Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

106 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.2)0.25%—Apache CouchdbAIBudibaseAI27/5/202617/6/2026
Budibase is an open-source low-code platform. Prior to 3.38.2, the public API role unassignment endpoint (POST /api/public/v1/roles/unassign) updates user documents in CouchDB but does not invalidate the corresponding Redis user cache entries. Because the authentication middleware resolves user identity and…
AplazadaMedia (5.1)0.17%—CouchcmsAI16/5/202617/6/2026
CouchCMS 2.2.1 contains a cross-site scripting vulnerability that allows authenticated attackers to execute arbitrary JavaScript by uploading malicious SVG files through the file upload functionality. Attackers can upload SVG files containing embedded script tags to the browse.php endpoint, which are then executed in…
AplazadaMedia (5.3)0.24%—CouchcmsAI15/5/202617/6/2026
CouchCMS 2.2.1 contains a server-side request forgery vulnerability that allows authenticated attackers to make arbitrary HTTP requests by uploading malicious SVG files. Attackers can upload SVG files containing external entity references through the browse.php endpoint to access internal services and resources.
AnalizadaAlta (8.6)0.66%—Couchcms10/4/202614/7/2026
CouchCMS contains a privilege escalation vulnerability that allows authenticated Admin-level users to create SuperAdmin accounts by tampering with the f_k_levels_list parameter in user creation requests. Attackers can modify the parameter value from 4 to 10 in the HTTP request body to bypass authorization validation…
AplazadaAlta (7.5)0.39%—Perfood Couch-authAI5/3/202617/6/2026
An observable timing discrepancy in @perfood/couch-auth v0.26.0 allows attackers to access sensitive information via a timing side-channel.
AplazadaCrítica (9.3)0.36%—Perfood Couch-authAI5/3/202617/6/2026
A host header injection vulnerability in the mailer component of @perfood/couch-auth v0.26.0 allows attackers to obtain reset tokens and execute an account takeover via spoofing the HTTP Host header.
ModificadaMedia (6.5)6.1%—Couchcms9/1/202617/6/2026
** Disputed ** An Information Disclosure vulnerability in CouchCMS 2.4 allow an Admin user to read arbitrary files via traversing directories back after back. It can Disclosure the source code or any other confidential information if weaponize accordingly. NOTE: A community member states that this is not a CouchCMS…
ModificadaBaja (2.9)0.46%—Couchcms22/12/202517/6/2026
A security flaw has been discovered in CouchCMS up to 2.4. Affected is an unknown function of the file couch/config.example.php of the component reCAPTCHA Handler. The manipulation of the argument K_RECAPTCHA_SITE_KEY/K_RECAPTCHA_SECRET_KEY results in use of hard-coded cryptographic key . It is possible to launch the…
AnalizadaMedia (6.5)0.21%—Perfood Couchauth20/11/202517/6/2026
Session tokens and passwords in couch-auth 0.21.2 are stored in JavaScript objects and remain in memory without explicit clearing in src/user.ts lines 700-707. This creates a window of opportunity for sensitive data extraction through memory dumps, debugging tools, or other memory access techniques, potentially…
AnalizadaAlta (7.3)0.19%—Couchbase Sync Gateway29/7/202517/6/2026
An issue was discovered in Couchbase Sync Gateway before 3.2.6. In sgcollect_info_options.log and sync_gateway.log, there are cleartext passwords in redacted and unredacted output.
AnalizadaMedia (4.9)0.23%—Couchbase .net SDK18/6/202517/6/2026
The Couchbase .NET SDK (client library) before 3.7.1 does not properly enable hostname verification for TLS certificates. In fact, the SDK was also using IP addresses instead of hostnames due to a configuration option that was incorrectly enabled by default.
AnalizadaAlta (7.6)0.48%—Couchbase Server30/4/202517/6/2026
A security issue has been discovered in Couchbase Server before 7.6.4 and fixed in v.7.6.4 and v.7.2.7 for Windows that could allow unauthorized access to sensitive files. Depending on the level of privileges, this vulnerability may grant access to files such as /etc/passwd or /etc/shadow.
AplazadaAlta (7.3)0.32%—Perfood Couch-authAI10/2/202517/6/2026
A host header injection vulnerability exists in the NPM package of perfood/couch-auth <= 0.21.2. By sending a specially crafted host header in the email change confirmation request, it is possible to trigger a SSTI which can be leveraged to run limited commands or leak server-side information
AnalizadaMedia (6.5)0.34%—Couchbase Server27/1/202517/6/2026
An issue was discovered in Couchbase Server 7.6.x through 7.6.3. A user with the security_admin_local role can create a new user in a group that has the admin role.
ModificadaMedia (6.1)0.30%—Couchbase Server19/9/202417/6/2026
Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection.
ModificadaMedia (5.9)0.16%—Couchbase Server26/7/202417/6/2026
An issue was discovered in Couchbase Server before 7.2.5 and 7.6.0 before 7.6.1. It does not ensure that credentials are negotiated with the Key-Value (KV) service using SCRAM-SHA when remote link encryption is configured for Half-Secure.
AnalizadaAlta (7.5)0.75%—Couchbase Server27/3/202417/6/2026
An issue was discovered in Couchbase Server 6.6.x through 7.2.0, before 7.1.5 and 7.2.1. Unauthenticated users may cause memcached to run out of memory via large commands.
AnalizadaAlta (7.5)0.75%—Couchbase Server29/2/202417/6/2026
Couchbase Server before 7.2.4 has a private key leak in goxdcr.log.
AnalizadaAlta (8.6)0.68%—Couchbase Server29/2/202417/6/2026
An issue was discovered in Couchbase Server before 7.2.x before 7.2.4. otpCookie is shown with full admin on pools/default/serverGroups and engageCluster2.
AnalizadaMedia (5.3)0.24%—Couchbase Server29/2/202417/6/2026
An issue was discovered in Couchbase Server before 7.2.4. ns_server admin credentials are leaked in encoded form in the diag.log file. The earliest affected version is 7.1.5.
AnalizadaMedia (5.4)0.53%—Couchbase Server29/2/202417/6/2026
An issue was discovered in Couchbase Server before 7.2.4. An attacker can bypass SQL++ N1QL cURL host restrictions.
AnalizadaCrítica (9.8)0.90%—Couchbase Server29/2/202417/6/2026
An issue was discovered in Couchbase Server before 7.2.4. SQL++ cURL calls to /diag/eval are not sufficiently restricted.
ModificadaCrítica (9.8)0.90%—Couchbase Server29/2/202417/6/2026
An issue was discovered in Couchbase Server before 7.2.4. cURL calls to /diag/eval are not sufficiently restricted.
ModificadaMedia (4.3)0.76%—Couchbase Server29/2/202417/6/2026
An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (outage of reader threads).
AnalizadaMedia (6.3)0.44%—Couchbase Server29/2/202417/6/2026
An issue was discovered in Couchbase Server through 7.1.4 before 7.1.5 and before 7.2.1. There are Unauthenticated RMI Service Ports Exposed in Analytics.
Orbitaley — Vulnerabilidades