Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2756▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 162 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
1243 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.36% | — | Crmperks Database FOR Contact Form 7, Wpforms, Elementor Forms | 29/12/2023 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja Forms.This issue affects Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja Forms: from n/a through 1.2.8. | |
| Modificada | Alta (7.2) | 0.74% | — | Sigmaplugin Advanced Database Cleaner | 19/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Younes JFR. Advanced Database Cleaner.This issue affects Advanced Database Cleaner: from n/a through 3.1.2. | |
| Modificada | Alta (8.8) | 0.25% | — | Xnau Participants Database | 19/12/2023 | 17/6/2026 | Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in Roland Barker, xnau webdesign Participants Database allows Accessing Functionality Not Properly Constrained by ACLs, Cross Site Request Forgery.This issue affects Participants Database: from n/a through 2.5.5. | |
| Modificada | Alta (8.8) | 0.34% | — | Xnau Participants Database | 9/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Roland Barker, xnau webdesign Participants Database plugin <= 2.4.9 versions. | |
| Modificada | Media (6.1) | 0.61% | — | Mldb Machine Learning Database | 9/11/2023 | 17/6/2026 | Cross Site Scripting vulnerability in MLDB.ai v.2017.04.17.0 allows a remote attacker to execute arbitrary code via a crafted payload to the public_html/doc/index.html. | |
| Modificada | Media (5.4) | 0.41% | — | Timeteccloud Auto Web-based Database Management System | 8/11/2023 | 17/6/2026 | Cross Site Scripting vulnerability in timetec AWDMS v.2.0 allows an attacker to obtain sensitive information via a crafted payload to the remark parameter of the New Zone function. | |
| Modificada | Media (5.4) | 0.34% | — | Ragic Enterprise Cloud Database | 3/11/2023 | 17/6/2026 | Rogic No-Code Database Builder's file uploading function has insufficient filtering for special characters. A remote attacker with regular user privilege can inject JavaScript to perform XSS (Stored Cross-Site Scripting) attack. | |
| Modificada | Crítica (9.8) | 0.74% | — | Crmperks Database FOR Contact Form 7, Wpforms, Elementor Forms | 31/10/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks Database for Contact Form 7, WPforms, Elementor forms contact-form-entries allows SQL Injection.This issue affects Database for Contact Form 7, WPforms, Elementor forms: from n/a through 1.3.0. | |
| Modificada | Media (4.3) | 0.38% | — | Oracle Database Server | 17/10/2023 | 17/6/2026 | Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.20 and 21.3-21.11. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful… | |
| Modificada | Media (4.9) | 0.63% | 💥 PoC | Oracle Database Server | 17/10/2023 | 17/6/2026 | Vulnerability in the Oracle Database Recovery Manager component of Oracle Database Server. Supported versions that are affected are 19.3-19.20 and 21.3-21.11. Easily exploitable vulnerability allows high privileged attacker having DBA account privilege with network access via Oracle Net to compromise Oracle Database… | |
| Modificada | Baja (2.4) | 0.40% | — | Oracle Database Server | 17/10/2023 | 17/6/2026 | Vulnerability in the Oracle Database Sharding component of Oracle Database Server. Supported versions that are affected are 19.3-19.20 and 21.3-21.11. Easily exploitable vulnerability allows high privileged attacker having Create Session, Create Any View, Select Any Table privilege with network access via Oracle Net… | |
| Modificada | Baja (2.4) | 0.89% | 💥 PoC | Oracle Database Server | 17/10/2023 | 17/6/2026 | Vulnerability in the Oracle Database Sharding component of Oracle Database Server. Supported versions that are affected are 19.3-19.20 and 21.3-21.11. Easily exploitable vulnerability allows high privileged attacker having Create Session, Select Any Dictionary privilege with network access via Oracle Net to compromise… | |
| Modificada | Media (4.3) | 0.33% | — | Oracle Database Server | 17/10/2023 | 17/6/2026 | Vulnerability in the Oracle Notification Server component of Oracle Database Server. Supported versions that are affected are 19.3-19.20 and 21.3-21.11. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle… | |
| Modificada | Media (5.9) | 0.31% | — | Oracle Database Server | 17/10/2023 | 17/6/2026 | Vulnerability in the PL/SQL component of Oracle Database Server. Supported versions that are affected are 19.3-19.20 and 21.3-21.11. Easily exploitable vulnerability allows high privileged attacker having Create Session, Execute on sys.utl_http privilege with network access via Oracle Net to compromise PL/SQL.… | |
| Modificada | Alta (8.8) | 0.26% | — | Cagewebdev Optimize Database After Deleting Revisions | 4/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in CAGE Web Design | Rolf van Gelder Optimize Database after Deleting Revisions plugin <= 5.1 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Peprodev CF7 Database | 25/9/2023 | 17/6/2026 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Pepro Dev. Group PeproDev CF7 Database plugin <= 1.7.0 versions. | |
| Modificada | Crítica (9.8) | 0.88% | — | SAP CommoncryptolibSAP Content ServerSAP Extended Application Services AND RuntimeSAP Hana Database+5 | 12/9/2023 | 17/6/2026 | SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation of privileges. Depending on the application and the level of privileges acquired, an attacker could abuse functionality restricted to a… | |
| Modificada | Alta (7.5) | 0.75% | — | SAP CommoncryptolibSAP Content ServerSAP Extended Application Services AND RuntimeSAP Hana Database+5 | 12/9/2023 | 17/6/2026 | SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a library which in turn causes the target component to crash making it unavailable. There is no ability to view or modify any information. | |
| Modificada | Alta (7.8) | 0.16% | — | Cisco Broadworks Application Delivery PlatformCisco Broadworks Application ServerCisco Broadworks Database ServerCisco Broadworks Execution Server+8 | 3/8/2023 | 17/6/2026 | A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevate privileges to root on an affected system. This vulnerability is due to incorrect implementation of user role permissions. An attacker could exploit this vulnerability… | |
| Modificada | Baja (3.1) | 0.41% | — | Oracle Database Server | 18/7/2023 | 17/6/2026 | Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.19 and 21.3-21.10. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to compromise Java VM.… | |
| Modificada | Media (4.9) | 0.50% | — | Oracle Database Server | 18/7/2023 | 17/6/2026 | Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are affected are 19.3-19.19 and 21.3-21.10. Easily exploitable vulnerability allows high privileged attacker having SYSDBA privilege with network access via Oracle Net to compromise Unified Audit. Successful attacks of this… | |
| Modificada | Baja (3.7) | 0.39% | — | Oracle Database Server | 18/7/2023 | 17/6/2026 | Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 19.3-19.19 and 21.3-21.10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks of… | |
| Modificada | Media (6.1) | 0.50% | — | Solarwinds Database Performance Analyzer | 18/7/2023 | 17/6/2026 | XSS attack was possible in DPA 2023.2 due to insufficient input validation | |
| Modificada | Media (6) | 0.20% | — | Cisco Broadworks Application Delivery Platform FirmwareCisco Broadworks Application Server FirmwareCisco Broadworks Database Server FirmwareCisco Broadworks Database Troubleshooting Server Firmware+12 | 12/7/2023 | 17/6/2026 | A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device. The vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this vulnerability by issuing a crafted command to the affected… | |
| Modificada | Alta (8.8) | 0.26% | — | Database Collation FIX Project Database Collation FIX | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Dave Jesch Database Collation Fix plugin <= 1.2.7 versions. |