Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
5033 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.79% | — | Datadog DD Trace RSAI | 28/8/2026 | 9/9/2026 | dd-trace-rs provides Datadog application performance monitoring for Rust. From 0.1.0 until 0.3.3, datadog-opentelemetry/src/propagation/tracecontext.rs parses the W3C tracestate header and collects every semicolon-separated key and value pair in the Datadog dd=... vendor entry into a HashMap without enforcing a pair… | |
| Aplazada | Media (5.1) | 0.44% | — | Watchguard Dimension Database ServerAI | 28/8/2026 | 28/8/2026 | A blind server-side request forgery (SSRF) vulnerability WatchGuard Dimension Database Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems. | |
| Analizada | Alta (7.1) | 0.35% | — | Vmware Spring Data Rest | 27/8/2026 | 2/9/2026 | Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 JSON Patch (application/json-patch+json) requests. Spring Data REST 5.1.0 Spring Data REST 5.0.0 - 5.0.6 Spring Data REST 4.5.0 - 4.5.12 Spring Data REST 4.0.0 - 4.4.15 Spring Data REST 3.7.20 and earlier | |
| Analizada | Media (4.3) | 0.31% | — | Vmware Spring Data Rest | 27/8/2026 | 4/9/2026 | Spring Data REST does not preserve the persisted version (@Version) property of an aggregate root when handling an HTTP PUT against an immutable target type. Spring Data REST 5.1.0 Spring Data REST 5.0.0 - 5.0.6 Spring Data REST 4.5.0 - 4.5.12 Spring Data REST 4.0.0 - 4.4.15 Spring Data REST 3.7.20 and earlier | |
| Analizada | Media (6.5) | 0.34% | — | Vmware Spring Data JPA | 26/8/2026 | 4/9/2026 | Spring Data JPA's Sort validation can be bypassed when parameters containing crafted payload are accepted from untrusted sources. Spring Data JPA 4.1.0 Spring Data JPA 4.0.0 - 4.0.6 Spring Data JPA 3.5.0 - 3.5.13 Spring Data JPA 3.0.0 - 3.4.15 | |
| Aplazada | Alta (8.5) | 0.55% | — | Open-metadata OpenmetadataAI | 26/8/2026 | 16/9/2026 | OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLoginServlet reads the callback request parameter and stores it in the HTTP session without comparing it against any configured or registered destination, and the assertion consumer servlet later formats… | |
| Pendiente de análisis | Crítica (9.4) | 0.45% | — | Google Cloud Bigquery Data Transfer ServiceAICdata Jdbc DriverAI | 26/8/2026 | 31/8/2026 | An Improper Input Validation vulnerability in CData JDBC driver integration in Google Cloud BigQuery Data Transfer Service versions prior to 2026-05-01 on Google Cloud Platform allows an authenticated attacker to achieve remote code execution in the connector container and escalate privileges in the tenant project… | |
| Aplazada | Media (5.3) | 0.40% | — | Wpdataaccess WP Data AccessAI | 26/8/2026 | 28/8/2026 | The WP Data Access plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.5.68 via the 'check_app_access' function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to access data from protected app… | |
| Aplazada | Alta (8.7) | 0.31% | — | Innodata Labs PopplerAIPopplerAI | 25/8/2026 | 28/9/2026 | Denial-of-service (DoS) vulnerability in the internal JPEG2000 (JPX) decoding implementation of the Poppler fork developed by Innodata Labs. When an application processes an untrusted PDF file containing specially crafted JPXDecode images, a remote attacker can cause uncontrolled memory consumption. The flaw occurs in… | |
| Aplazada | Media (5.3) | 0.31% | — | Fasterxml Jackson-databindAI | 24/8/2026 | 9/9/2026 | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Prior to versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1 on their respective release lines, the java.net.InetAddress branch of FromStringDeserializer.Std._deserialize() calls InetAddress.getByName() on… | |
| Analizada | Crítica (10) | 0.80% | — | Microsoft Azure SQL Database | 21/8/2026 | 4/9/2026 | Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Alta (7.1) | 0.50% | — | Juicedata JuicefsAI | 21/8/2026 | 24/9/2026 | The filestore backend in pkg/object/file.go, used for file:// stores and as a common juicefs sync destination, derived every operation's target from path(key), which returned either filepath.Join(d.root, key) or filepath.Clean(d.root + key) with no check that the result stayed beneath the root. Put, Get, Head, Delete,… | |
| Aplazada | Crítica (9.3) | 0.52% | — | Datiphy Data Management CenterAI | 21/8/2026 | 26/8/2026 | External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to write files to arbitrary locations outside the intended upload directory via relative or absolute path sequences. | |
| Aplazada | Alta (8.8) | 0.73% | — | Datiphy Data Management CenterAI | 21/8/2026 | 26/8/2026 | Missing authentication for a critical function in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an unauthenticated remote attacker to upload arbitrary files to the server's configured upload directory. | |
| Aplazada | Crítica (9.4) | 1.1% | — | Datiphy Data Management CenterAI | 21/8/2026 | 26/8/2026 | OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an authenticated administrator to execute arbitrary operating system commands as root. | |
| Aplazada | Crítica (9.3) | 0.49% | — | Datiphy Data Management CenterAI | 21/8/2026 | 26/8/2026 | Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to gain administrative access to the management platform by logging in with default administrator credentials. | |
| Analizada | Alta (8.8) | 0.74% | — | Microsoft Azure Data Manager FOR Energy | 20/8/2026 | 4/9/2026 | Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network. | |
| Analizada | Crítica (9.9) | 0.99% | — | Microsoft Azure SQL Database | 20/8/2026 | 24/8/2026 | Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.9) | 0.99% | — | Microsoft Azure SQL Database | 20/8/2026 | 24/8/2026 | Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.5) | 0.97% | — | Microsoft Azure Data Factory | 20/8/2026 | 24/8/2026 | Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Crítica (9.1) | 0.86% | — | Microsoft Azure SQL Database | 20/8/2026 | 24/8/2026 | Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.8) | 0.53% | — | Microsoft Azure Data Factory | 20/8/2026 | 24/8/2026 | Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Alta (7.2) | 1.3% | — | Heimdall Data Database ProxyAI | 20/8/2026 | 1/9/2026 | Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentication is required to exploit this vulnerability. The specific flaw exists within the… | |
| Aplazada | Crítica (9.8) | 0.69% | — | Osnexus QuantastorAIInfluxdata KapacitorAI | 20/8/2026 | 1/9/2026 | OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OSNEXUS QuantaStor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of… | |
| Aplazada | Alta (7.1) | 0.25% | — | WpdatatablesAI | 20/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.4 versions. |