Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
3323 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.55% | — | IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os | 4/9/2026 | 9/9/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a remote attacker to cause a denial of service due to an infinite loop. | |
| Analizada | Media (5.5) | 0.11% | — | IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os | 4/9/2026 | 9/9/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of database credentials. | |
| Analizada | Alta (7.7) | 0.38% | — | IBM APP Connect EnterpriseIBM Integration BUS FOR Z/os | 4/9/2026 | 8/9/2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 SAP Adapter is vulnerable to an XML external entity (XXE) attack. | |
| Pendiente de análisis | Alta (8.5) | 0.35% | — | Google Cloud Integration ConnectorsAI | 4/9/2026 | 8/9/2026 | A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated user to escalate privileges and take over a Google Cloud Project using unauthorized service account attachment. This vulnerability was patched on… | |
| Aplazada | Media (6.5) | 0.33% | — | Mountdev AI MCP Connector FOR WordpressAI | 3/9/2026 | 4/9/2026 | Missing Authorization vulnerability in Cascadia Web Services MountDev AI MCP Connector for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MountDev AI MCP Connector for WordPress: from n/a through 1.6.5. | |
| Aplazada | Alta (7.1) | 0.25% | — | LeadconnectorAI | 31/8/2026 | 1/9/2026 | Unauthenticated Cross Site Scripting (XSS) in LeadConnector <= 4.0.5 versions. | |
| Pendiente de análisis | Baja (3.1) | 0.15% | — | HCL ConnectionsAI | 31/8/2026 | 3/9/2026 | HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling of request data they are not entitled to, caused by improper handling of request data. | |
| Pendiente de análisis | Media (5.9) | 0.23% | — | Mariadb Connector R2dbcAI | 28/8/2026 | 8/9/2026 | MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2dbc-mariadb does not gate clear-text password authentication plugins on transport encryption because the AuthenticationPlugin interface has no capability for a plugin to require a secure connection. A… | |
| Pendiente de análisis | Media (5.9) | 0.49% | — | Mariadb Connector R2dbcAIMariadbAI | 28/8/2026 | 8/9/2026 | MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2dbc-mariadb encodes and decodes all character data under the assumption that the connection character set is UTF-8. A server can announce a mid-session change to character_set_client through the… | |
| Pendiente de análisis | Media (5.9) | 0.87% | — | Mariadb Connector/jAIMariadbAI | 28/8/2026 | 8/9/2026 | MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, the connector encodes and decodes protocol text and performs client-side escaping under the assumption that the connection character set is UTF-8. The server can report a… | |
| Pendiente de análisis | Media (5.9) | 0.39% | — | Mariadb Connector JAIMariadbAI | 28/8/2026 | 8/9/2026 | MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, PAM dialog authentication can be coerced into transmitting the account password over an insecure connection. The mysql_clear_password plugin is gated behind a secure… | |
| Pendiente de análisis | Media (5.9) | 0.44% | — | Mariadb Connector/jAI | 28/8/2026 | 8/9/2026 | MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, when a Java application connects with sslMode=verify-full or sslMode=verify-ca, supplies a password, and does not configure serverSslCert or trustStore, Connector/J can accept… | |
| Pendiente de análisis | Media (6.5) | 0.47% | — | Mariadb Connector/node.jsAI | 28/8/2026 | 8/9/2026 | MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js permits SQL injection when attacker-controlled Buffer parameters are escaped client-side under the big5, gbk, sjis, cp932, or gb18030 client… | |
| Pendiente de análisis | Media (5.9) | 0.42% | — | Mariadb Connector/node.jsAI | 28/8/2026 | 8/9/2026 | MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js can disclose an account password when PAM dialog authentication is negotiated over an insecure transport. In… | |
| Analizada | Media (6) | 0.37% | — | Mongodb BI Connector Odbc Driver | 28/8/2026 | 11/9/2026 | An application using the MongoDB BI Connector ODBC Driver may encounter a memory-safety issue when a submitted SQL statement contains an unusually long run of digits following a LIMIT clause. The issue occurs only on connections where the driver's optional prefetch setting is enabled, and stems from the driver copying… | |
| Analizada | Alta (8.7) | 0.49% | — | Mongodb BI Connector Odbc Driver | 28/8/2026 | 11/9/2026 | A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver can supply a positioned-cursor statement whose cursor name exceeds the size of an internal fixed-length buffer. Because the name length is not bounded before the driver builds its diagnostic message, memory adjacent to that… | |
| Pendiente de análisis | Alta (7.5) | 0.57% | — | Mariadb Connector Node.jsAI | 28/8/2026 | 8/9/2026 | MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to versions 3.3.3, 3.4.6, and 3.5.3, when ssl is enabled without a pinned CA or server certificate, MariaDB Connector/Node.js sends credentials before completing certificate fingerprint validation. In… | |
| Analizada | Alta (8.7) | 0.42% | — | Mongodb BI Connector | 28/8/2026 | 29/9/2026 | A network-reachable client that has not yet authenticated can hold a MongoDB Connector for BI authentication session open indefinitely by beginning a SASL-based login exchange and then declining to complete it. Because the negotiation loop had no overall time bound and the read from the client had no deadline, each… | |
| Analizada | Alta (8.7) | 0.25% | — | Mongodb BI Connector | 28/8/2026 | 29/9/2026 | When mongosqld is configured with a client certificate authority file, the listener requests a client certificate during the TLS handshake but does not require one, so a client that presents no certificate is still accepted. In deployments that rely on client certificates as the sole means of identifying users, a… | |
| Analizada | Alta (8.7) | 0.46% | — | Mongodb BI Connector | 28/8/2026 | 29/9/2026 | An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance may generate enough routine connection log activity to exhaust the storage backing the configured log path. When a log write or log rotation operation subsequently fails, the resulting error is not handled and the shared… | |
| Analizada | Alta (8.3) | 0.42% | — | Mongodb BI Connector | 28/8/2026 | 29/9/2026 | A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling routine to stop functioning by defining a view whose evaluation reliably fails. The sampling logic classifies the resulting server message as transient and, after the configured retries are… | |
| Analizada | Alta (8.5) | 0.42% | — | Mongodb BI Connector | 28/8/2026 | 29/9/2026 | In MongoDB Connector for BI, MongoDB object names such as collection, field, and index names are placed into the quoted identifiers of the DDL text returned by SHOW CREATE statements without escaping the identifier delimiter. A user with permission to write to a sampled MongoDB collection can choose a name that closes… | |
| Analizada | Media (5.7) | 0.30% | — | Mongodb BI Connector | 28/8/2026 | 29/9/2026 | In MongoDB Connector for BI, the description text of a collection's JSON schema validator is incorporated into the comment text of the DDL returned by SHOW CREATE statements without complete escaping of backslash characters. A user with permission to modify a collection's schema validator, in deployments configured to… | |
| Analizada | Media (4.1) | 0.10% | — | Mongodb BI Connector | 27/8/2026 | 23/9/2026 | In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is supplied through both the connection URI and the corresponding command-line option. A local user with access to the captured command output and encrypted key file may use the disclosed password to access… | |
| Analizada | Alta (8.2) | 0.28% | — | Mongodb BI Connector | 27/8/2026 | 23/9/2026 | An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authentication may cause mongosqld to terminate when a crafted authentication exchange encounters a specific GSSAPI error-handling condition. This can interrupt BI Connector availability until the process restarts. |