Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
5029 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.34% | — | Data443 Gdpr FrameworkAI | 6/10/2026 | 6/10/2026 | Unauthenticated PHP Object Injection in GDPR Framework By Data443 <= 2.5.0 versions. | |
| Aplazada | Alta (7.1) | 0.24% | — | Database FOR CF7AI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Database for CF7 <= 1.2.6 versions. | |
| Pendiente de análisis | Crítica (9.3) | 0.74% | — | Atlassian Bitbucket Data CenterAIAtlassian Confluence Data CenterAIAtlassian Jira Service Management Data CenterAIAtlassian Jira Software Data CenterAI+4 | 5/10/2026 | 6/10/2026 | This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web… | |
| Aplazada | Alta (7.1) | 0.36% | — | 4TU Researchdata DjehutyAI | 1/10/2026 | 2/10/2026 | djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, An unauthenticated attacker can inject SPARQL into the search/listing queries through three separate parameters. Because the affected queries are read (SELECT) queries, this does not write to the store, but it allows:… | |
| Pendiente de análisis | Alta (7.5) | 0.67% | — | Fasterxml Jackson-dataformats-binaryAI | 1/10/2026 | 2/10/2026 | The Smile parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this format. SmileParser._handleLongFieldName() grows its internal name buffer through an unconstrained… | |
| Pendiente de análisis | Alta (7.5) | 0.67% | — | Fasterxml Jackson Dataformats BinaryAI | 1/10/2026 | 2/10/2026 | The CBOR parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this format. CBORParser._decodeLongerName() decodes a definite-length property name with no length check, and… | |
| Aplazada | Alta (8.4) | 0.30% | — | 4tu.researchdata DjehutyAI | 1/10/2026 | 6/10/2026 | djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, an authenticated depositor can inject arbitrary SPARQL into a state-modifying (DELETE/INSERT) query by supplying a crafted session name, letting them write (and delete) arbitrary triples anywhere in the RDF store.… | |
| Aplazada | Baja (2.1) | 0.23% | — | Datadrivenconstruction OpenconstructionerpAI | 1/10/2026 | 1/10/2026 | A vulnerability was found in datadrivenconstruction OpenConstructionERP up to 14.8.1. The impacted element is an unknown function of the file backend/app/modules/ai/ai_client.py of the component Al Provider Configuration Handler. Performing a manipulation results in exposure of data element to wrong session. The… | |
| Aplazada | Baja (2.1) | 0.21% | — | David-crty DatabasementAI | 1/10/2026 | 5/10/2026 | A vulnerability was determined in David-Crty databasement up to 1.7.1. Affected is the function SnapshotPolicy.viewAny/SnapshotPolicy.view of the file /api/v1/snapshots of the component Snapshot Model. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has… | |
| Aplazada | Baja (1.2) | 0.29% | — | David-crty DatabasementAI | 1/10/2026 | 1/10/2026 | A vulnerability was found in David-Crty databasement up to 1.7.1. This impacts the function https:/github.com/David-Crty/databasement/pull/511 of the file app/Http/Requests/Api/V1/RestoreRequest.php of the component database-servers API Endpoint. The manipulation of the argument schema_name results in path traversal.… | |
| Pendiente de análisis | Baja (1.1) | 0.29% | — | Wikimedia CommonsmetadataAI | 30/9/2026 | 1/10/2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki CommonsMetadata extension allows Cross-Site Scripting (XSS). This issue affects MediaWiki CommonsMetadata extension: 1.46, 1.45, and 1.43. | |
| En análisis | Alta (7.1) | 0.24% | — | Kiteworks Secure Data FormsAI | 30/9/2026 | 1/10/2026 | A SQL injection vulnerability existed in Kiteworks Secure Data Forms, where a value derived from the authenticated user's stored account data was incorporated into a database query without proper sanitization. An authenticated user could potentially influence that value to inject SQL. Exploitation requires an… | |
| En análisis | Alta (7.5) | 0.32% | — | Kiteworks Secure Data FormsAI | 30/9/2026 | 1/10/2026 | Kiteworks Secure Data Forms before version 9.5.0 is vulnerable to Server-Side Request Forgery that could allow an unauthenticated, remote attacker to make the server issue arbitrary outbound network requests and read back the responses. This could potentially be used to reach internal-only services or other… | |
| Aplazada | Alta (8.8) | 0.29% | — | ALL IN ONE Structured DataAI | 30/9/2026 | 30/9/2026 | Contributor PHP Object Injection in Schema & Structured Data for WP & AMP <= 1.66 versions. | |
| Aplazada | Alta (8.2) | 0.25% | — | Wpdataaccess WP Data AccessAI | 30/9/2026 | 30/9/2026 | Unauthenticated SQL Injection in WP Data Access <= 5.5.84 versions. | |
| Aplazada | Baja (3.5) | 0.14% | — | ALL IN ONE Schemas Schema AND Structured Data FOR WP AND AMPAI | 30/9/2026 | 30/9/2026 | The Schema & Structured Data for WP & AMP WordPress plugin before 1.67 does not perform a capability check when saving several of its fields, nor escape them when outputting them back, allowing users with the editor role and above to inject arbitrary web scripts that execute when a higher privileged user views the… | |
| Analizada | Alta (8.1) | 0.39% | — | IBM Guardium Data Protection | 29/9/2026 | 1/10/2026 | IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An authenticated remote attacker could exploit this vulnerability to delete files and potentially cause denial of service or impact system integrity. | |
| Analizada | Alta (8.8) | 0.74% | — | IBM Guardium Data Protection | 29/9/2026 | 1/10/2026 | IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can influence policy alert text can cause attacker-controlled data to be executed as operating system commands by the SNMP alerter service, which runs with root privileges. | |
| Analizada | Crítica (9.1) | 0.68% | — | IBM Guardium Data Protection | 29/9/2026 | 2/10/2026 | IBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export CLI functionality, allowing a privileged authenticated CLI user to execute arbitrary commands with root privileges. | |
| Analizada | Alta (7.2) | 0.68% | — | IBM Guardium Data Protection | 29/9/2026 | 2/10/2026 | IBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME recipient deletion functionality, allowing an authenticated privileged CLI user to execute arbitrary commands with root privileges. | |
| Analizada | Alta (8.8) | 0.57% | — | IBM Datastage ON Cloud PAK FOR Data | 29/9/2026 | 2/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of paths during archive extraction. | |
| Pendiente de análisis | Alta (8.6) | 0.37% | — | Google MCP Toolbox FOR DatabasesAI | 29/9/2026 | 29/9/2026 | Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0 allows a remote authenticated attacker with tool execution permissions to bypass directory boundary restrictions via symbolic links. Because path validation checks… | |
| Pendiente de análisis | Alta (7.5) | 0.34% | — | Wikimedia DatatransferAI | 29/9/2026 | 1/10/2026 | Dependency on Vulnerable Third-Party Component and Uncontrolled Resource Consumption vulnerability in Wikimedia Foundation Mediawiki - DataTransfer Extension allows Excessive Allocation. This issue affects Mediawiki - DataTransfer Extension: from 1.46.0 before 1.47.0. | |
| Pendiente de análisis | Media (6.3) | 0.39% | — | Apache Airflow Teradata ProviderAI | 29/9/2026 | 29/9/2026 | The Apache Airflow Teradata provider's compute-cluster example Dag declared every one of its Dag Params as unconstrained free text and templated them straight into the compute-cluster operators, which interpolate those values into Teradata DDL. A user who is permitted to trigger that Dag - a lower-trust role than the… | |
| Pendiente de análisis | Media (6.5) | 0.28% | — | Apache Airflow Providers TeradataAI | 29/9/2026 | 29/9/2026 | Apache Airflow's Teradata provider embedded cloud storage credentials directly into SQL statements. `S3ToTeradataOperator` and `AzureBlobStorageToTeradataOperator` interpolate the source bucket's credentials as plain string literals into the `CREATE MULTISET TABLE ... LOCATION` statement whenever the bucket is private… |