Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
1243 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.26% | — | Sigmaplugin Advanced Database Cleaner | 23/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Younes JFR. Advanced Database Cleaner plugin <= 3.1.1 versions. | |
| Modificada | Crítica (9.1) | 0.75% | — | Vmware Greenplum Database | 15/5/2023 | 17/6/2026 | Greenplum Database (GPDB) is an open source data warehouse based on PostgreSQL. In versions prior to 6.22.3 Greenplum Database used an unsafe methods to extract tar files within GPPKGs. greenplum-db is vulnerable to path traversal leading to arbitrary file writes. An attacker can use this vulnerability to overwrite… | |
| Modificada | Media (6.1) | 0.85% | 💥 Exploit | Membership Database Project Membership Database | 8/5/2023 | 17/6/2026 | The Membership Database WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (6.5) | 1.3% | — | Solarwinds Database Performance Analyzer | 25/4/2023 | 17/6/2026 | Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server. | |
| Modificada | Alta (7.5) | 0.81% | — | Solarwinds Database Performance Analyzer | 25/4/2023 | 17/6/2026 | No exception handling vulnerability which revealed sensitive or excessive information to users. | |
| Modificada | Media (6.8) | 0.54% | — | Oracle Database | 18/4/2023 | 17/6/2026 | Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Difficult to exploit vulnerability allows low privileged attacker having User Account privilege with network access via TLS to compromise Java VM. Successful attacks of this vulnerability can result… | |
| Modificada | Media (6.8) | 0.67% | — | Oracle Database Recovery Manager | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Database Recovery Manager component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Easily exploitable vulnerability allows high privileged attacker having Local SYSDBA privilege with network access via Oracle Net to compromise Oracle Database Recovery… | |
| Modificada | Alta (7.5) | 0.25% | — | WP CSV TO Database Project WP CSV TO Database | 14/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tips and Tricks HQ, josh401 WP CSV to Database – Insert CSV file content into WordPress plugin <= 2.6 versions. | |
| Modificada | Media (4.3) | 0.23% | — | Xnau Participants Database | 28/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Roland Barker, xnau webdesign Participants Database plugin <= 2.4.5 leads to list column update. | |
| Modificada | Alta (7.5) | 0.42% | — | Solarwinds Database Performance Analyzer | 20/1/2023 | 17/6/2026 | In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext. | |
| Modificada | Media (5.4) | 0.40% | — | Solarwinds Database Performance Analyzer | 20/1/2023 | 17/6/2026 | In Database Performance Analyzer (DPA) 2022.4 and older releases, certain URL vectors are susceptible to authenticated reflected cross-site scripting. | |
| Modificada | Alta (7.5) | 0.59% | — | Oracle Database Server | 18/1/2023 | 17/6/2026 | Vulnerability in the Oracle Data Provider for .NET component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCPS to compromise Oracle Data Provider for .NET. Successful attacks require human… | |
| Modificada | Media (6.3) | 0.45% | — | Oracle Database | 18/1/2023 | 17/6/2026 | Vulnerability in the Oracle Database RDBMS Security component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Oracle Database RDBMS Security.… | |
| Modificada | Media (4.3) | 0.45% | — | Oracle Database | 18/1/2023 | 17/6/2026 | Vulnerability in the Oracle Database Data Redaction component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Oracle Database Data Redaction.… | |
| Modificada | Crítica (9.8) | 0.67% | — | Pokemon-database-php Project Pokemon-database-php | 17/1/2023 | 17/6/2026 | A vulnerability was found in VictorFerraresi pokemon-database-php. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection. The patch is named dd0e1e6cdf648d6a3deff441f515bcb1d7573d68. It is recommended to apply a patch to fix this issue.… | |
| Modificada | Crítica (9.8) | 0.68% | — | Mnbikeways Database Project Mnbikeways Database | 17/1/2023 | 17/6/2026 | A vulnerability was found in MNBikeways database and classified as critical. This issue affects some unknown processing of the file Data/views.py. The manipulation of the argument id1/id2 leads to sql injection. The identifier of the patch is 829a027aca7c17f5a7ec1addca8dd5d5542f86ac. It is recommended to apply a patch… | |
| Modificada | Crítica (9.8) | 0.67% | — | Liftkit Database Library Project Liftkit Database Library | 16/1/2023 | 17/6/2026 | A vulnerability was found in liftkit database up to 2.13.1. It has been classified as critical. This affects the function processOrderBy of the file src/Query/Query.php. The manipulation leads to sql injection. Upgrading to version 2.13.2 is able to address this issue. The patch is named… | |
| Modificada | Crítica (9.8) | 0.66% | — | Mirna Database BY PHP Mysql Project Mirna Database BY PHP Mysql | 15/1/2023 | 17/6/2026 | A vulnerability was found in brandonfire miRNA_Database_by_PHP_MySql. It has been declared as critical. This vulnerability affects the function __construct/select_single_rna/count_rna of the file inc/model.php. The manipulation leads to sql injection. The patch is identified as… | |
| Modificada | Alta (8.8) | 0.79% | — | Gnome Gvariant Database | 26/12/2022 | 17/6/2026 | A vulnerability was found in GNOME gvdb. It has been classified as critical. This affects the function gvdb_table_write_contents_async of the file gvdb-builder.c. The manipulation leads to use after free. It is possible to initiate the attack remotely. The name of the patch is d83587b2a364eb9a9a53be7e6a708074e252de14.… | |
| Modificada | Alta (7.8) | 0.31% | — | H2database H2 | 23/11/2022 | 17/6/2026 | The web-based admin console in H2 Database Engine before 2.2.220 can be started via the CLI with the argument -webAdminPassword, which allows the user to specify the password in cleartext for the web admin console. Consequently, a local user (or an attacker that has obtained local access through some means) would be… | |
| Modificada | Crítica (9.8) | 3.9% | — | Ciphercoin Contact Form 7 Database Addon | 21/11/2022 | 17/6/2026 | The Contact Form 7 Database Addon WordPress plugin before 1.2.6.5 does not validate data when output it back in a CSV file, which could lead to CSV injection | |
| Modificada | Media (6.1) | 0.50% | — | Oracle Database Server | 18/10/2022 | 17/6/2026 | Vulnerability in the Oracle Services for Microsoft Transaction Server component of Oracle Database Server. The supported version that is affected is 19c. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Services for Microsoft Transaction Server.… | |
| Modificada | Alta (7.2) | 0.90% | — | Oracle Database - Sharding | 18/10/2022 | 17/6/2026 | Vulnerability in the Oracle Database - Sharding component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Easily exploitable vulnerability allows high privileged attacker having Local Logon privilege with network access via Local Logon to compromise Oracle Database - Sharding.… | |
| Modificada | Alta (7.2) | 0.90% | — | Oracle Database | 18/10/2022 | 17/6/2026 | Vulnerability in the Oracle Database - Advanced Queuing component of Oracle Database Server. The supported version that is affected is 19c. Easily exploitable vulnerability allows high privileged attacker having DBA user privilege with network access via Oracle Net to compromise Oracle Database - Advanced Queuing.… | |
| Modificada | Crítica (9.8) | 5.1% | 💥 PoC | Hsqldb Hypersql DatabaseDebian Linux | 6/10/2022 | 17/6/2026 | Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by… |