Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

571 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.14%—Snowflake Connector29/1/202517/6/2026
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. On Linux systems, when temporary credential caching is enabled, the…
AnalizadaAlta (7.8)0.25%—Snowflake Connector29/1/202517/6/2026
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. The OCSP response cache uses pickle as the serialization format,…
AnalizadaAlta (7)0.33%—Snowflake Connector29/1/202517/6/2026
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. A function from the snowflake.connector.pandas_tools module is…
AnalizadaMedia (5.5)0.14%—Snowflake Connector29/1/202517/6/2026
snowflake-connector-net is the Snowflake Connector for .NET. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them accessible to unauthorized users on the same machine. This…
AnalizadaMedia (5.5)0.15%—Snowflake Connector29/1/202517/6/2026
snowflake-connector-nodejs is a NodeJS driver for Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake NodeJS Driver. File permissions checks of the temporary credential cache could be bypassed by an attacker with write access to the local cache directory. This vulnerability affects versions…
AnalizadaMedia (6.4)0.46%—Oracle Mysql Connector/python21/1/202517/6/2026
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require…
AplazadaMedia (4.3)0.17%—Shipworks Connector FOR WoocommerceAI18/1/202517/6/2026
The ShipWorks Connector for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.2.5. This is due to missing or incorrect nonce validation on the 'shipworks-wordpress' page. This makes it possible for unauthenticated attackers to update the services…
AplazadaAlta (8.7)0.55%—Cloudera Jdbc Connector FOR HiveAICloudera Jdbc Connector FOR ImpalaAI16/1/202517/6/2026
A JNDI injection issue was discovered in Cloudera JDBC Connector for Hive before 2.6.26 and JDBC Connector for Impala before 2.6.35. Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This could lead…
ModificadaMedia (6.1)0.34%—Gsheetconnector FOR Forminator Forms15/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WesternDeal GSheetConnector for Forminator Forms gsheetconnector-forminator allows Reflected XSS.This issue affects GSheetConnector for Forminator Forms: from n/a through <= 1.0.12.
AnalizadaAlta (8.8)1.1%—Fortinet Fortisoar Imap Connector14/1/202517/6/2026
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR IMAP connector version 3.5.7 and below may allow an authenticated attacker to execute unauthorized code or commands via a specifically crafted playbook
AnalizadaAlta (8.5)0.31%💥 PoCForescout Secureconnector2/1/202517/6/2026
A vulnerability in Forescout SecureConnector v11.3.07.0109 on Windows allows unauthenticated user to modify compliance scripts due to insecure temporary directory.
AplazadaMedia (6.5)0.30%—Storeapps Putler Connector FOR WoocommerceAI2/1/202517/6/2026
Missing Authorization vulnerability in Putler / Storeapps Putler Connector for WooCommerce.This issue affects Putler Connector for WooCommerce: from n/a through 2.12.0.
AnalizadaAlta (8.6)0.53%—Amazon Redshift Connector24/12/202417/6/2026
A SQL injection in the Amazon Redshift Python Connector v2.1.4 allows a user to gain escalated privileges via the get_schemas, get_tables, or get_columns Metadata APIs. Users are recommended to upgrade to the driver version 2.1.5 or revert to driver version 2.1.3.
AplazadaCrítica (9.8)1.7%💥 PoCDenniskravetstns VrpconnectorAI18/12/202417/6/2026
Deserialization of Untrusted Data vulnerability in denniskravetstns VRPConnector vrpconnector allows Object Injection.This issue affects VRPConnector: from n/a through <= 2.0.1.
AplazadaAlta (8.1)0.51%—Dapperduckling Keycloak Connector ServerAI26/11/202417/6/2026
@dapperduckling/keycloak-connector-server is an opinionated series of libraries for Node.js applications and frontend clients to interface with keycloak. A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the authentication flow of the application. This issue arises due to improper sanitization of…
AnalizadaMedia (5.5)0.20%—Snowflake Connector24/10/202417/6/2026
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Prior to version 3.12.3, when the logging level was set by the user to DEBUG, the Connector could have logged Duo passcodes (when specified via the `passcode`…
AnalizadaMedia (5.8)0.14%—Forescout Secureconnector23/10/202417/6/2026
Denial of Service in Forescout SecureConnector 11.1.02.1019 on Windows allows Unprivileged user to corrupt the configuration file and cause Denial of Service in the application.
AnalizadaMedia (6.5)0.57%💥 PoCNetapp Oncommand InsightOracle Mysql Connector/odbc15/10/202418/9/2026
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). Supported versions that are affected are 9.0.0 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this…
AnalizadaCrítica (9.8)0.94%💥 PoCPedalo Connector11/10/202417/6/2026
The Pedalo Connector plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.5. This is due to insufficient restriction on the 'login_admin_user' function. This makes it possible for unauthenticated attackers to log to the first user, who is usually the administrator, or if it…
AnalizadaCrítica (9.1)1.6%—Microsoft Azure Command-line InterfaceMicrosoft Azure Service Connector8/10/202417/6/2026
Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability
AplazadaMedia (5.3)0.42%—M-files Connector FOR CopilotAI2/10/202417/6/2026
Permissions bypass in M-Files Connector for Copilot before version 24.9.3 allows authenticated user to access limited amount of documents via incorrect access control list calculation
AnalizadaMedia (5.9)0.33%—Apache Tomcat ConnectorsDebian Linux23/9/202417/6/2026
Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configuration which may lead to information disclosure and/or denial of service. This issue affects Apache Tomcat Connectors: from 1.2.9-beta through 1.2.49. Only mod_jk on Unix…
AnalizadaCrítica (9.8)0.75%—Zscaler Client Connector6/8/202417/6/2026
An Improper Input Validation vulnerability in Zscaler Client Connector on MacOS allows OS Command Injection. This issue affects Zscaler Client Connector on MacOS <4.2.
AnalizadaMedia (4.9)0.43%—Zscaler Client Connector6/8/202417/6/2026
In certain cases, Zscaler Internet Access (ZIA) can be disabled by PowerShell commands with admin rights. This affects Zscaler Client Connector on Windows <4.2.1
AnalizadaAlta (7.8)0.13%—Zscaler Client Connector6/8/202417/6/2026
The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrary code to be locally executed. This affects Zscaler Client Connector on MacOS <4.2.
Orbitaley — Vulnerabilidades