Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

5033 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7)0.13%—Oracle Agile Engineering Data Management18/8/202625/8/2026
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile…
ModificadaMedia (6.3)0.14%—Oracle Agile Engineering Data Management18/8/202626/8/2026
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Agile…
ModificadaAlta (7.5)0.33%—Oracle Agile Engineering Data Management18/8/202625/8/2026
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached…
AplazadaAlta (8.7)0.52%—DataeaseAI18/8/202618/9/2026
DataEase is an open source data visualization and analysis tool. Versions prior to 2.10.23 have a path traversal vulnerability. The root cause is that on Windows, the `FILE_SEPARATOR` is `\`, while the server only filters the `/` character during string truncation. The vulnerability has been fixed in v2.10.23. No…
AplazadaCrítica (9.8)0.79%—Acryl DatahubAI17/8/20269/9/2026
A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to execute arbitrary code via the server retrieving an image from a crafted URL, and it fails to return the content or any errors directly.
AplazadaMedia (5.3)0.38%—Ondata Ckan MCP ServerAI14/8/202618/9/2026
CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_quality and ckan_get_mqa_quality_details tools in src/tools/quality.ts use isValidMqaServer to validate the server_url parameter with a prefix-only regular expression for dati.gov.it, allowing suffix-host and URL-userinfo…
AplazadaMedia (5.5)0.69%—AlldataAI14/8/202614/8/2026
A flaw has been found in alldatacenter alldata up to 0.6.8. This impacts the function FileInputStream of the file /admin/controller/JobLogController.java of the component logDetailCat Endpoint. This manipulation of the argument executorAddress causes path traversal. It is possible to initiate the attack remotely. The…
AplazadaMedia (5.5)0.56%—Alldatacenter Xxl-rpcAIAlldataAI14/8/202618/8/2026
A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian2Input.readObject of the file /serialize/impl/HessianSerializer.java of the component xxl-rpc Listener. The manipulation results in deserialization. The attack may be performed from remote. The exploit is now public and…
AplazadaAlta (8.3)0.43%—Datavane TISAI14/8/202624/9/2026
Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows authenticated attackers to perform server-side request forgery and out-of-band file exfiltration by supplying a crafted taskScript payload to the doEditWorkflow endpoint, which processes XML through an unhardened…
AplazadaAlta (8.2)0.56%—Data Mufform LocalizerAI13/8/202626/8/2026
Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename. load_lexicon builds the catalog path by appending `Messages/$lang.po` to the directory holding…
AplazadaMedia (5.9)0.24%—Wpdataaccess WP Data AccessAI13/8/202614/8/2026
Author Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions.
AplazadaAlta (7.4)0.43%—Xnau Participants DatabaseAI13/8/202614/8/2026
Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.4 versions.
AnalizadaMedia (4.2)0.16%—IBM Datapower Gateway12/8/20264/10/2026
IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gateway 10.5.0.0 through 10.5.0.21 and IBM DataPower Gateway 10.6.0.0 through 10.6.0.9 allows a race condition that results in improper isolation of request state when handling the built‑in X‑Client‑IP header. Under concurrent request processing,…
AnalizadaAlta (7.8)0.30%—Microsoft Azure SQL Database11/8/202617/8/2026
Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally.
En análisisAlta (8.9)0.45%—Intel Data Center Attestation PrimitivesAI11/8/202612/8/2026
Protection mechanism failure for some Intel(R) Data Center Attestation Primitives (Intel(R) DCAP) may allow information disclosure. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable data exposure. This result may potentially occur via network access when…
En análisisMedia (4.3)0.13%—Intel Software Guard Extensions Data Center Attestation PrimitivesAI11/8/202629/9/2026
Omission of security-relevant information for some Intel(R) Software Guard Extensions Data Center Attestation Primitives within Ring 0: Kernel may allow a denial of service. Authorized adversary with a privileged user combined with a high complexity attack may enable data alteration. This result may potentially occur…
Pendiente de análisisBaja (3.7)0.19%—SAP Data Services Management ConsoleAI11/8/202626/8/2026
SAP Data Services Management Console allows an overly permissive Content Security Policy (CSP) configuration and lacks certain restrictive directives, which could enable an authenticated malicious user to leverage this weakness in combination with another vulnerability to inject and execute malicious scripts within…
Pendiente de análisisAlta (8.8)0.60%—Opendatahub ODH DashboardAI10/8/202614/8/2026
A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Account (SA) token, to exploit overly broad permissions granted to the SA. This enables the attacker to escalate their privileges to cluster-administrator level, gain access to sensitive data like…
Pendiente de análisisAlta (7.6)0.51%—Data Science PipelinesAIArgoproj Argo WorkflowsAI10/8/20268/9/2026
A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with elevated privileges, acting as a 'confused deputy' on behalf of the attacker.…
Pendiente de análisisAlta (7.1)0.48%—Kubeflow Data Science PipelinesAI10/8/202621/9/2026
A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerability in the setDefaultServiceAccount function. By specifying a more privileged ServiceAccount (SA) during a CreateRun request, an attacker can bypass authorization checks. This allows the tenant to…
Pendiente de análisisAlta (7.5)0.83%—Google Ml-metadataAI10/8/202621/9/2026
A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to known HTTP/2 denial of service (DoS) issues. An in-cluster attacker, with network access to the MLMD pod, could exploit these vulnerabilities by sending specially crafted HTTP/2 requests. This could…
Pendiente de análisisAlta (8.8)0.73%—Data Science Pipelines OperatorAI10/8/202621/9/2026
A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the spec.database.customExtraParams field, which allows for the injection of dangerous parameters into the MySQL Data Source Name (DSN) string. By manipulating these parameters, an attacker can enable…
Pendiente de análisisAlta (7.5)0.61%—MinioAIRedhat Data Science Pipelines OperatorAI10/8/202621/9/2026
A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive sensitive credentials, such as MariaDB root/user passwords and MinIO access/secret keys, if they can access the MinIO Route or MariaDB Service. The flaw occurs because the operator uses a…
Pendiente de análisisAlta (8.7)0.70%—Kubeflow Data Science Pipelines OperatorAI10/8/202621/9/2026
A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privileges beyond what is necessary for its operation. These excessive permissions, such as the ability to execute commands within pods and manage cluster-wide roles, could be…
AplazadaBaja (2.1)0.37%—Aliyun Alibabacloud-dataworks-mcp-serverAI9/8/202612/8/2026
A security flaw has been discovered in aliyun alibabacloud-dataworks-mcp-server up to 1.0.43. The impacted element is the function ReadResourceRequestSchema of the file src/resources/initResources.ts. The manipulation of the argument request.params.uri results in server-side request forgery. The attack may be launched…