Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
2768 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.3) | 0.30% | — | Qt5compatAIQtbaseAI | 21/7/2026 | 23/7/2026 | An out-of-bounds read (buffer over-read) vulnerability exists in QTextCodec::codecForName() in Qt. When the function is called with a QByteArray that is not NUL-terminated (for example, one created with QByteArray::fromRawData()), the codec-name matching routine reads past the end of the supplied buffer. In most cases… | |
| Pendiente de análisis | Alta (8.5) | 0.35% | — | Google Cloud Firebase StudioAIGoogle Cloud PlatformAI | 17/7/2026 | 17/7/2026 | Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an attacker to download other users' deployed source code and access sensitive data via unauthorized GCS URL signing requests. This vulnerability was patched on 15 April 2026, and no customer action is… | |
| Aplazada | Media (6.7) | 0.72% | — | Nocobase Plugin BackupsAI | 15/7/2026 | 18/7/2026 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.1.19, NocoBase @nocobase/plugin-backups restored PostgreSQL backups by interpolating the database.schema value from _metadata.json into shell command strings executed with Node.js… | |
| Aplazada | Media (6.8) | 0.47% | — | NocobaseAINocobase Plugin Collection SQLAI | 15/7/2026 | 16/7/2026 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. In 2.0.59 and earlier, NocoBase @nocobase/plugin-collection-sql used the checkSQL() function in packages/plugins/@nocobase/plugin-collection-sql/src/server/utils.ts with an incomplete keyword blacklist that… | |
| Aplazada | Crítica (10) | 0.89% | 💥 PoC | Nocobase Plugin Notification IN APP MessageAI | 15/7/2026 | 20/7/2026 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/plugin-notification-in-app-message exposed GET /api/myInAppChannels:list, where the filter[latestMsgReceiveTimestamp][$lt] value was inserted into a Sequelize.literal()… | |
| Aplazada | Crítica (9.3) | 0.52% | — | SAP Cloud Application Programming ModelAICap-js Db-serviceAISqliteAISupabase PostgresAI | 15/7/2026 | 15/7/2026 | The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL database services for that tool. On April 29, 2026, compromised versions of `@cap-js/sqlite@2.2.2`, `@cap-js/postgres@2.2.2`, and `@cap-js/db-service@2.10.1` were… | |
| Analizada | Crítica (9.1) | 0.77% | — | Metabase | 15/7/2026 | 30/7/2026 | Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase user with permission to add or edit a database connection can achieve remote code execution on the Metabase server by configuring a Snowflake… | |
| Analizada | Alta (7.6) | 0.34% | — | Metabase | 15/7/2026 | 30/7/2026 | Metabase is an open-source business intelligence and embedded analytics tool. From 1.57.0 until 1.57.19.1, 1.58.14.1, 1.59.10, and 1.60.4, an attacker who can configure a Metabase database connection can read arbitrary files from the Metabase server's filesystem by adding unsafe JDBC parameters to a MySQL or MariaDB… | |
| Aplazada | Alta (8.7) | 0.46% | — | CapgoAISupabase PostgrestAI | 15/7/2026 | 15/7/2026 | Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST SECURITY DEFINER RPC function public.rescind_invitation that allows unauthenticated attackers to enumerate organization existence. The function returns distinct error messages (NO_ORG vs NO_RIGHTS) when… | |
| Pendiente de análisis | Baja (3.7) | 0.35% | — | SAP Hana DatabaseAI | 14/7/2026 | 14/7/2026 | SAP HANA Database (user self service tools) allows an unauthenticated user to send specially crafted requests that produce distinguishable responses, enabling enumeration of valid user accounts and email addresses. Successful exploitation could allow the attacker to enumerate valid user accounts, resulting in low… | |
| Aplazada | Media (5) | 0.22% | — | Database FOR Contact Form 7 Wpforms Elementor FormsAI | 13/7/2026 | 13/7/2026 | The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.2 does not restrict the PHP classes allowed when unserializing an attacker-supplied form-field value, allowing unauthenticated users to inject arbitrary PHP objects that are instantiated when an administrator views the stored entry.… | |
| Aplazada | Media (6.9) | 0.41% | — | Ragic Enterprise Cloud DatabaseAI | 13/7/2026 | 14/7/2026 | Enterprise Cloud Database developed by Ragic has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload malicious files and make them available for users to download. | |
| Aplazada | Media (5.3) | 0.34% | — | Ragic Enterprise Cloud DatabaseAI | 13/7/2026 | 14/7/2026 | Enterprise Cloud Database developed by Ragic has a Stored Cross-Site Scripting vulnerability, allowing unauthenticated remote attackers to inject persistent JavaScript code executed in users' browsers upon page load. | |
| Aplazada | Alta (8.7) | 0.56% | — | CapgoAISupabase PostgrestAI | 12/7/2026 | 13/7/2026 | Capgo before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST global_stats endpoint that allows unauthenticated attackers to read sensitive financial and operational metrics using only the public apikey. Remote attackers can query the /rest/v1/global_stats endpoint to expose MRR,… | |
| Aplazada | Media (5.1) | 0.50% | — | Grav-plugin-databaseAI | 10/7/2026 | 13/7/2026 | grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, Database::__call builds PDO DSN strings by directly concatenating user-configurable YAML values from fields such as host, dbname, charset, server, database, directory, and filename without sanitization or validation, allowing an administrator… | |
| Aplazada | Crítica (9.2) | 0.53% | — | Grav-plugin-databaseAI | 10/7/2026 | 10/7/2026 | grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, the PDO::tableExists method interpolates its table argument directly into a raw SQL query string without sanitization, escaping, quoting, or whitelisting, allowing attacker-controlled table names passed by consuming plugin or developer code to… | |
| Analizada | Alta (8.8) | 3.8% | 💥 Exploit | Metabase | 9/7/2026 | 13/7/2026 | Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection, including the default sample database, deserialize arbitrary Java objects returned in H2 native query result columns of type OTHER without… | |
| Analizada | Crítica (9.1) | 1.0% | — | Metabase | 9/7/2026 | 30/7/2026 | Metabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 until 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2, Metabase did not validate unsafe H2 connection properties on one database-creation code path, allowing an authenticated administrator to register a crafted H2 database connection… | |
| Pendiente de análisis | Media (6.3) | 0.23% | — | Siemens Cpci85AISiemens Sicore Base SystemAI | 9/7/2026 | 9/7/2026 | A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application ships with a default configuration that disables all OPC UA security mechanisms. This could allow an attacker to gain unauthorized access and… | |
| Analizada | Media (6.1) | 0.56% | 💥 Exploit | Appium/base-driver | 8/7/2026 | 15/7/2026 | Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior to 10.7.0, Appium's base-driver unconditionally mounts the /test/guinea-pig, /test/guinea-pig-scrollable, and /test/guinea-pig-app-banner routes, and compileLodashTemplate reflects the throwError… | |
| Aplazada | Media (6.9) | 0.36% | — | CapgoAISupabase PostgrestAI | 8/7/2026 | 8/7/2026 | Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST RPC function public.get_total_metrics(org_id), which is callable by the anon role using only the public sb_publishable_* key. An unauthenticated attacker can probe organization existence and leak sensitive… | |
| Aplazada | Alta (8.7) | 0.43% | — | CapgoAISupabase PostgrestAI | 8/7/2026 | 8/7/2026 | Capgo (Cap-go/capgo) before 12.128.2 exposes the Supabase PostgREST RPC function public.get_orgs_v6(userid uuid), which is SECURITY DEFINER and granted to the anon role, allowing unauthenticated access. Because the function accepts a caller-supplied user UUID without verifying it matches the authenticated user, an… | |
| Aplazada | Media (5.1) | 0.34% | — | NocobaseAI | 7/7/2026 | 14/7/2026 | NocoBase through 2.1.20 contains a server-side request forgery vulnerability in the serverRequest wrapper that allows authenticated administrators to issue arbitrary outbound HTTP requests by supplying malicious URLs to workflow request nodes, custom request action buttons, or the AI plugin. Attackers can target… | |
| Aplazada | Alta (7.2) | 2.7% | — | Wpseeds WP Database BackupAI | 2/7/2026 | 2/7/2026 | The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to OS Command Injection in all versions up to and including 7.11 via the `wp_db_exclude_table` parameter. This is due to the direct concatenation of user-supplied `$_POST['wp_db_exclude_table']` values into… | |
| Aplazada | Alta (8.7) | 0.97% | — | Supabase AuthAI | 1/7/2026 | 2/7/2026 | @acastellon/auth is an authentication control system for microservices. Versions prior to 2.3.0 appear to allow an unauthenticated authentication bypass in validateToken() through spoofable auth-user and Host request headers. The validateToken middleware contains a service-to-service bypass for auth-user:… |