.45.5, 1.43.10. | |
| Aplazada | Alta (7.1) | 0.26% | — | BudibaseAI | 26/9/2026 | 28/9/2026 | Budibase server before 3.45.0 contains a cross-tenant information disclosure vulnerability in the GET /api/applications/:appId/appPackage endpoint that allows authenticated users to read another tenant's application metadata and source code. Attackers can supply a victim tenant's app id to retrieve sensitive… | |
| Aplazada | Alta (7) | 0.26% | — | Budibase ServerAI | 26/9/2026 | 28/9/2026 | Budibase Server before 3.45.0 fails to redact plaintext datasource credentials before broadcasting external table updates to the Builder collaboration websocket room. Attackers with Builder access can intercept unredacted datasource objects containing database passwords and API keys by observing table save or delete… |